CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-3726

    Last Modified: 23 Apr 2026

    The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote NFS servers to cause a denial of service (NULL pointer dereference and panic) by sending a certain response containing incorrect file attributes, which trigger attempted use of an open file that lacks NFSv4 state.

    Published: 22 Oct 2008
    9.3
    Critical

    CVE-2008-4664

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in QvodInsert.QvodCtrl.1 ActiveX control (QvodInsert.dll) in QVOD Player before 2.1.5 build 0053 allows remote attackers to execute arbitrary code via a long URL property. NOTE: some of these details are obtained from third party information.

    Published: 22 Oct 2008
    6.8
    Medium

    CVE-2008-4662

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4663

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in analysis.cgi 1.44, as used in K's CGI Access Log Kaiseki (1) jcode.pl and (2) Jcode.pm, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Oct 2008
    9
    Critical

    CVE-2008-4645

    Last Modified: 23 Apr 2026

    plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

    Published: 21 Oct 2008
    2.1
    Low

    CVE-2008-4646

    Last Modified: 23 Apr 2026

    The Websense Reporter Module in Websense Enterprise 6.3.2 stores the SQL database system administrator password in plaintext in CreateDbInstall.log, which allows local users to gain privileges to the database.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4647

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in sweetCMS 1.5.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4648

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO or the (2) option, (3) Itemid, (4) id, (5) task, (6) bid, and (7) contact_id parameters. NOTE: the error might be located in modules/mod_language.php, and index.php might be the interaction point.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4649

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4650

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4644

    Last Modified: 23 Apr 2026

    hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 21 Oct 2008
    9.3
    Critical

    CVE-2008-4654

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player 0.9.0 through 0.9.4 allows remote attackers to execute arbitrary code via a TiVo TY media file with a header containing a crafted size value.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4655

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Simple survey (simplesurvey) 1.7.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4656

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Frontend Users View (feusersview) 0.1.6 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4657

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Econda Plugin (econda) 0.0.2 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4658

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JobControl (dmmjobcontrol) 1.15.4 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4659

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Mannschaftsliste (kiddog_playerlist) 1.0.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    9.3
    Critical

    CVE-2008-4652

    Last Modified: 23 Apr 2026

    Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4643

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4661

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Page Improvements (sm_pageimprovements) 1.1.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Oct 2008
    6
    Medium

    CVE-2008-4651

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4660

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the M1 Intern (m1_intern) 1.0.0 extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4642

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action.

    Published: 21 Oct 2008
    4.6
    Medium

    CVE-2008-3248

    Last Modified: 23 Apr 2026

    qiomkfile in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, does not initialize filesystem blocks during creation of a file, which allows local users to obtain sensitive information by creating and then reading files.

    Published: 21 Oct 2008
    4.6
    Medium

    CVE-2008-4638

    Last Modified: 23 Apr 2026

    qioadmin in the Quick I/O for Database feature in Symantec Veritas File System (VxFS) on HP-UX, and before 5.0 MP3 on Solaris, Linux, and AIX, allows local users to read arbitrary files by causing qioadmin to write a file's content to standard error in an error message.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4637

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cpCommerce before 1.2.4 allows remote attackers to inject arbitrary web script or HTML via unknown vectors in the advanced search feature. NOTE: this is probably a variant of CVE-2008-4121.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2007-4350

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the management interface in HP SiteScope 9.0 build 911 allows remote attackers to inject arbitrary web script or HTML via an SNMP trap message.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4121

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in cpCommerce before 1.2.4 allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter in a search.quick action to search.php and (2) the name parameter in a sendtofriend action to sendtofriend.php.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execute arbitrary SQL commands via the itemID parameter in the RGalleryImageWrapper page in index.php.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4622

    Last Modified: 23 Apr 2026

    The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and gain administrative access by setting the fn-loggedin cookie to 1.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4623

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the DS-Syndicate (com_ds-syndicate) component 1.1.1 for Joomla allows remote attackers to execute arbitrary SQL commands via the feed_id parameter to index2.php.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4625

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4629

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Usagi Project MyNETS 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Oct 2008
    10
    Critical

    CVE-2008-4630

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Midgard Components (MidCOM) Framework before 8.09.1 have unknown impact and attack vectors.

    Published: 21 Oct 2008
    6.8
    Medium

    CVE-2008-4632

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Kure 0.6.3, when magic_quotes_gpc is disabled, allow remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the (1) post and (2) doc parameters.

    Published: 21 Oct 2008
    3.5
    Low

    CVE-2008-4634

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Movable Type 4 through 4.21 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the administrative page, a different vulnerability than CVE-2008-4079.

    Published: 21 Oct 2008
    10
    Critical

    CVE-2008-6079

    Last Modified: 23 Apr 2026

    imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3) JPEG, (4) LBM, (5) PNM, (6) TGA, or (7) XPM file, related to "several heap and stack based buffer overflows - partly due to integer overflows."

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4620

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Meeting Room Booking System (MRBS) before 1.4 allows remote attackers to execute arbitrary SQL commands via the area parameter to (1) month.php, and possibly (2) day.php and (3) week.php.

    Published: 21 Oct 2008
    6
    Medium

    CVE-2008-4633

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 and 6.x before 6.x-1.0, a module for Drupal, when "Allow user to vote again" is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors related to a "previously cast vote."

    Published: 21 Oct 2008
    5
    Medium

    CVE-2008-4635

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa_cart 1.29 and earlier, a module for XOOPS, allows remote attackers to obtain sensitive user information via unknown vectors.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4621

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-4723

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 3.0.1 through 3.0.3 allow remote attackers to inject arbitrary web script or HTML via an ftp:// URL for an HTML document within a (1) JPG, (2) PDF, or (3) TXT file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Oct 2008
    4.3
    Medium

    CVE-2008-1547

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2 (aka build 6.5.7638) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the URL parameter.

    Published: 21 Oct 2008
    10
    Critical

    CVE-2008-4631

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted message. NOTE: some of these details are obtained from third party information.

    Published: 21 Oct 2008
    9.3
    Critical

    CVE-2008-4624

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CFG[CDIR] parameter.

    Published: 21 Oct 2008
    6.8
    Medium

    CVE-2008-4626

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions through 2.3.3-beta0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the album parameter.

    Published: 21 Oct 2008
    7.5
    High

    CVE-2008-4617

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Oct 2008
    4.3
    Medium

    CVE-2008-4612

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PortalApp 4.0 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter to (1) forums.asp and (2) content.asp.

    Published: 20 Oct 2008