CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-7248

    Last Modified: 23 Apr 2026

    Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain.

    Published: 18 Nov 2008
    5
    Medium

    CVE-2008-6059

    Last Modified: 23 Apr 2026

    xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

    Published: 18 Nov 2008
    7.5
    High

    CVE-2008-5122

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.

    Published: 18 Nov 2008
    6.4
    Medium

    CVE-2008-5117

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 18 Nov 2008
    4.3
    Medium

    CVE-2008-5118

    Last Modified: 23 Apr 2026

    Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."

    Published: 18 Nov 2008
    4.3
    Medium

    CVE-2008-5119

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Published: 18 Nov 2008
    10
    Critical

    CVE-2008-5120

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

    Published: 18 Nov 2008
    6.8
    Medium

    CVE-2008-5125

    Last Modified: 23 Apr 2026

    admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

    Published: 18 Nov 2008
    4.3
    Medium

    CVE-2008-5114

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Nov 2008
    6.8
    Medium

    CVE-2008-5115

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.

    Published: 18 Nov 2008
    7.8
    High

    CVE-2008-5116

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.

    Published: 18 Nov 2008
    7.2
    High

    CVE-2008-5121

    Last Modified: 23 Apr 2026

    dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

    Published: 18 Nov 2008
    6.8
    Medium

    CVE-2008-5123

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

    Published: 18 Nov 2008
    7.5
    High

    CVE-2008-5124

    Last Modified: 23 Apr 2026

    JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

    Published: 18 Nov 2008
    4.3
    Medium

    CVE-2008-5277

    Last Modified: 23 Apr 2026

    PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.

    Published: 18 Nov 2008
    10
    Critical

    CVE-2006-5269

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, probably related to an RPC interface.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2006-5268

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via vectors related to obtaining "administrative access to the RPC interface."

    Published: 17 Nov 2008
    10
    Critical

    CVE-2007-0072

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a read operation over RPC.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2007-0073

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a file read operation over RPC.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2007-0074

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a folder read operation over RPC.

    Published: 17 Nov 2008
    4.7
    Medium

    CVE-2008-5111

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the socket function in Sun Solaris 10 and OpenSolaris snv_57 through snv_91, when InfiniBand hardware is not installed, allows local users to cause a denial of service (panic) via unknown vectors, related to the socksdpv_close function.

    Published: 17 Nov 2008
    5
    Medium

    CVE-2008-5112

    Last Modified: 23 Apr 2026

    The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a failed bind attempt depending on whether the user account exists and is permitted to login, which allows remote attackers to enumerate valid usernames via a series of LDAP bind requests, as demonstrated by ldapuserenum.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-0013

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0014.

    Published: 17 Nov 2008
    9
    Critical

    CVE-2008-4415

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Service Manager (HPSM) before 7.01.71 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 17 Nov 2008
    6.9
    Medium

    CVE-2008-4832

    Last Modified: 23 Apr 2026

    rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-0014

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0012 and CVE-2008-0013.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-0012

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-2008-0013 and CVE-2008-0014.

    Published: 17 Nov 2008
    6.8
    Medium

    CVE-2008-5108

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors.

    Published: 17 Nov 2008
    1.9
    Low

    CVE-2008-3644

    Last Modified: 23 Apr 2026

    Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.

    Published: 17 Nov 2008
    7.2
    High

    CVE-2008-5103

    Last Modified: 23 Apr 2026

    The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.

    Published: 17 Nov 2008
    7.2
    High

    CVE-2008-5104

    Last Modified: 23 Apr 2026

    Ubuntu 6.06 LTS, 7.10, 8.04 LTS, and 8.10, when installed as a virtual machine by (1) python-vm-builder or (2) ubuntu-vm-builder in VMBuilder 0.9 in Ubuntu 8.10, have ! (exclamation point) as the default root password, which allows attackers to bypass intended login restrictions.

    Published: 17 Nov 2008
    5
    Medium

    CVE-2008-5105

    Last Modified: 23 Apr 2026

    KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (4) MKD, (5) RMD, (6) RETR, (7) RNFR, (8) RNTO, (9) SIZE, and (10) STOR commands.

    Published: 17 Nov 2008
    1.9
    Low

    CVE-2008-5107

    Last Modified: 23 Apr 2026

    The installation process for Citrix Presentation Server 4.5 and Desktop Server 1.0, when MSI logging is enabled, stores database credentials in MSI log files, which allows local users to obtain these credentials by reading the log files.

    Published: 17 Nov 2008
    4.3
    Medium

    CVE-2008-4216

    Last Modified: 23 Apr 2026

    The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."

    Published: 17 Nov 2008
    4.6
    Medium

    CVE-2008-5099

    Last Modified: 23 Apr 2026

    Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-5100

    Last Modified: 23 Apr 2026

    The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.

    Published: 17 Nov 2008
    9.3
    Critical

    CVE-2008-3623

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows, in iPhone OS 1.0 through 2.2.1, and in iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.

    Published: 17 Nov 2008
    4.3
    Medium

    CVE-2008-5098

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-5106

    Last Modified: 23 Apr 2026

    Buffer overflow in KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to an arbitrary command, which triggers the overflow when the SamyFtp.binlog log file is viewed in the management console. NOTE: this may overlap CVE-2006-0441 and CVE-2006-2212.

    Published: 17 Nov 2008
    4.3
    Medium

    CVE-2008-5363

    Last Modified: 23 Apr 2026

    The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not validate character elements during retrieval from the dictionary data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF file.

    Published: 17 Nov 2008
    4.3
    Medium

    CVE-2008-5362

    Last Modified: 23 Apr 2026

    The DefineConstantPool action in the ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, accepts an untrusted input value for a "constant count," which allows remote attackers to read sensitive data from process memory via a crafted PDF file.

    Published: 17 Nov 2008
    7.8
    High

    CVE-2008-4225

    Last Modified: 23 Apr 2026

    Integer overflow in the xmlBufferResize function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (infinite loop) via a large XML document.

    Published: 17 Nov 2008
    10
    Critical

    CVE-2008-4226

    Last Modified: 23 Apr 2026

    Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.

    Published: 17 Nov 2008
    5
    Medium

    CVE-2011-0755

    Last Modified: 11 Apr 2025

    Integer overflow in the mt_rand function in PHP before 5.3.4 might make it easier for context-dependent attackers to predict the return values by leveraging a script's use of a large max parameter, as demonstrated by a value that exceeds mt_getrandmax.

    Published: 17 Nov 2008
    4.3
    Medium

    CVE-2008-5361

    Last Modified: 23 Apr 2026

    The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element's size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file.

    Published: 17 Nov 2008
    9.3
    Critical

    CVE-2008-4824

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0 allow remote attackers to execute arbitrary code via unknown vectors related to "input validation errors."

    Published: 17 Nov 2008
    9.3
    Critical

    CVE-2008-5110

    Last Modified: 23 Apr 2026

    syslog-ng does not call chdir when it calls chroot, which might allow attackers to escape the intended jail. NOTE: this is only a vulnerability when a separate vulnerability is present. This flaw affects syslog-ng versions prior to and including 2.0.9.

    Published: 17 Nov 2008
    7.2
    High

    CVE-2012-0028

    Last Modified: 11 Apr 2025

    The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child process.

    Published: 15 Nov 2008
    7.5
    High

    CVE-2008-5183

    Last Modified: 23 Apr 2026

    cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.

    Published: 15 Nov 2008
    6.9
    Medium

    CVE-2008-5182

    Last Modified: 23 Apr 2026

    The inotify functionality in Linux kernel 2.6 before 2.6.28-rc5 might allow local users to gain privileges via unknown vectors related to race conditions in inotify watch removal and umount.

    Published: 15 Nov 2008