CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-5682

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Opera before 9.63 allows remote attackers to inject arbitrary web script or HTML via built-in XSLT templates.

    Published: 19 Dec 2008
    7.8
    High

    CVE-2008-5683

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.63 allows remote attackers to "reveal random data" via unknown vectors.

    Published: 19 Dec 2008
    4.3
    Medium

    CVE-2008-5681

    Last Modified: 23 Apr 2026

    Opera before 9.63 does not block unspecified "scripted URLs" during the feed preview, which allows remote attackers to read existing subscriptions and force subscriptions to arbitrary feed URLs.

    Published: 19 Dec 2008
    9.3
    Critical

    CVE-2008-5680

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL. NOTE: this might overlap CVE-2008-5178.

    Published: 19 Dec 2008
    9.3
    Critical

    CVE-2008-5679

    Last Modified: 23 Apr 2026

    The HTML parsing engine in Opera before 9.63 allows remote attackers to execute arbitrary code via crafted web pages that trigger an invalid pointer calculation and heap corruption.

    Published: 19 Dec 2008
    5
    Medium

    CVE-2009-1271

    Last Modified: 23 Apr 2026

    The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.

    Published: 19 Dec 2008
    7.2
    High

    CVE-2008-5744

    Last Modified: 23 Apr 2026

    Array index error in the dahdi/tor2.c driver in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value in kernel memory by writing to /dev/zap/ctl, related to an incorrect tor2 patch for CVE-2008-5396 that uses the wrong variable in a range check against the value of lc->sync.

    Published: 19 Dec 2008
    2.6
    Low

    CVE-2008-5814

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP, possibly 5.2.7 and earlier, when display_errors is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: because of the lack of details, it is unclear whether this is related to CVE-2006-0208.

    Published: 19 Dec 2008
    10
    Critical

    CVE-2008-5675

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuthTAI."

    Published: 18 Dec 2008
    5
    Medium

    CVE-2008-5676

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."

    Published: 18 Dec 2008
    7.1
    High

    CVE-2008-5677

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root, allows remote authenticated users with upload capability to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under items/, related to the ReplaceBadFilenameChars function in include/ItemAdder.php. NOTE: some of these details are obtained from third party information.

    Published: 18 Dec 2008
    4
    Medium

    CVE-2008-5678

    Last Modified: 23 Apr 2026

    Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

    Published: 18 Dec 2008
    3.5
    Low

    CVE-2008-5666

    Last Modified: 23 Apr 2026

    WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of service via a sequence of FTP sessions that include an invalid "NLST -1" command.

    Published: 18 Dec 2008
    5
    Medium

    CVE-2008-5667

    Last Modified: 23 Apr 2026

    The scanning engine in VirusBlokAda VBA32 Personal Antivirus 3.12.8.x allows remote attackers to cause a denial of service (memory corruption and application crash) via a malformed RAR archive.

    Published: 18 Dec 2008
    4.3
    Medium

    CVE-2008-5668

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section.

    Published: 18 Dec 2008
    5
    Medium

    CVE-2008-5669

    Last Modified: 23 Apr 2026

    index.php in the comments preview section in Textpattern (aka Txp CMS) 4.0.5 allows remote attackers to cause a denial of service via a long message parameter.

    Published: 18 Dec 2008
    6.8
    Medium

    CVE-2008-5670

    Last Modified: 23 Apr 2026

    Textpattern (aka Txp CMS) 4.0.5 does not ask for the old password during a password reset, which makes it easier for remote attackers to change a password after hijacking a session.

    Published: 18 Dec 2008
    9
    Critical

    CVE-2008-5663

    Last Modified: 23 Apr 2026

    Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension using (1) load_receiver.php or (2) a shipainter action to paint_save.php, then accessing the uploaded file via a direct request to this file in their user directory.

    Published: 18 Dec 2008
    9.3
    Critical

    CVE-2008-5664

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows remote attackers to execute arbitrary code via a crafted playlist (PLA) file.

    Published: 18 Dec 2008
    7.5
    High

    CVE-2008-5665

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL commands via the no parameter.

    Published: 18 Dec 2008
    7.5
    High

    CVE-2008-5671

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Joomla! 1.0.11 through 1.0.14, when RG_EMULATION is enabled in configuration.php, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 18 Dec 2008
    6.8
    Medium

    CVE-2008-5672

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in PHParanoid before 0.4 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) admin.php or (2) private messages.

    Published: 18 Dec 2008
    6.5
    Medium

    CVE-2008-5673

    Last Modified: 23 Apr 2026

    PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors.

    Published: 18 Dec 2008
    9.4
    Critical

    CVE-2008-5674

    Last Modified: 23 Apr 2026

    Multiple array index errors in the HTTP server in Darkwet Network webcamXP 3.72.440.0 and earlier and beta 4.05.280 and earlier allow remote attackers to cause a denial of service (device crash) and read portions of memory via (1) an invalid camnum parameter to the pocketpc component and (2) an invalid id parameter to the show_gallery_pic component.

    Published: 18 Dec 2008
    7.2
    High

    CVE-2008-5716

    Last Modified: 23 Apr 2026

    xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405.

    Published: 18 Dec 2008
    6.8
    Medium

    CVE-2008-5660

    Last Modified: 23 Apr 2026

    Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2 and 2.x before 2.24.2 might allow remote attackers to execute arbitrary code via format string specifiers in a crafted URI or VNC server response.

    Published: 17 Dec 2008
    5.4
    Medium

    CVE-2008-5661

    Last Modified: 23 Apr 2026

    The IPv4 Forwarding feature in Sun Solaris 10 and OpenSolaris snv_47 through snv_82, with certain patches installed, allows remote attackers to cause a denial of service (panic) via unknown vectors that trigger a NULL pointer dereference.

    Published: 17 Dec 2008
    4.3
    Medium

    CVE-2008-5656

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the frontend plugin for the felogin system extension in TYPO3 4.2.0, 4.2.1 and 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 17 Dec 2008
    9.3
    Critical

    CVE-2008-5662

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Sun Java Wireless Toolkit (WTK) for CLDC 2.5.2 and earlier allow downloaded programs to execute arbitrary code via unknown vectors.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5657

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Quassel Core before 0.3.0.3 allows remote attackers to spoof IRC messages as other users via a crafted CTCP message.

    Published: 17 Dec 2008
    4.3
    Medium

    CVE-2008-5644

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the file backend module in TYPO3 4.2.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 17 Dec 2008
    7.8
    High

    CVE-2008-5645

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the media server in Orb Networks Orb before 2.01.0022 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP GET request.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5646

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Trac before 0.11.2 allows attackers to cause a denial of service via unknown attack vectors related to "certain wiki markup."

    Published: 17 Dec 2008
    5
    Medium

    CVE-2008-5647

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HTML sanitizer filter in Trac before 0.11.2 allows attackers to conduct phishing attacks via unknown attack vectors.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5651

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in plugins/bookmarker/bookmarker_backend.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the Parent parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5654

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter, a different vector than CVE-2008-1344. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5643

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter in a book_details action to index.php.

    Published: 17 Dec 2008
    10
    Critical

    CVE-2008-5649

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5648

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary SQL commands via the admin_username parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5650

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute arbitrary SQL commands via the pwd parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5655

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Dec 2008
    4.3
    Medium

    CVE-2008-5558

    Last Modified: 23 Apr 2026

    Asterisk Open Source 1.2.26 through 1.2.30.3 and Business Edition B.2.3.5 through B.2.5.5, when realtime IAX2 users are enabled, allows remote attackers to cause a denial of service (crash) via authentication attempts involving (1) an unknown user or (2) a user using hostname matching.

    Published: 17 Dec 2008
    4
    Medium

    CVE-2008-5626

    Last Modified: 23 Apr 2026

    XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument to the NLST command, as demonstrated by a -1 argument.

    Published: 17 Dec 2008
    6.8
    Medium

    CVE-2008-5628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands via the term parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5629

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL commands via the id parameter in a play action.

    Published: 17 Dec 2008
    6.8
    Medium

    CVE-2008-5630

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in merchants/index.php in Post Affiliate Pro 3 and 3.1.4 allows remote attackers to execute arbitrary SQL commands via the umprof_status parameter.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5634

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account.asp in Active Force Matrix 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008
    7.5
    High

    CVE-2008-5635

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters, possibly related to start.asp. NOTE: some of these details are obtained from third party information.

    Published: 17 Dec 2008