CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-4613

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via the sortby parameter.

    Published: 20 Oct 2008
    7.5
    High

    CVE-2008-4614

    Last Modified: 23 Apr 2026

    PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to create and delete forums, topics, and replies.

    Published: 20 Oct 2008
    10
    Critical

    CVE-2008-4615

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in i_utils.asp in PortalApp before 4.01a has unknown impact and attack vectors.

    Published: 20 Oct 2008
    5
    Medium

    CVE-2008-4616

    Last Modified: 23 Apr 2026

    The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a shared key.

    Published: 20 Oct 2008
    7.5
    High

    CVE-2008-4611

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Arsivimiz Php Ziyaretci Defteri allows remote attackers to execute arbitrary SQL commands via the sayfa parameter.

    Published: 20 Oct 2008
    4.3
    Medium

    CVE-2007-6718

    Last Modified: 23 Apr 2026

    MPlayer, possibly 1.0rc1, allows remote attackers to cause a denial of service (SIGSEGV and application crash) via (1) a malformed MP3 file, as demonstrated by lol-mplayer.mp3; (2) a malformed Ogg Vorbis file, as demonstrated by lol-mplayer.ogg; (3) a malformed MPEG-1 file, as demonstrated by lol-mplayer.mpg; (4) a malformed MPEG-2 file, as demonstrated by lol-mplayer.m2v; (5) a malformed MPEG-4 AVI file, as demonstrated by lol-mplayer.avi; (6) a malformed FLAC file, as demonstrated by lol-mplayer.flac; (7) a malformed Ogg Theora file, as demonstrated by lol-mplayer.ogm; (8) a malformed WMV file, as demonstrated by lol-mplayer.wmv; or (9) a malformed AAC file, as demonstrated by lol-mplayer.aac. NOTE: vector 5 might overlap CVE-2007-4938, and vector 6 might overlap CVE-2008-0486.

    Published: 20 Oct 2008
    7.1
    High

    CVE-2008-4609

    Last Modified: 23 Apr 2026

    The TCP implementation in (1) Linux, (2) platforms based on BSD Unix, (3) Microsoft Windows, (4) Cisco products, and probably other operating systems allows remote attackers to cause a denial of service (connection queue exhaustion) via multiple vectors that manipulate information in the TCP state table, as demonstrated by sockstress.

    Published: 20 Oct 2008
    5
    Medium

    CVE-2008-4610

    Last Modified: 23 Apr 2026

    MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) file, as demonstrated by lol-ffplay.ogm, different vectors than CVE-2007-6718.

    Published: 20 Oct 2008
    4.3
    Medium

    CVE-2008-4681

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.

    Published: 20 Oct 2008
    7.5
    High

    CVE-2008-4864

    Last Modified: 23 Apr 2026

    Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent attackers to break out of the Python VM and execute arbitrary code via large integer values in certain arguments to the crop function, leading to a buffer overflow, a different vulnerability than CVE-2007-4965 and CVE-2008-1679.

    Published: 19 Oct 2008
    10
    Critical

    CVE-2008-5031

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function in Objects/stringobject.c and (2) the unicode_expandtabs function in Objects/unicodeobject.c. NOTE: this vulnerability reportedly exists because of an incomplete fix for CVE-2008-2315.

    Published: 19 Oct 2008
    7.5
    High

    CVE-2008-4599

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4600

    Last Modified: 23 Apr 2026

    configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by setting the ValidUserAdmin cookie.

    Published: 17 Oct 2008
    4.3
    Medium

    CVE-2008-4601

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the habari_username parameter.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4605

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) dish.php and (2) menu.php.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4603

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL commands via the keywords parameter in a search_games action.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4604

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL commands via the itemid parameter.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4606

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) location_id parameter to locationdel.php and (2) vlan_id parameter to vlanedit.php. NOTE: the vlanview.php and vlandel.php vectors are already covered by CVE-2007-6579.

    Published: 17 Oct 2008
    6.5
    Medium

    CVE-2008-4602

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and possibly execute arbitrary local files via a .. (dot dot) in the md parameter.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4597

    Last Modified: 23 Apr 2026

    Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via unspecified vectors.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4598

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Shindig-Integrator 5.x, a module for Drupal, has unspecified impact and remote attack vectors related to "numerous flaws" that are not related to XSS or access control, a different vulnerability than CVE-2008-4596 and CVE-2008-4597.

    Published: 17 Oct 2008
    4.3
    Medium

    CVE-2008-4596

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Shindig-Integrator 5.x, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in generated pages.

    Published: 17 Oct 2008
    10
    Critical

    CVE-2008-4595

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Slaytanic Scripts Content Plus 2.1.1 have unknown impact and remote attack vectors.

    Published: 17 Oct 2008
    5
    Medium

    CVE-2008-4412

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00) allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 17 Oct 2008
    1.2
    Low

    CVE-2008-4593

    Last Modified: 23 Apr 2026

    Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is disabled, allows physically proximate attackers to obtain sensitive information by performing an Emergency Call tap and then reading SMS messages on the device screen, aka Apple bug number 6267416.

    Published: 17 Oct 2008
    10
    Critical

    CVE-2008-4594

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SNMPv3 component in Linksys WAP4400N firmware 1.2.14 on the Marvell Semiconductor 88W8361P-BEM1 chipset has unknown impact and attack vectors, probably remote.

    Published: 17 Oct 2008
    9.3
    Critical

    CVE-2008-4473

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.

    Published: 17 Oct 2008
    4.7
    Medium

    CVE-2008-3831

    Last Modified: 23 Apr 2026

    The i915 driver in (1) drivers/char/drm/i915_dma.c in the Linux kernel 2.6.24 on Debian GNU/Linux and (2) sys/dev/pci/drm/i915_drv.c in OpenBSD does not restrict the DRM_I915_HWS_ADDR ioctl to the Direct Rendering Manager (DRM) master, which allows local users to cause a denial of service (memory corruption) via a crafted ioctl call, related to absence of the DRM_MASTER and DRM_ROOT_ONLY flags in the ioctl's configuration.

    Published: 17 Oct 2008
    10
    Critical

    CVE-2008-4619

    Last Modified: 23 Apr 2026

    The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this might be a duplicate of CVE-2007-0165.

    Published: 17 Oct 2008
    7.5
    High

    CVE-2008-4590

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the username parameter to admin/login.php and (2) the post parameter to admin/news.php.

    Published: 16 Oct 2008
    10
    Critical

    CVE-2008-4592

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.

    Published: 16 Oct 2008
    4.3
    Medium

    CVE-2008-4591

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters.

    Published: 16 Oct 2008
    7.5
    High

    CVE-2008-5286

    Last Modified: 23 Apr 2026

    Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

    Published: 16 Oct 2008
    7.5
    High

    CVE-2008-4585

    Last Modified: 23 Apr 2026

    Belong Software Site Builder 0.1 beta allows remote attackers to bypass intended access restrictions and perform administrative actions via a direct request to admin/home.php.

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-4588

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command.

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-4589

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-4587

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods. NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.

    Published: 15 Oct 2008
    7.5
    High

    CVE-2008-4583

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname in the SavePkcs8File method.

    Published: 15 Oct 2008
    6.8
    Medium

    CVE-2008-4584

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname to the SaveLastError method.

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-4586

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method.

    Published: 15 Oct 2008
    4
    Medium

    CVE-2008-4581

    Last Modified: 23 Apr 2026

    The Editor in IBM ENOVIA SmarTeam 5 before release 18 SP5, and release 19 before SP01, allows remote authenticated users to bypass intended access restrictions and read Document objects via the Workflow Process (aka Flow Process) view.

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-4553

    Last Modified: 23 Apr 2026

    qemu-make-debian-root in qemu 0.9.1-5 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on temporary files and directories.

    Published: 15 Oct 2008
    7.5
    High

    CVE-2008-4569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-4572

    Last Modified: 23 Apr 2026

    GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the CWD and LIST commands, which triggers heap corruption related to an improper free call, and possibly triggering a heap-based buffer overflow.

    Published: 15 Oct 2008
    4.3
    Medium

    CVE-2008-4571

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag.

    Published: 15 Oct 2008
    7.5
    High

    CVE-2008-4570

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 15 Oct 2008
    7.5
    High

    CVE-2008-4574

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL commands via the linkid parameter.

    Published: 15 Oct 2008
    7.5
    High

    CVE-2008-4573

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Published: 15 Oct 2008
    7.8
    High

    CVE-2008-4934

    Last Modified: 23 Apr 2026

    The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.

    Published: 15 Oct 2008
    7.8
    High

    CVE-2008-4933

    Last Modified: 23 Apr 2026

    Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function.

    Published: 15 Oct 2008