month report
December 2007
Data as of Jun 4, 2026, 13:24 UTCSnapshot v1 Sources NVD+CISA KEV+EPSS+Nuclei templates Methodology →
December 2007 closed with 449 published CVEs. 71 criticals, apple led volume, mostly via mac os x. Biggest breakout: apple at ×5.2 their 12-month median. Top weakness class — CWE-119 (69 CVE). 10 vendors cracked the top-100 for the first time.
Total CVEs
449
— MoM— YoY
Severity mix
71 / 114
critical / high
KEV added
0
0 ransomware-linked
Nuclei coverage
0.4%
2 CVEs with templates
Time to exploit
How fast the community ships detection after a CVE drops.
Days → Nuclei (median)
6658.3
n=2
Within 7 days
0.0%
Within 30 days
0.0%
Days → KEV (median)
—
n=0
Weakness × Vendor
What's spreading where in December 2007
Cells shaded by share of vendor's hottest weakness. Click any cell to open the CWE history.
119Memory Buffer Bounds79XSS89SQL Injection264CWE-26422Path Traversal20Improper Input Validation94Code Injection200Information Exposure189CWE-189399CWE-399apple523133microsoft711223sun41hp3111ibm3431hosting controller1811gentoo foundation inc.11112сообщество свободного программного обеспечения411linux111211oracle11runcms111adobe1121
First time in top-100
Vendors never in top-100 in the prior 24 periods.
- #6hosting controller11 CVE
- #19xigla5 CVE
- #21bcoos4 CVE
- #23real time logic4 CVE
- #25aertherwide3 CVE
- #26badblue3 CVE
- #32falcon3 CVE
- #33flac3 CVE
- #34flat php3 CVE
- #35gadu-gadu3 CVE
Top vendors
Ranked by distinct CVE count this period.
- 26 CVE9 critCVSS 7.4×5.2PoC 3mac os x (20) · mac os x server (3) · quicktime (3)
- 17 CVE7 critCVSS 7.7PoC 5internet explorer (5) · ie (4) · windows vista (2)
- 13 CVE2 critCVSS 5.6solaris (4) · java system web server (4) · java system web proxy server (4)
- 12 CVE7 critCVSS 7.9×4.0PoC 6quick launch button (3) · info center (3) · openview network node manager (2)
- 12 CVE3 critCVSS 6.4PoC 1hardware management console (3) · lotus notes (2) · tivoli netcool security manager (2)
- 11 CVE1 critCVSS 6.4NEWPoC 11hosting controller (11)
- 8 CVE3 critCVSS 7.4PoC 2debian gnu/linux (8)
- 6 CVE2 critCVSS 6.2PoC 2gentoo linux (6)
- 6 CVECVSS 5.6linux kernel (6)
- 6 CVECVSS 5.0PoC 1mysql (3) · http server (1) · linux (1)
- 6 CVECVSS 6.7PoC 5runcms (6)
- 5 CVE1 critCVSS 6.1flash player (5)
- 5 CVE1 critCVSS 6.3PoC 1clamav (5)
- 5 CVECVSS 6.0org.mortbay.jetty:jetty (3) · org.apache.tomcat:tomcat-juli (1) · net.sf.robocode:robocode.core (1)
- 5 CVE3 critCVSS 8.4kerberos 5 (5)
- 5 CVE1 critCVSS 6.8PoC 1opera browser (5)
- 5 CVECVSS 4.3enterprise linux (4) · enterprise linux desktop (3) · enterprise linux server (2)
- 5 CVECVSS 4.7wireshark (5)
- 5 CVECVSS 5.9NEWPoC 1absolute news manager.net (4) · absolute banner manager.net (1)
- 4 CVECVSS 4.8PoC 1http server (3) · tomcat (1)
- 4 CVECVSS 5.9NEWPoC 2bcoos (3) · event calendar (1)
- 4 CVE1 critCVSS 7.5PoC 1ciscoworks server (1) · firewall services module (1) · ip phone 7940 (1)
- 4 CVECVSS 4.7NEWPoC 2barracudadrive web server home server (4) · barracudadrive web server (4)
- 4 CVE1 critCVSS 7.4red hat enterprise linux (4) · jboss enterprise application platform (1) · red hat web application (1)
- 3 CVE2 critCVSS 8.3NEWexiftags (3)
- 3 CVECVSS 6.7NEWPoC 2badblue (3)
- 3 CVECVSS 5.8PoC 2aqualogic interaction (2) · weblogic mobility server (1)
- 3 CVECVSS 6.2PoC 2bitweaver (3)
- 3 CVECVSS 4.6ubuntu linux (3)
- 3 CVECVSS 3.9debian linux (3)
- 3 CVECVSS 5.4drupal (1) · feature module (1) · shoutbox (1)
- 3 CVECVSS 6.2NEWPoC 3series one cms (3)
- 3 CVE3 critCVSS 9.3NEWlibflac (3)
- 3 CVECVSS 5.0NEWPoC 3board (3)
- 3 CVECVSS 4.3NEWgadu-gadu instant messenger (3)
- 3 CVECVSS 5.2NEWPoC 3gf 3xplorer (3)
- 3 CVECVSS 5.4NEWPoC 1kml (1) · toolbar (1) · web toolkit (1)
- 3 CVECVSS 5.6NEWjetty (3)
- 3 CVECVSS 6.0PoC 2mysql (2) · community server (1) · mysql enterprise server (1)
- 3 CVECVSS 4.8NEWPoC 2openbiblio (3)
- 3 CVE1 critCVSS 7.5NEWPoC 1phprpg (3)
- 3 CVECVSS 4.0linux enterprise desktop (2) · linux enterprise server (2) · linux enterprise software development kit (1)
- 3 CVE1 critCVSS 6.4PoC 1tikiwiki cms\/groupware (3)
- 3 CVECVSS 7.1NEWPoC 3xzero community classifieds (3)
- 2 CVECVSS 7.0NEWPoC 21024 cms (2)
- 2 CVE2 critCVSS 9.3NEWPoC 1mpeg-4 codec (2)
- 2 CVECVSS 7.5NEWPoC 2adultscript (2)
- 2 CVECVSS 5.5NEWPoC 1anon proxy server (2)
- 2 CVECVSS 7.5NEWbeehive forum (2)
- 2 CVECVSS 2.6PoC 1edgesight for endpoints (1) · edgesight for netscaler (1) · edgesight for presentation server (1)
| # | Vendor | CVEs | Crit | KEV | Nuclei | Signals | Top products | Δ | |
|---|---|---|---|---|---|---|---|---|---|
| 1 | apple | 26 | 9 | · | · | ×5.2PoC 3 | mac os x (20) · mac os x server (3) · quicktime (3) | — | |
| 2 | microsoft | 17 | 7 | · | · | PoC 5 | internet explorer (5) · ie (4) · windows vista (2) | — | |
| 3 | sun | 13 | 2 | · | · | solaris (4) · java system web server (4) · java system web proxy server (4) | — | ||
| 4 | hp | 12 | 7 | · | · | ×4.0PoC 6 | quick launch button (3) · info center (3) · openview network node manager (2) | — | |
| 5 | ibm | 12 | 3 | · | · | PoC 1 | hardware management console (3) · lotus notes (2) · tivoli netcool security manager (2) | — | |
| 6 | hosting controller | 11 | 1 | · | · | NEWPoC 11 | hosting controller (11) | — | |
| 7 | сообщество свободного программного обеспечения | 8 | 3 | · | · | PoC 2 | debian gnu/linux (8) | — | |
| 8 | gentoo foundation inc. | 6 | 2 | · | · | PoC 2 | gentoo linux (6) | — | |
| 9 | linux | 6 | · | · | · | linux kernel (6) | — | ||
| 10 | oracle | 6 | · | · | · | PoC 1 | mysql (3) · http server (1) · linux (1) | — | |
| 11 | runcms | 6 | · | · | · | PoC 5 | runcms (6) | — | |
| 12 | adobe | 5 | 1 | · | · | flash player (5) | — | ||
| 13 | clam anti-virus | 5 | 1 | · | · | PoC 1 | clamav (5) | — | |
| 14 | maven | 5 | · | · | · | org.mortbay.jetty:jetty (3) · org.apache.tomcat:tomcat-juli (1) · net.sf.robocode:robocode.core (1) | — | ||
| 15 | mit | 5 | 3 | · | · | kerberos 5 (5) | — | ||
| 16 | opera | 5 | 1 | · | · | PoC 1 | opera browser (5) | — | |
| 17 | redhat | 5 | · | · | · | enterprise linux (4) · enterprise linux desktop (3) · enterprise linux server (2) | — | ||
| 18 | wireshark | 5 | · | · | · | wireshark (5) | — | ||
| 19 | xigla | 5 | · | · | · | NEWPoC 1 | absolute news manager.net (4) · absolute banner manager.net (1) | — | |
| 20 | apache | 4 | · | · | · | PoC 1 | http server (3) · tomcat (1) | — | |
| 21 | bcoos | 4 | · | · | · | NEWPoC 2 | bcoos (3) · event calendar (1) | — | |
| 22 | cisco | 4 | 1 | · | · | PoC 1 | ciscoworks server (1) · firewall services module (1) · ip phone 7940 (1) | — | |
| 23 | real time logic | 4 | · | · | · | NEWPoC 2 | barracudadrive web server home server (4) · barracudadrive web server (4) | — | |
| 24 | red hat inc. | 4 | 1 | · | · | red hat enterprise linux (4) · jboss enterprise application platform (1) · red hat web application (1) | — | ||
| 25 | aertherwide | 3 | 2 | · | · | NEW | exiftags (3) | — | |
| 26 | badblue | 3 | · | · | · | NEWPoC 2 | badblue (3) | — | |
| 27 | bea | 3 | · | · | · | PoC 2 | aqualogic interaction (2) · weblogic mobility server (1) | — | |
| 28 | bitweaver | 3 | · | · | · | PoC 2 | bitweaver (3) | — | |
| 29 | canonical | 3 | · | · | · | ubuntu linux (3) | — | ||
| 30 | debian | 3 | · | · | · | debian linux (3) | — | ||
| 31 | drupal | 3 | · | · | · | drupal (1) · feature module (1) · shoutbox (1) | — | ||
| 32 | falcon | 3 | · | · | · | NEWPoC 3 | series one cms (3) | — | |
| 33 | flac | 3 | 3 | · | · | NEW | libflac (3) | — | |
| 34 | flat php | 3 | · | · | · | NEWPoC 3 | board (3) | — | |
| 35 | gadu-gadu | 3 | · | · | · | NEW | gadu-gadu instant messenger (3) | — | |
| 36 | gf 3xplorer | 3 | · | · | · | NEWPoC 3 | gf 3xplorer (3) | — | |
| 37 | 3 | · | · | · | NEWPoC 1 | kml (1) · toolbar (1) · web toolkit (1) | — | ||
| 38 | mortbay jetty | 3 | · | · | · | NEW | jetty (3) | — | |
| 39 | mysql | 3 | · | · | · | PoC 2 | mysql (2) · community server (1) · mysql enterprise server (1) | — | |
| 40 | openbiblio | 3 | · | · | · | NEWPoC 2 | openbiblio (3) | — | |
| 41 | phprpg | 3 | 1 | · | · | NEWPoC 1 | phprpg (3) | — | |
| 42 | suse | 3 | · | · | · | linux enterprise desktop (2) · linux enterprise server (2) · linux enterprise software development kit (1) | — | ||
| 43 | tiki | 3 | 1 | · | · | PoC 1 | tikiwiki cms\/groupware (3) | — | |
| 44 | xzero scripts | 3 | · | · | · | NEWPoC 3 | xzero community classifieds (3) | — | |
| 45 | 1024 cms | 2 | · | · | · | NEWPoC 2 | 1024 cms (2) | — | |
| 46 | 3ivx | 2 | 2 | · | · | NEWPoC 1 | mpeg-4 codec (2) | — | |
| 47 | adultscript | 2 | · | · | · | NEWPoC 2 | adultscript (2) | — | |
| 48 | anon proxy server | 2 | · | · | · | NEWPoC 1 | anon proxy server (2) | — | |
| 49 | beehive forum | 2 | · | · | · | NEW | beehive forum (2) | — | |
| 50 | citrix | 2 | · | · | · | PoC 1 | edgesight for endpoints (1) · edgesight for netscaler (1) · edgesight for presentation server (1) | — |