CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-5596

    Last Modified: 23 Apr 2026

    Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for ikonBAnner_AdManager.mdb.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5601

    Last Modified: 23 Apr 2026

    User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for users.mdb.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5607

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 16 Dec 2008
    6.5
    Medium

    CVE-2008-5083

    Last Modified: 21 Nov 2024

    In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5501

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

    Published: 16 Dec 2008
    4.3
    Medium

    CVE-2008-5511

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."

    Published: 16 Dec 2008
    6
    Medium

    CVE-2008-5507

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.

    Published: 16 Dec 2008
    6.8
    Medium

    CVE-2008-5512

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5504

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

    Published: 16 Dec 2008
    10
    Critical

    CVE-2008-5500

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5502

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5505

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

    Published: 16 Dec 2008
    4.3
    Medium

    CVE-2008-5508

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.

    Published: 16 Dec 2008
    5
    Medium

    CVE-2008-5510

    Last Modified: 23 Apr 2026

    The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

    Published: 16 Dec 2008
    4.3
    Medium

    CVE-2008-5513

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.

    Published: 16 Dec 2008
    2.6
    Low

    CVE-2008-5503

    Last Modified: 23 Apr 2026

    The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

    Published: 16 Dec 2008
    6.8
    Medium

    CVE-2008-5506

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."

    Published: 16 Dec 2008
    7.8
    High

    CVE-2008-5620

    Last Modified: 23 Apr 2026

    RoundCube Webmail (roundcubemail) before 0.2-beta allows remote attackers to cause a denial of service (memory consumption) via crafted size parameters that are used to create a large quota image.

    Published: 16 Dec 2008
    7.5
    High

    CVE-2008-5559

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 15 Dec 2008
    5
    Medium

    CVE-2008-5560

    Last Modified: 23 Apr 2026

    PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for postcards.mdb.

    Published: 15 Dec 2008
    5
    Medium

    CVE-2008-5564

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the media server in Orb Networks Orb before 2.01.0025 allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5565

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

    Published: 15 Dec 2008
    4.3
    Medium

    CVE-2008-5566

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5567

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the NewAdmin, NewPass1, and NewPass2 parameters.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5568

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attackers to change the admin password via a logout action in conjunction with the admin_id, newpass_1, and newpass_2 parameters.

    Published: 15 Dec 2008
    5
    Medium

    CVE-2008-5572

    Last Modified: 23 Apr 2026

    Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5573

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) Password and (2) username parameters.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5574

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5575

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Pro Clan Manager 0.4.2 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5576

    Last Modified: 23 Apr 2026

    admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain administrative access via a large value of the current_user[users_level] parameter.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5577

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to execute arbitrary PHP code via a URL in the inc_function parameter.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5580

    Last Modified: 23 Apr 2026

    mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the sFileName argument.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5581

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the sFileName parameter.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5582

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Published: 15 Dec 2008
    4.3
    Medium

    CVE-2008-5584

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ProjectPier 0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a message, (2) a milestone, or (3) a display name in a profile, or the (4) a or (5) c parameter to index.php.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) fiche_product.php and (2) presentation.php.

    Published: 15 Dec 2008
    4.3
    Medium

    CVE-2008-5569

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHPepperShop 1.4 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php or (2) shop/kontakt.php, or (3) shop_kunden_mgmt.php or (4) SHOP_KONFIGURATION.php in shop/Admin/.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5570

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 15 Dec 2008
    5
    Medium

    CVE-2008-5562

    Last Modified: 23 Apr 2026

    ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for xportal.mdb.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5571

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute arbitrary SQL commands via the (1) uname parameter (aka user field) or the (2) psw parameter (aka passwd field). NOTE: some of these details are obtained from third party information.

    Published: 15 Dec 2008
    5
    Medium

    CVE-2008-5579

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read arbitrary files via a full pathname in the sFileName parameter.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5583

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as demonstrated by a delete project action.

    Published: 15 Dec 2008
    7.8
    High

    CVE-2008-5563

    Last Modified: 23 Apr 2026

    Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.x, 3.1.x, 3.2.x, 3.3.1.x, and 3.3.2.x allows remote attackers to cause a denial of service (device crash) via a malformed Extensible Authentication Protocol (EAP) frame.

    Published: 15 Dec 2008
    7.5
    High

    CVE-2008-5578

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to execute arbitrary SQL commands via (1) the f parameter in a showforum action, (2) the u parameter in a profile action, (3) the viewcat parameter, or (4) a combination of scb_uid and scb_ident cookie values.

    Published: 15 Dec 2008
    6.8
    Medium

    CVE-2008-5078

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the (1) recognize_eps_file function (src/psgen.c) and (2) tilde_subst function (src/util.c) in GNU enscript 1.6.1, and possibly earlier, might allow remote attackers to execute arbitrary code via an epsf escape sequence with a long filename.

    Published: 15 Dec 2008
    4.3
    Medium

    CVE-2008-5514

    Last Modified: 23 Apr 2026

    Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.

    Published: 15 Dec 2008
    4.3
    Medium

    CVE-2008-5430

    Last Modified: 23 Apr 2026

    Mozilla Thunderbird 2.0.14 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which might allow remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173.

    Published: 13 Dec 2008
    5.8
    Medium

    CVE-2008-7160

    Last Modified: 23 Apr 2026

    The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect use of a %lu format string.

    Published: 13 Dec 2008
    9.3
    Critical

    CVE-2008-5522

    Last Modified: 23 Apr 2026

    AVG Anti-Virus 8.0.0.161, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

    Published: 12 Dec 2008
    9.3
    Critical

    CVE-2008-5523

    Last Modified: 23 Apr 2026

    avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.

    Published: 12 Dec 2008