CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2008-5038

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence of "Get NCP Extension Information By Name" requests that cause one thread to operate on memory after it has been freed in another thread, which triggers memory corruption, aka Novell Bug 373852.

    Published: 12 Nov 2008
    4.3
    Medium

    CVE-2008-5039

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5040

    Last Modified: 23 Apr 2026

    Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.

    Published: 12 Nov 2008
    9.3
    Critical

    CVE-2008-0017

    Last Modified: 23 Apr 2026

    The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.

    Published: 12 Nov 2008
    9.3
    Critical

    CVE-2008-5013

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that "dynamically unloads itself from an outside JavaScript function," which triggers an access of an expired memory address.

    Published: 12 Nov 2008
    10
    Critical

    CVE-2008-5018

    Last Modified: 23 Apr 2026

    The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

    Published: 12 Nov 2008
    10
    Critical

    CVE-2008-5014

    Last Modified: 23 Apr 2026

    jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.

    Published: 12 Nov 2008
    5
    Medium

    CVE-2008-5016

    Last Modified: 23 Apr 2026

    The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.

    Published: 12 Nov 2008
    4.3
    Medium

    CVE-2008-5019

    Last Modified: 23 Apr 2026

    The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

    Published: 12 Nov 2008
    9.3
    Critical

    CVE-2008-5021

    Last Modified: 23 Apr 2026

    nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5022

    Last Modified: 23 Apr 2026

    The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5024

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

    Published: 12 Nov 2008
    5
    Medium

    CVE-2008-5012

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.

    Published: 12 Nov 2008
    10
    Critical

    CVE-2008-5017

    Last Modified: 23 Apr 2026

    Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.

    Published: 12 Nov 2008
    7.5
    High

    CVE-2008-5023

    Last Modified: 23 Apr 2026

    Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.

    Published: 12 Nov 2008
    5.1
    Medium

    CVE-2008-5015

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

    Published: 12 Nov 2008
    10
    Critical

    CVE-2008-5052

    Last Modified: 23 Apr 2026

    The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger memory corruption, as demonstrated by e4x/extensions/regress-410192.js.

    Published: 12 Nov 2008
    4
    Medium

    CVE-2008-5102

    Last Modified: 23 Apr 2026

    PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.

    Published: 11 Nov 2008
    9.3
    Critical

    CVE-2008-5036

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execute arbitrary code via an an invalid RealText (rt) subtitle file, related to the ParseRealText function in modules/demux/subtitle.c. NOTE: this issue was SPLIT from CVE-2008-5032 on 20081110.

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-5032

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in VideoLAN VLC media player 0.5.0 through 0.9.5 might allow user-assisted attackers to execute arbitrary code via the header of an invalid CUE image file, related to modules/access/vcd/cdrom.c. NOTE: this identifier originally included an issue related to RealText, but that issue has been assigned a separate identifier, CVE-2008-5036.

    Published: 10 Nov 2008
    5
    Medium

    CVE-2008-5035

    Last Modified: 23 Apr 2026

    The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.

    Published: 10 Nov 2008
    6.9
    Medium

    CVE-2008-5034

    Last Modified: 23 Apr 2026

    master-filter in printfilters-ppd 2.13 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filter.debug temporary file. NOTE: the vendor disputes this vulnerability, stating 'this package does not have " possibility of attack with the help of symlinks"'

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-4387

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Simba MDrmSap ActiveX control in mdrmsap.dll in SAP SAPgui allows remote attackers to execute arbitrary code via unknown vectors involving instantiation by Internet Explorer.

    Published: 10 Nov 2008
    4.3
    Medium

    CVE-2008-5011

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to qpconfig_sample.xml, aka SPR CWIR7KMPVP and THES7F9NVR, a different vulnerability than CVE-2008-2163 and CVE-2008-3860.

    Published: 10 Nov 2008
    3.5
    Low

    CVE-2008-5026

    Last Modified: 23 Apr 2026

    Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.

    Published: 10 Nov 2008
    4
    Medium

    CVE-2008-5009

    Last Modified: 23 Apr 2026

    Race condition in the s_xout kernel module in Sun Solstice X.25 9.2, when running on a multiple CPU machine, allows local users to cause a denial of service (panic) via vectors involving reading the /dev/xty file.

    Published: 10 Nov 2008
    10
    Critical

    CVE-2008-5010

    Last Modified: 23 Apr 2026

    in.dhcpd in the DHCP implementation in Sun Solaris 8 through 10, and OpenSolaris before snv_103, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unknown DHCP requests related to the "number of offers," aka Bug ID 6713805.

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-5008

    Last Modified: 23 Apr 2026

    Buffer overflow in src/src_sinc.c in Secret Rabbit Code (aka SRC or libsamplerate) before 0.1.4, when "extreme low conversion ratios" are used, allows user-assisted attackers to have an unknown impact via a crafted audio file.

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-5002

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-5001

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in multiple functions in vncviewer/FileTransfer.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified parameters, a different issue than CVE-2008-0610.

    Published: 10 Nov 2008
    7.2
    High

    CVE-2008-4831

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.

    Published: 10 Nov 2008
    6.8
    Medium

    CVE-2008-5000

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via uppercase characters in the news_id parameter.

    Published: 10 Nov 2008
    7.5
    High

    CVE-2008-5003

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 10 Nov 2008
    7.5
    High

    CVE-2008-5004

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbitrary SQL commands via a crafted cookie.

    Published: 10 Nov 2008
    9.3
    Critical

    CVE-2008-4281

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.

    Published: 10 Nov 2008
    7.1
    High

    CVE-2008-4820

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

    Published: 10 Nov 2008
    6.9
    Medium

    CVE-2008-4915

    Last Modified: 23 Apr 2026

    The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when running 32-bit and 64-bit guest operating systems, does not properly handle the Trap flag, which allows authenticated guest OS users to gain privileges on the guest OS.

    Published: 10 Nov 2008
    5.9
    Medium

    CVE-2008-4989

    Last Modified: 23 Apr 2026

    The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).

    Published: 10 Nov 2008
    7.8
    High

    CVE-2008-4999

    Last Modified: 23 Apr 2026

    Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able to reliably reproduce the issue.

    Published: 7 Nov 2008
    5.5
    Medium

    CVE-2008-4996

    Last Modified: 23 Apr 2026

    init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE: the vendor disputes this vulnerability, stating that "init is [used in] a single-user context; there's no possibility that this is exploitable.

    Published: 7 Nov 2008
    6.9
    Medium

    CVE-2008-4997

    Last Modified: 23 Apr 2026

    dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely "an EXAMPLE used in the manpage.

    Published: 7 Nov 2008
    6.9
    Medium

    CVE-2008-4998

    Last Modified: 23 Apr 2026

    postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid.

    Published: 7 Nov 2008
    6.9
    Medium

    CVE-2008-4995

    Last Modified: 23 Apr 2026

    redirect.pl in bk2site 1.1.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/redirect.log temporary file. NOTE: this vulnerability is only limited to debug mode, which is disabled by default.

    Published: 7 Nov 2008
    6.9
    Medium

    CVE-2008-4994

    Last Modified: 23 Apr 2026

    The (1) ncsarmt and (2) ncsawrap scripts in xmcd 2.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.*pid temporary file.

    Published: 7 Nov 2008
    7.2
    High

    CVE-2008-4414

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vectors.

    Published: 7 Nov 2008
    4.6
    Medium

    CVE-2008-4992

    Last Modified: 23 Apr 2026

    The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors.

    Published: 7 Nov 2008
    7.5
    High

    CVE-2008-4991

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in LOCKON CO.,LTD. EC-CUBE 2.3.0 and earlier, 1.4.7 and earlier, and 1.5.0-beta2 and earlier; and Community Edition 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the parameter.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4975

    Last Modified: 23 Apr 2026

    mkmailpost in newsgate 1.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mmp##### temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4985

    Last Modified: 23 Apr 2026

    vdrleaktest in Video Disk Recorder (aka vdr-dbg or vdr) 1.6.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/memleaktest.log temporary file.

    Published: 6 Nov 2008
    6.9
    Medium

    CVE-2008-4984

    Last Modified: 23 Apr 2026

    scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (1) dpkg-checkbuilddeps and (2) sb2-check-pkg-mappings scripts.

    Published: 6 Nov 2008