NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53008  CVE-2007-0791  Cross-site scripting (XSS) vulnerability in Atom feeds in Bugzilla 2.20.3, 2.22.1, and 2.23.3, and earlier versions down to 2.20.1, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2011-03-07  View
53264  CVE-2007-1056  VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restricted operations such as changing system time, accessing hardware components, and stopping the "VMware tools service" service. NOTE: exploitation is simplified via (1) weak file permisssions (Users = Read & Execute) for %PROGRAMFILES%VMware; and weak registry key permissions (access by Users) for (2) vmmouse, (3) vmscsi, (4) VMTools, (5) vmx_svga, and (6) vmxnet in HKLMSYSTEMCurrentControlSetServices; which allows local users to perform various privileged actions outside of the guest OS by executing certain files under %PROGRAMFILES%VMwareVMware Tools, as demonstrated by (a) VMControlPanel.cpl and (b) vmwareservice.exe.    7.2  High  2017-01-07  2008-11-15  View
53520  CVE-2007-1330  Comodo Firewall Pro (CFP) (formerly Comodo Personal Firewall) 2.4.18.184 and earlier allows local users to bypass driver protections on the HKLMSYSTEMSoftwareComodoPersonal Firewall registry key by guessing the name of a named pipe under DeviceNamedPipeOLE and attempting to open it multiple times.    4.4  Medium  2017-01-07  2008-11-15  View
53776  CVE-2007-1592  net/ipv6/tcp_ipv6.c in Linux kernel 2.6.x up to 2.6.21-rc3 inadvertently copies the ipv6_fl_socklist from a listening TCP socket to child sockets, which allows local users to cause a denial of service (OOPS) or double free by opening a listening IPv6 socket, attaching a flow label, and connecting to that socket.    4.9  Medium  2017-01-07  2013-08-29  View
54032  CVE-2007-1861  The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.    4.9  Medium  2017-01-07  2012-03-19  View

Page 1498 of 17672, showing 5 records out of 88360 total, starting on record 7486, ending on 7490

Actions