Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-03-14 CVE-2007-1451 Remote Security vulnerability in Guppy 4.0
GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression des fichiers d'installation" (delete.php).
network
low complexity
guppy
6.4
2007-03-14 CVE-2007-1449 Local File Include and SQL Injection vulnerability in PHP-Nuke Lang Parameter
Directory traversal vulnerability in mainfile.php in PHP-Nuke 8.0 and earlier allows remote attackers to read arbitrary files via a ..
network
phpnuke
4.3
2007-03-14 CVE-2007-1444 Unspecified vulnerability in Netperf 2.4.3
netserver in netperf 2.4.3 allows local users to overwrite arbitrary files via a symlink attack on /tmp/netperf.debug.
local
netperf
4.4
2007-03-14 CVE-2007-1443 Cross-Site Scripting vulnerability in Woltlab Burning Board and Burning Board Lite
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Woltlab Burning Board (wBB) 2.3.6 and Burning Board Lite 1.0.2pl3e allow remote attackers to inject arbitrary web script or HTML via the (1) r_username, (2) r_email, (3) r_password, (4) r_confirmpassword, (5) r_homepage, (6) r_icq, (7) r_aim, (8) r_yim, (9) r_msn, (10) r_year, (11) r_month, (12) r_day, (13) r_gender, (14) r_signature, (15) r_usertext, (16) r_invisible, (17) r_usecookies, (18) r_admincanemail, (19) r_emailnotify, (20) r_notificationperpm, (21) r_receivepm, (22) r_emailonpm, (23) r_pmpopup, (24) r_showsignatures, (25) r_showavatars, (26) r_showimages, (27) r_daysprune, (28) r_umaxposts, (29) r_dateformat, (30) r_timeformat, (31) r_startweek, (32) r_timezoneoffset, (33) r_usewysiwyg, (34) r_styleid, (35) r_langid, (36) key_string, (37) key_number, (38) disablesmilies, (39) disablebbcode, (40) disableimages, (41) field[1], (42) field[2], and (43) field[3] parameters.
network
woltlab CWE-79
4.3
2007-03-14 CVE-2007-1441 Improper Input Validation vulnerability in RIM Blackberry, Blackberry 8100 and Blackberry Browser
The 4thPass browser (BlackBerry Browser) on the RIM BlackBerry 8100 (Pearl) before 4.2.1 allows remote attackers to cause a denial of service (temporary functionality loss) via a long href attribute in a link in a WML page.
network
rim CWE-20
4.3
2007-03-13 CVE-2007-0730 Applications Multiple vulnerability in Apple Mac OS X
Server Manager (servermgrd) in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently validate authentication credentials, which allows remote attackers to bypass authentication and modify system configuration.
network
apple
6.8
2007-03-13 CVE-2007-0728 Applications Multiple vulnerability in Apple Mac OS X
Unspecified vulnerability in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 creates files insecurely while initializing a USB printer, which allows local users to create or overwrite arbitrary files.
local
apple
4.4
2007-03-13 CVE-2007-0726 Applications Multiple vulnerability in Apple Mac OS X
The SSH key generation process in OpenSSH in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote attackers to cause a denial of service by connecting to the server before SSH has finished creating keys, which causes the keys to be regenerated and can break trust relationships that were based on the original keys.
network
low complexity
apple
5.0
2007-03-13 CVE-2007-0724 Applications Multiple vulnerability in Apple Mac OS X
The IOKit HID interface in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 does not sufficiently limit access to certain controls, which allows local users to gain privileges by using HID device events to read keystrokes from the console.
local
apple
6.9
2007-03-13 CVE-2007-0722 Applications Multiple vulnerability in Apple Mac OS X
Integer overflow in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to execute arbitrary code via a crafted AppleSingleEncoding disk image.
network
apple
6.8