CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-4902

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Published: 4 Nov 2008
    7.5
    High

    CVE-2008-4881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4882

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4883

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4884

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4885

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4886

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4879

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in prod.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2008-4880.

    Published: 3 Nov 2008
    4.3
    Medium

    CVE-2008-4888

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4880

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in prodshow.php in Maran PHP Shop allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-4879.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4889

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.

    Published: 3 Nov 2008
    7.5
    High

    CVE-2008-4887

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) profile page (profile.php) or (2) game page (game.php). NOTE: some of these details are obtained from third party information.

    Published: 3 Nov 2008
    6.8
    Medium

    CVE-2008-3868

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Interact 2.4.1 allows remote attackers to hijack the authentication of super administrators for requests that create super administrator accounts.

    Published: 3 Nov 2008
    6.8
    Medium

    CVE-2008-3867

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL commands via the email_user_key parameter.

    Published: 3 Nov 2008
    10
    Critical

    CVE-2008-4910

    Last Modified: 23 Apr 2026

    The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.

    Published: 3 Nov 2008
    5
    Medium

    CVE-2008-5006

    Last Modified: 23 Apr 2026

    smtp.c in the c-client library in University of Washington IMAP Toolkit 2007b allows remote SMTP servers to cause a denial of service (NULL pointer dereference and application crash) by responding to the QUIT command with a close of the TCP connection instead of the expected 221 response code.

    Published: 3 Nov 2008
    6.9
    Medium

    CVE-2008-5987

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python interface in Eye of GNOME (eog) 2.22.3, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 2 Nov 2008
    6.9
    Medium

    CVE-2008-5986

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the (1) "VST plugin with Python scripting" and (2) "VST plugin for writing score generators in Python" in Csound 5.08.2, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 2 Nov 2008
    6.9
    Medium

    CVE-2008-5984

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).

    Published: 2 Nov 2008
    4.6
    Medium

    CVE-2008-5076

    Last Modified: 23 Apr 2026

    htop 0.7 writes process names to a terminal without sanitizing non-printable characters, which might allow local users to hide processes, modify arbitrary files, or have unspecified other impact via a process name with "crazy control strings."

    Published: 2 Nov 2008
    5
    Medium

    CVE-2008-4874

    Last Modified: 23 Apr 2026

    The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service" account with "service" as its password, which makes it easier for remote attackers to obtain access.

    Published: 31 Oct 2008
    6.8
    Medium

    CVE-2008-4875

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a GET request. NOTE: this can be leveraged with CVE-2008-4874 for unauthenticated access to sensitive files such as (1) save.dat and (2) apply.log, which can contain other credentials such as the Skype username and password.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4876

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 allows remote attackers to inject arbitrary web script or HTML via the request URL, which is not properly handled in a 404 web error page.

    Published: 31 Oct 2008
    6.8
    Medium

    CVE-2008-4877

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter. NOTE: some of these details are obtained from third party information.

    Published: 31 Oct 2008
    8.5
    High

    CVE-2008-4878

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the uploaded file.

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4866

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-dependent attackers to have an unknown impact via vectors related to execution of DTS generation code with a delay greater than MAX_REORDER_DELAY.

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4867

    Last Modified: 23 Apr 2026

    Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attackers to have an unknown impact via vectors related to an incorrect DCA_MAX_FRAME_SIZE value.

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4868

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4869

    Last Modified: 23 Apr 2026

    FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to cause a denial of service (memory consumption) via unknown vectors, aka a "Tcp/udp memory leak."

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4873

    Last Modified: 23 Apr 2026

    board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4872

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbitrary web script or HTML via the item_id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4871

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbitrary web script or HTML via BBcode IMG tags.

    Published: 31 Oct 2008
    6.9
    Medium

    CVE-2008-4863

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to an erroneous setting of sys.path by the PySys_SetArgv function.

    Published: 31 Oct 2008
    9.3
    Critical

    CVE-2007-6432

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AldFs32.dll in Adobe PageMaker 7.0.1 and 7.0.2 allows user-assisted remote attackers to execute arbitrary code via a malformed .PMD file, related to "Key Strings," a different vulnerability than CVE-2007-5169 and CVE-2007-5394.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4805

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the community title, (2) API input, and vectors related to the (3) Homepage, (4) Blogs, (5) Profiles, (6) Dogear, (7) Activities, and (8) Global Search components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    7.5
    High

    CVE-2008-4806

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbitrary SQL commands via the sortField parameter to unspecified components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    7.5
    High

    CVE-2008-4810

    Last Modified: 23 Apr 2026

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers to execute arbitrary PHP code via vectors related to templates and (1) a dollar-sign character, aka "php executed in templates;" and (2) a double quoted literal string, aka a "function injection security hole." NOTE: each vector affects slightly different SVN revisions.

    Published: 31 Oct 2008
    7.5
    High

    CVE-2008-4811

    Last Modified: 23 Apr 2026

    The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PHP code via vectors related to templates and a \ (backslash) before a dollar-sign character.

    Published: 31 Oct 2008
    5
    Medium

    CVE-2008-4808

    Last Modified: 23 Apr 2026

    IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-4809

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    2.1
    Low

    CVE-2008-4807

    Last Modified: 23 Apr 2026

    IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allows local users to obtain sensitive information by reading this file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    Unknown

    CVE-2008-6432

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6432. Reason: This candidate is a duplicate of CVE-2007-6432. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2007-6432 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4802

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    7.5
    High

    CVE-2008-4804

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the aid parameter in a showalbum action to index.php. NOTE: some of these details are obtained from third party information. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4803

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Oct 2008
    6.9
    Medium

    CVE-2008-6552

    Last Modified: 23 Apr 2026

    Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

    Published: 31 Oct 2008
    10
    Critical

    CVE-2008-5005

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension argument on the command line to the tmail or dmail program; and (b) remote attackers to execute arbitrary code by sending e-mail to a destination mailbox name composed of a username and '+' character followed by a long string, processed by the tmail or possibly dmail program.

    Published: 31 Oct 2008
    7.5
    High

    CVE-2008-4309

    Last Modified: 28 May 2026

    Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow, related to the number of responses or repeats.

    Published: 31 Oct 2008
    4.3
    Medium

    CVE-2008-4799

    Last Modified: 23 Apr 2026

    pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent attackers to cause a denial of service (crash) via a crafted image file that triggers an out-of-bounds read.

    Published: 30 Oct 2008