CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2008-4941

    Last Modified: 23 Apr 2026

    arb-common 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/arb_fdnaml_*, (b) /tmp/arb_pids_*, (c) /tmp/arbdsmz.html, and (d) /tmp/arbdsmz.htm temporary files, related to the (1) arb_fastdnaml and (2) dszmconnect.pl scripts.

    Published: 5 Nov 2008
    6.9
    Medium

    CVE-2008-4946

    Last Modified: 23 Apr 2026

    convirt 0.8.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/set_output temporary file, related to the (1) _template_/provision.sh, (2) Linux_CD_Install/provision.sh, (3) Fedora_PV_Install/provision.sh, (4) CentOS_PV_Install/provision.sh, (5) common/provision.sh, (6) example/provision.sh, and (7) Windows_CD_Install/provision.sh scripts in image_store/.

    Published: 5 Nov 2008
    6.2
    Medium

    CVE-2008-4955

    Last Modified: 23 Apr 2026

    freevo.real in freevo 1.8.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-#####.pid, (2) /tmp/freevo-gdb, (3) /tmp/freevo-gdb.sh, and (4) /tmp/*.stats temporary files. NOTE: this issue is only a vulnerability when a verbose debug mode is activated by modifying source code.

    Published: 5 Nov 2008
    6.8
    Medium

    CVE-2008-4822

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.

    Published: 5 Nov 2008
    4.3
    Medium

    CVE-2008-4818

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.

    Published: 5 Nov 2008
    6.8
    Medium

    CVE-2008-4819

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.

    Published: 5 Nov 2008
    4.3
    Medium

    CVE-2008-4821

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.

    Published: 5 Nov 2008
    4.3
    Medium

    CVE-2008-4823

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.

    Published: 5 Nov 2008
    10
    Critical

    CVE-2008-5030

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the cddb_read_disc_data function in cddb.c in libcdaudio 0.99.12p2 allows remote CDDB servers to execute arbitrary code via long CDDB data.

    Published: 5 Nov 2008
    7.5
    High

    CVE-2008-4921

    Last Modified: 23 Apr 2026

    board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. NOTE: some of these details are obtained from third party information.

    Published: 4 Nov 2008
    Unknown

    CVE-2008-4920

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate was based on an incorrect claim regarding a directory issue in Agavi. The vendor has disputed the issue and the original researcher has retracted the original claim, so this is not a vulnerability. Further investigation by the vendor and original researcher show that the original issue was in a site-specific modification, which is outside the scope of CVE. Notes: CVE users should not use this identifier

    Published: 4 Nov 2008
    9
    Critical

    CVE-2008-4926

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4927

    Last Modified: 23 Apr 2026

    Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Nov 2008
    5
    Medium

    CVE-2008-4930

    Last Modified: 23 Apr 2026

    MyBB (aka MyBulletinBoard) 1.4.2 does not properly handle an uploaded file with a nonstandard file type that contains HTML sequences, which allows remote attackers to cause that file to be processed as HTML by Internet Explorer's content inspection, aka "Incomplete protection against MIME-sniffing." NOTE: this could be leveraged for XSS and other attacks.

    Published: 4 Nov 2008
    9
    Critical

    CVE-2008-4924

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4918

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and TZ 180 and 190, allows remote attackers to inject arbitrary web script or HTML into arbitrary web sites via a URL to a site that is blocked based on content filtering, which is not properly handled in the CFS block page, aka "universal website hijacking."

    Published: 4 Nov 2008
    8.8
    High

    CVE-2008-4919

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remote attackers to overwrite arbitrary files via a full pathname to the savePageAsBitmap method.

    Published: 4 Nov 2008
    9.3
    Critical

    CVE-2008-4922

    Last Modified: 23 Apr 2026

    Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.

    Published: 4 Nov 2008
    9
    Critical

    CVE-2008-4925

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, DataMatrix.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4928

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the redirect function in functions.php in MyBB (aka MyBulletinBoard) 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the url parameter in a removesubscriptions action to moderation.php, related to use of the ajax option to request a JavaScript redirect. NOTE: this can be leveraged to execute PHP code and bypass cross-site request forgery (CSRF) protection.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4929

    Last Modified: 23 Apr 2026

    MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments, which makes it easier for remote attackers to read these files by guessing filenames.

    Published: 4 Nov 2008
    9
    Critical

    CVE-2008-4923

    Last Modified: 23 Apr 2026

    Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.1 allow remote attackers to overwrite arbitrary files via a full pathname argument to the (1) SaveAsBMP and (2) SaveAsWMF methods.

    Published: 4 Nov 2008
    6.2
    Medium

    CVE-2008-4413

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 and B.11.23, and SMH 2.2.6 and 2.2.8 and earlier on HP-UX B.11.23 and B.11.31, allows local users to gain "unauthorized access" via unknown vectors, possibly related to temporary file permissions.

    Published: 4 Nov 2008
    5
    Medium

    CVE-2008-4913

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary files via a .. (dot dot) in the delete parameter.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4912

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4911

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in read.php in Chattaitaliano Istant-Replay allows remote attackers to execute arbitrary PHP code via a URL in the data parameter.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4909

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in CompactCMS 1.1 and earlier allows remote attackers to perform unauthorized actions as legitimate users via unspecified vectors.

    Published: 4 Nov 2008
    3.3
    Low

    CVE-2008-4908

    Last Modified: 23 Apr 2026

    maps/Info/combine.pl in CrossFire crossfire-maps 1.11.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4895

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Nov 2008
    4.6
    Medium

    CVE-2008-3527

    Last Modified: 23 Apr 2026

    arch/i386/kernel/sysenter.c in the Virtual Dynamic Shared Objects (vDSO) implementation in the Linux kernel before 2.6.21 does not properly check boundaries, which allows local users to gain privileges or cause a denial of service via unspecified vectors, related to the install_special_mapping, syscall, and syscall32_nopage functions.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4891

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4892

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject arbitrary web script or HTML via the mghash parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Nov 2008
    2.6
    Low

    CVE-2008-4893

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the template_path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Nov 2008
    5.1
    Medium

    CVE-2008-4894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10a, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the template_path parameter. NOTE: it was later reported that this issue also affects 5.0.12c.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4906

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.

    Published: 4 Nov 2008
    9.3
    Critical

    CVE-2008-4813

    Last Modified: 23 Apr 2026

    Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allow remote attackers to execute arbitrary code via a crafted PDF document that (1) performs unspecified actions on a Collab object that trigger memory corruption, related to a GetCosObj method; or (2) contains a malformed PDF object that triggers memory corruption during parsing.

    Published: 4 Nov 2008
    9.3
    Critical

    CVE-2008-4814

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in a JavaScript method in Adobe Reader and Acrobat 8.1.2 and earlier, and before 7.1.1, allows remote attackers to execute arbitrary code via unknown vectors, related to an "input validation issue."

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4896

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the art parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4901

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4903

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the leave comment (feedback) feature in Typo 5.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) comment[author] (Name) and (2) comment[url] (Website) parameters.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4905

    Last Modified: 23 Apr 2026

    Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.

    Published: 4 Nov 2008
    4.3
    Medium

    CVE-2008-4898

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action.

    Published: 4 Nov 2008
    6.8
    Medium

    CVE-2008-4899

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors.

    Published: 4 Nov 2008
    7.8
    High

    CVE-2008-2992

    Last Modified: 22 Apr 2026

    Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4815

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan Horse program in an unspecified directory that is associated with an insecure RPATH.

    Published: 4 Nov 2008
    9.3
    Critical

    CVE-2008-4817

    Last Modified: 23 Apr 2026

    The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS function with a long string argument, triggering heap corruption.

    Published: 4 Nov 2008
    6.8
    Medium

    CVE-2008-4897

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the art parameter.

    Published: 4 Nov 2008
    6
    Medium

    CVE-2008-4904

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the "Manage pages" feature (admin/pages) in Typo 5.1.3 and earlier allows remote authenticated users with "blog publisher" rights to execute arbitrary SQL commands via the search[published_at] parameter.

    Published: 4 Nov 2008
    9.3
    Critical

    CVE-2008-4812

    Last Modified: 23 Apr 2026

    Array index error in Adobe Reader and Acrobat, and the Explorer extension (aka AcroRd32Info), 8.1.2, 8.1.1, and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that triggers an out-of-bounds write, related to parsing of Type 1 fonts.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4900

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 4 Nov 2008