month report
November 2007
Data as of Jun 4, 2026, 13:24 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
November 2007 closed with 486 published CVEs. 76 criticals, apple led volume, mostly via mac os x. Biggest breakout: apple at ×8.4 their 12-month median. Top weakness class — CWE-119 (65 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
486
— MoM— YoY
Severity mix
76 / 144
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.4%
2 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6690.4
n=2
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in November 2007
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds79XSS89SQL Injection264CWE-26420Improper Input Validation22Path Traversal94Code Injection200Information Exposure287Improper Authentication399CWE-399apple91821132ibm64613novell inc.41сообщество свободного программного обеспечения5121pcre4wireshark41microsoft411redhat2111symantec22111ingate121citrix12hitachi121
Breakout vendors
CVE count ≥3× their own 12-period median.
- 8.4×apple42 CVE
- 3.5×ibm28 CVE
- 3.0×сообщество свободного программного обеспечения12 CVE
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #4pcre11 CVE
- #17flatnuke34 CVE
- #19openbase international ltd4 CVE
- #21softbizscripts4 CVE
- #22tug4 CVE
- #23acdsee3 CVE
- #25bosdev3 CVE
- #26bti-tracker3 CVE
- #27jportal3 CVE
- #32project alumni3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 42 CVE15 critCVSS 7.3×8.4PoC 2mac os x (34) · mac os x server (19) · quicktime (5)
- 28 CVE8 critCVSS 7.1×3.5db2 universal database (9) · aix (7) · websphere application server (3)
- 12 CVE1 critCVSS 7.0×3.0PoC 2debian gnu/linux (12)
- 11 CVECVSS 6.0NEWpcre (10) · perl-compatible regular expression library (1)
- 11 CVE3 critCVSS 7.0PoC 1wireshark (11)
- 10 CVE1 critCVSS 6.6suse linux enterprise (7) · opensuse (3)
- 9 CVE6 critCVSS 8.1windows xp (6) · windows vista (4) · windows 2000 (4)
- 9 CVECVSS 5.4PoC 2enterprise linux (3) · certificate server (1) · conga (1)
- 9 CVE3 critCVSS 6.9backupexec system recovery (2) · mail security (2) · web security (1)
- 8 CVE3 critCVSS 7.2ingate firewall (8) · ingate siparator (8)
- 5 CVECVSS 4.5netscaler (3) · access gateway (1) · metaframe presentation server (1)
- 5 CVE1 critCVSS 6.3gentoo linux (5)
- 5 CVECVSS 4.7cosminexus application server enterprise (2) · cosminexus application server standard (2) · cosminexus developer light version 6 (2)
- 5 CVECVSS 6.7linux kernel (5)
- 5 CVE1 critCVSS 6.9PoC 2javamail (1) · net connect software (1) · solaris (1)
- 4 CVECVSS 6.2ethereal (4)
- 4 CVECVSS 5.7NEWPoC 4flatnuke3 (4)
- 4 CVE1 critCVSS 6.1firefox (4) · seamonkey (3)
- 4 CVE2 critCVSS 8.6NEWPoC 2openbase (4)
- 4 CVECVSS 4.9php (4)
- 4 CVECVSS 7.0NEWPoC 4ad management plus script (1) · banner exchange network script (1) · link directory script (1)
- 4 CVECVSS 5.5NEWPoC 1texlive 2007 (4)
- 3 CVE2 critCVSS 8.5NEWphoto editor (3) · photo manager (3) · pro photo manager (3)
- 3 CVE3 critCVSS 9.3keyview export sdk (3) · keyview filter sdk (3) · keyview viewer sdk (3)
- 3 CVECVSS 4.3NEWbosnews (2) · bosmarket business directory system (1)
- 3 CVECVSS 6.2NEWbti-tracker (3)
- 3 CVECVSS 7.5NEWPoC 3jportal web portal (3)
- 3 CVE1 critCVSS 7.2bordermanager (1) · client (1) · ichain (1)
- 3 CVECVSS 7.3database server (2) · e-business suite (1)
- 3 CVECVSS 4.2phpmyadmin (3)
- 3 CVECVSS 5.4PoC 1postnuke (3)
- 3 CVECVSS 6.4NEWPoC 3project alumni (3)
- 3 CVE3 critCVSS 9.7NEWPoC 1ssl vpn (2) · ssl vpn 200 (1) · ssl vpn2000\/4000 (1)
- 3 CVECVSS 5.7PoC 1tetex (3)
- 3 CVECVSS 5.6NEWtilde cms (3)
- 3 CVE1 critCVSS 6.8NEWPoC 3vigilecms (3)
- 3 CVECVSS 7.5NEWcase manager (2) · mass mailer (1)
- 3 CVE2 critCVSS 8.7xpdf (3)
- 2 CVE2 critCVSS 9.3NEWdocconverter (2)
- 2 CVE1 critCVSS 8.4PoC 1coldfusion (1) · shockwave player (1)
- 2 CVECVSS 4.2NEWbandersnatch (2)
- 2 CVECVSS 7.2NEWPoC 2bcoos (2)
- 2 CVECVSS 4.8NEWbitchx (2)
- 2 CVE2 critCVSS 9.7NEWPoC 1online anti-virus scanner (1) · antivirus (1) · internet security (1)
- 2 CVECVSS 5.0NEWi-gallery (2)
- 2 CVECVSS 3.9unified ip phone (1) · unified meetingplace (1)
- 2 CVECVSS 5.5NEWPoC 1contentcustomizer (2)
- 2 CVECVSS 7.2NEWPoC 2social networking script (2)
- 2 CVECVSS 7.0asterisk (2)
- 2 CVECVSS 7.5NEWPoC 2eurologon cms (2)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | apple | 42 | 15 | · | · | ×8.4PoC 2 | mac os x (34) · mac os x server (19) · quicktime (5) | — | |
| 2 | ibm | 28 | 8 | · | · | ×3.5 | db2 universal database (9) · aix (7) · websphere application server (3) | — | |
| 3 | сообщество свободного программного обеспечения | 12 | 1 | · | · | ×3.0PoC 2 | debian gnu/linux (12) | — | |
| 4 | pcre | 11 | · | · | · | NEW | pcre (10) · perl-compatible regular expression library (1) | — | |
| 5 | wireshark | 11 | 3 | · | · | PoC 1 | wireshark (11) | — | |
| 6 | novell inc. | 10 | 1 | · | · | suse linux enterprise (7) · opensuse (3) | — | ||
| 7 | microsoft | 9 | 6 | · | · | windows xp (6) · windows vista (4) · windows 2000 (4) | — | ||
| 8 | redhat | 9 | · | · | · | PoC 2 | enterprise linux (3) · certificate server (1) · conga (1) | — | |
| 9 | symantec | 9 | 3 | · | · | backupexec system recovery (2) · mail security (2) · web security (1) | — | ||
| 10 | ingate | 8 | 3 | · | · | ingate firewall (8) · ingate siparator (8) | — | ||
| 11 | citrix | 5 | · | · | · | netscaler (3) · access gateway (1) · metaframe presentation server (1) | — | ||
| 12 | gentoo foundation inc. | 5 | 1 | · | · | gentoo linux (5) | — | ||
| 13 | hitachi | 5 | · | · | · | cosminexus application server enterprise (2) · cosminexus application server standard (2) · cosminexus developer light version 6 (2) | — | ||
| 14 | linux | 5 | · | · | · | linux kernel (5) | — | ||
| 15 | sun | 5 | 1 | · | · | PoC 2 | javamail (1) · net connect software (1) · solaris (1) | — | |
| 16 | ethereal group | 4 | · | · | · | ethereal (4) | — | ||
| 17 | flatnuke3 | 4 | · | · | · | NEWPoC 4 | flatnuke3 (4) | — | |
| 18 | mozilla | 4 | 1 | · | · | firefox (4) · seamonkey (3) | — | ||
| 19 | openbase international ltd | 4 | 2 | · | · | NEWPoC 2 | openbase (4) | — | |
| 20 | php | 4 | · | · | · | php (4) | — | ||
| 21 | softbizscripts | 4 | · | · | · | NEWPoC 4 | ad management plus script (1) · banner exchange network script (1) · link directory script (1) | — | |
| 22 | tug | 4 | · | · | · | NEWPoC 1 | texlive 2007 (4) | — | |
| 23 | acdsee | 3 | 2 | · | · | NEW | photo editor (3) · photo manager (3) · pro photo manager (3) | — | |
| 24 | autonomy | 3 | 3 | · | · | keyview export sdk (3) · keyview filter sdk (3) · keyview viewer sdk (3) | — | ||
| 25 | bosdev | 3 | · | · | · | NEW | bosnews (2) · bosmarket business directory system (1) | — | |
| 26 | bti-tracker | 3 | · | · | · | NEW | bti-tracker (3) | — | |
| 27 | jportal | 3 | · | · | · | NEWPoC 3 | jportal web portal (3) | — | |
| 28 | novell | 3 | 1 | · | · | bordermanager (1) · client (1) · ichain (1) | — | ||
| 29 | oracle | 3 | · | · | · | database server (2) · e-business suite (1) | — | ||
| 30 | phpmyadmin | 3 | · | · | · | phpmyadmin (3) | — | ||
| 31 | postnuke software foundation | 3 | · | · | · | PoC 1 | postnuke (3) | — | |
| 32 | project alumni | 3 | · | · | · | NEWPoC 3 | project alumni (3) | — | |
| 33 | sonicwall | 3 | 3 | · | · | NEWPoC 1 | ssl vpn (2) · ssl vpn 200 (1) · ssl vpn2000\/4000 (1) | — | |
| 34 | tetex | 3 | · | · | · | PoC 1 | tetex (3) | — | |
| 35 | tilde | 3 | · | · | · | NEW | tilde cms (3) | — | |
| 36 | vigilecms | 3 | 1 | · | · | NEWPoC 3 | vigilecms (3) | — | |
| 37 | vu | 3 | · | · | · | NEW | case manager (2) · mass mailer (1) | — | |
| 38 | xpdf | 3 | 2 | · | · | xpdf (3) | — | ||
| 39 | activepdf | 2 | 2 | · | · | NEW | docconverter (2) | — | |
| 40 | adobe | 2 | 1 | · | · | PoC 1 | coldfusion (1) · shockwave player (1) | — | |
| 41 | bandersnatch | 2 | · | · | · | NEW | bandersnatch (2) | — | |
| 42 | bcoos | 2 | · | · | · | NEWPoC 2 | bcoos (2) | — | |
| 43 | bitchx | 2 | · | · | · | NEW | bitchx (2) | — | |
| 44 | bitdefender | 2 | 2 | · | · | NEWPoC 1 | online anti-virus scanner (1) · antivirus (1) · internet security (1) | — | |
| 45 | blue-collar productions | 2 | · | · | · | NEW | i-gallery (2) | — | |
| 46 | cisco | 2 | · | · | · | unified ip phone (1) · unified meetingplace (1) | — | ||
| 47 | contentcustomizer | 2 | · | · | · | NEWPoC 1 | contentcustomizer (2) | — | |
| 48 | datecomm | 2 | · | · | · | NEWPoC 2 | social networking script (2) | — | |
| 49 | digium | 2 | · | · | · | asterisk (2) | — | ||
| 50 | eurologon | 2 | · | · | · | NEWPoC 2 | eurologon cms (2) | — |