Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-03-20 CVE-2007-1545 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
The AddResource function in server/dia/resource.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID.
network
low complexity
mandrakesoft radscan
5.0
2007-03-20 CVE-2007-1544 Local Privilege Escalation and Denial of Service vulnerability in Radscan Network Audio System 1.8A
Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c in Network Audio System (NAS) before 1.8a SVN 237 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value.
network
low complexity
mandrakesoft radscan
5.0
2007-03-20 CVE-2007-1542 Remote Denial of Service vulnerability in Cisco 7940/7960 Phone SIP Invite
Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers to cause a denial of service via the Remote-Party-ID sipURI field in a SIP INVITE request.
network
low complexity
cisco
5.0
2007-03-20 CVE-2007-1539 Local File Include vulnerability in Pragmamx Landkarten 2.1
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to include arbitrary files via a ..
network
pragmamx
4.3
2007-03-20 CVE-2007-1533 Unspecified vulnerability in Microsoft Windows Vista
The Teredo implementation in Microsoft Windows Vista uses the same nonce for communication with different UDP ports within a solicitation session, which makes it easier for remote attackers to spoof the nonce through brute force attacks.
network
low complexity
microsoft
5.0
2007-03-20 CVE-2007-1532 Unspecified vulnerability in Microsoft Windows Vista
The neighbor discovery implementation in Microsoft Windows Vista allows remote attackers to conduct a redirect attack by (1) responding to queries by sending spoofed Neighbor Advertisements or (2) blindly sending Neighbor Advertisements.
network
low complexity
microsoft
6.4
2007-03-20 CVE-2007-1531 Resource Management Errors vulnerability in Microsoft Windows Vista and Windows XP
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to cause a denial of service (loss of network access) by sending a gratuitous ARP for the address of the Vista host.
network
low complexity
microsoft CWE-399
5.0
2007-03-20 CVE-2007-1530 Remote Denial Of Service vulnerability in Microsoft Windows Vista LLTD Mapper EMIT Packet
The LLTD Mapper in Microsoft Windows Vista does not properly gather responses to EMIT packets, which allows remote attackers to cause a denial of service (mapping failure) by omitting an ACK response, which triggers an XML syntax error.
network
low complexity
microsoft
5.0
2007-03-20 CVE-2007-1529 Unspecified vulnerability in Microsoft Windows Vista
The LLTD Responder in Microsoft Windows Vista does not send the Mapper a response to a DISCOVERY packet if another host has sent a spoofed response first, which allows remote attackers to spoof arbitrary hosts via a network-based race condition, aka the "Total Spoof" attack.
network
microsoft
4.3
2007-03-20 CVE-2007-1528 Unspecified vulnerability in Microsoft Windows Vista
The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack.
network
low complexity
microsoft
5.0