[
  {"cve_id":"CVE-2007-5461","description":"Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.","exploit_maturity":"Working exploit published","published":"2007-10-15","resolved":"MITIGATED-BY-RASP","severity":"Low"},
  {"cve_id":"CVE-2007-5273","description":"Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when an HTTP proxy server is used, allows remote attackers to violate the security model for an applet's outbound connections via a multi-pin DNS rebinding attack in which the applet download relies on DNS resolution on the proxy server, but the applet's socket operations rely on DNS resolution on the local machine, a different issue than CVE-2007-5274. NOTE: this is similar to CVE-2007-5232.","exploit_maturity":"No public exploit","published":"2007-10-08","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-5238","description":"Java Web Start in Sun JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to obtain sensitive information (the Java Web Start cache location) via an untrusted application, aka \"three vulnerabilities.\"","exploit_maturity":"No public exploit","published":"2007-10-06","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-2450","description":"Multiple cross-site scripting (XSS) vulnerabilities in the (1) Manager and (2) Host Manager web applications in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote authenticated users to inject arbitrary web script or HTML via a parameter name to manager/html/upload, and other unspecified vectors.","exploit_maturity":"No public exploit","published":"2007-06-14","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2007-1358","description":"Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted \"Accept-Language headers that do not conform to RFC 2616\".","exploit_maturity":"No public exploit","published":"2007-05-10","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Low"},
  {"cve_id":"CVE-2007-0296","description":"Unspecified vulnerability in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.13, 8.47.11, and 8.48.06 has unknown impact and attack vectors in PeopleTools, aka PSE02.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0294","description":"Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning \u0026 Data Guard Management, aka EM06.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0282","description":"Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt \u0026 Notification component, aka OPMN02.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2007-0275","description":"Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to inject arbitrary HTML or web script via the genuser parameter to rwcgi60, aka OWF01.","exploit_maturity":"No public exploit","published":"2007-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"Low"}
]
