CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-5176

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Client Software WinCom LPD Total 3.0.2.623 and earlier allow remote attackers to execute arbitrary code via (1) a long 0x02 command to the remote administration service on TCP port 13500 or (2) a long invalid control filename to LPDService.exe on TCP port 515.

    Published: 20 Nov 2008
    5.3
    Medium

    CVE-2008-5180

    Last Modified: 23 Apr 2026

    Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of service (memory consumption) via a large number of SIP INVITE requests, which trigger the creation of many sessions.

    Published: 20 Nov 2008
    4.9
    Medium

    CVE-2008-5300

    Last Modified: 23 Apr 2026

    Linux kernel 2.6.28 allows local users to cause a denial of service ("soft lockup" and process loss) via a large number of sendmsg function calls, which does not block during AF_UNIX garbage collection and triggers an OOM condition, a different vulnerability than CVE-2008-5029.

    Published: 20 Nov 2008
    7.5
    High

    CVE-2008-5163

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewarticle.php and (2) viewarticle2.php.

    Published: 19 Nov 2008
    4.3
    Medium

    CVE-2008-5164

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) viewarticle.php and (b) viewarticle2.php and the (2) PATH_INFO to viewarticle.php.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5165

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5170

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

    Published: 19 Nov 2008
    9
    Critical

    CVE-2008-5173

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in testMaker before 3.0p16 allows remote authenticated users to execute arbitrary PHP code via unspecified attack vectors.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5174

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL commands via the jokeid parameter.

    Published: 19 Nov 2008
    9.3
    Critical

    CVE-2008-5167

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5169

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbitrary SQL commands via the drinkid parameter.

    Published: 19 Nov 2008
    4.3
    Medium

    CVE-2008-5172

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5166

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.

    Published: 19 Nov 2008
    7.5
    High

    CVE-2008-5168

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL commands via the tipid parameter.

    Published: 19 Nov 2008
    9.3
    Critical

    CVE-2008-5171

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) DB, (2) lang, and (3) skin parameters.

    Published: 19 Nov 2008
    9.3
    Critical

    CVE-2008-5175

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

    Published: 19 Nov 2008
    6.9
    Medium

    CVE-2008-5303

    Last Modified: 23 Apr 2026

    Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5302 due to affected versions.

    Published: 19 Nov 2008
    6.9
    Medium

    CVE-2008-5302

    Last Modified: 23 Apr 2026

    Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827. NOTE: this is a regression error related to CVE-2005-0448. It is different from CVE-2008-5303 due to affected versions.

    Published: 19 Nov 2008
    3.7
    Low

    CVE-2008-5161

    Last Modified: 28 May 2026

    Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.

    Published: 19 Nov 2008
    10
    Critical

    CVE-2008-5159

    Last Modified: 23 Apr 2026

    Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-5160

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with the HTTP GET, DELETE, OPTIONS, and possibly other methods, related to a "204 No Content error."

    Published: 18 Nov 2008
    7.5
    High

    CVE-2008-5158

    Last Modified: 23 Apr 2026

    Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vectors involving "simply skipping the auth stage."

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5137

    Last Modified: 23 Apr 2026

    tkman in tkman 2.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/tkman##### or (2) /tmp/ll temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5139

    Last Modified: 23 Apr 2026

    updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5136

    Last Modified: 23 Apr 2026

    tkusr in tkusr 0.82 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/tkusr.pgm temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5143

    Last Modified: 23 Apr 2026

    mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5144

    Last Modified: 23 Apr 2026

    nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvidia-cg-toolkit-manifest temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5146

    Last Modified: 23 Apr 2026

    add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5147

    Last Modified: 23 Apr 2026

    test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5149

    Last Modified: 23 Apr 2026

    fwd_check.sh in libncbi6 6.1.20080302 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5152

    Last Modified: 23 Apr 2026

    inmail-show in mh-book 200605 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/inmail#####.log or (2) /tmp/inmail#####.stdin temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5154

    Last Modified: 23 Apr 2026

    bluetooth.rc in p3nfs 5.19 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/blue.log temporary file.

    Published: 18 Nov 2008
    9.3
    Critical

    CVE-2008-5155

    Last Modified: 23 Apr 2026

    mail2sms.sh in smsclient 2.0.8z allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/header.##### or (2) /tmp/body.##### temporary file, or append data to arbitrary files via a symlink attack on the (3) /tmp/sms.log temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5156

    Last Modified: 23 Apr 2026

    si_mkbootserver in systemimager-server 3.6.3 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.inetd.conf or (2) /tmp/pxe.conf.*.tmp temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5157

    Last Modified: 23 Apr 2026

    tau 2.16.4 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/makefile.tau.*.##### or (2) /tmp/makefile.tau*.##### temporary file, related to the (a) tau_cxx, (b) tau_f90, and (c) tau_cc scripts.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5151

    Last Modified: 23 Apr 2026

    test_parser.py in mayavi 1.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/err.log temporary file.

    Published: 18 Nov 2008
    5.8
    Medium

    CVE-2008-5133

    Last Modified: 23 Apr 2026

    ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5141

    Last Modified: 23 Apr 2026

    flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.

    Published: 18 Nov 2008
    6.2
    Medium

    CVE-2008-5135

    Last Modified: 23 Apr 2026

    os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file. NOTE: the vendor disputes this issue, stating "the insecure code path should only ever run inside a d-i environment, which has no non-root users.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5142

    Last Modified: 23 Apr 2026

    sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5140

    Last Modified: 23 Apr 2026

    trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5145

    Last Modified: 23 Apr 2026

    ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.

    Published: 18 Nov 2008
    6.9
    Medium

    CVE-2008-5150

    Last Modified: 23 Apr 2026

    sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-5128

    Last Modified: 23 Apr 2026

    Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-5130

    Last Modified: 23 Apr 2026

    Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12cal.mdb.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-5127

    Last Modified: 23 Apr 2026

    Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-5129

    Last Modified: 23 Apr 2026

    Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12poll.mdb.

    Published: 18 Nov 2008
    7.5
    High

    CVE-2008-5131

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).

    Published: 18 Nov 2008
    7.5
    High

    CVE-2008-5132

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

    Published: 18 Nov 2008
    4.3
    Medium

    CVE-2008-5126

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

    Published: 18 Nov 2008