CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-4641

    Last Modified: 23 Apr 2026

    The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.

    Published: 15 Oct 2008
    4.6
    Medium

    CVE-2008-4639

    Last Modified: 23 Apr 2026

    jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 15 Oct 2008
    5
    Medium

    CVE-2008-4575

    Last Modified: 23 Apr 2026

    Buffer overflow in the DoCommand function in jhead before 2.84 might allow context-dependent attackers to cause a denial of service (crash) via (1) a long -cmd argument and (2) unspecified vectors related to "a bunch of potential string overflows."

    Published: 15 Oct 2008
    8.8
    High

    CVE-2008-3475

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-3476

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability."

    Published: 15 Oct 2008
    3.6
    Low

    CVE-2008-4640

    Last Modified: 23 Apr 2026

    The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" character is replaced by a "t" character or (2) a final "t" character is replaced by a "z" character.

    Published: 15 Oct 2008
    7.8
    High

    CVE-2008-5025

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the hfs_cat_find_brec function in fs/hfs/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfs filesystem image with an invalid catalog namelength field, a related issue to CVE-2008-4933.

    Published: 15 Oct 2008
    9
    Critical

    CVE-2008-1446

    Last Modified: 23 Apr 2026

    Integer overflow in the Internet Printing Protocol (IPP) ISAPI extension in Microsoft Internet Information Services (IIS) 5.0 through 7.0 on Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to execute arbitrary code via an HTTP POST request that triggers an outbound IPP connection from a web server to a machine operated by the attacker, aka "Integer Overflow in IPP Service Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-3471

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via a BIFF file with a malformed record that triggers a user-influenced size calculation, aka "File Format Parsing Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-3472

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "HTML Element Cross-Domain Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-3473

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, via a crafted HTML document, aka "Event Handling Cross-Domain Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-4019

    Last Modified: 23 Apr 2026

    Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file containing a formula within a cell, aka "Formula Parsing Vulnerability."

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-4038

    Last Modified: 23 Apr 2026

    Buffer underflow in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a Server Message Block (SMB) request that contains a filename with a crafted length, aka "SMB Buffer Underflow Vulnerability."

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-2250

    Last Modified: 23 Apr 2026

    The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability."

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-2251

    Last Modified: 23 Apr 2026

    Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that makes system calls within multiple threads, aka "Windows Kernel Unhandled Exception Vulnerability." NOTE: according to Microsoft, this is not a duplicate of CVE-2008-4510.

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-2252

    Last Modified: 23 Apr 2026

    The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate parameters sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Corruption Vulnerability."

    Published: 15 Oct 2008
    7.2
    High

    CVE-2008-3464

    Last Modified: 23 Apr 2026

    afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly validate input sent from user mode to the kernel, which allows local users to gain privileges via a crafted application, as demonstrated using crafted pointers and lengths that bypass intended ProbeForRead and ProbeForWrite restrictions, aka "AFD Kernel Overwrite Vulnerability."

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-3466

    Last Modified: 23 Apr 2026

    Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."

    Published: 15 Oct 2008
    6.5
    Medium

    CVE-2008-3474

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document, aka "Cross-Domain Information Disclosure Vulnerability."

    Published: 15 Oct 2008
    9.3
    Critical

    CVE-2008-3477

    Last Modified: 23 Apr 2026

    Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containing a crafted value, leading to heap-based buffer overflows, integer overflows, array index errors, and memory corruption, aka "Calendar Object Validation Vulnerability."

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-3479

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters to string APIs, aka "Message Queuing Service Remote Code Execution Vulnerability."

    Published: 15 Oct 2008
    4.3
    Medium

    CVE-2008-4020

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Microsoft Office XP SP3 allows remote attackers to inject arbitrary web script or HTML via a document that contains a "Content-Disposition: attachment" header and is accessed through a cdo: URL, which renders the content instead of raising a File Download dialog box, aka "Vulnerability in Content-Disposition Header Vulnerability."

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-4023

    Last Modified: 23 Apr 2026

    Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."

    Published: 15 Oct 2008
    8.4
    High

    CVE-2008-4036

    Last Modified: 23 Apr 2026

    Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows local users to gain privileges via a crafted application that triggers an erroneous decrement of a variable, related to validation of parameters for Virtual Address Descriptors (VADs) and a "memory allocation mapping error," aka "Virtual Address Descriptor Elevation of Privilege Vulnerability."

    Published: 15 Oct 2008
    10
    Critical

    CVE-2008-4401

    Last Modified: 23 Apr 2026

    ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download API, which allows remote attackers to create a browse dialog box, and possibly have unspecified other impact, via an SWF file.

    Published: 15 Oct 2008
    6.8
    Medium

    CVE-2008-4558

    Last Modified: 23 Apr 2026

    Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary code via an XSPF playlist file with a negative identifier tag, which passes a signed comparison.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4557

    Last Modified: 23 Apr 2026

    plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4556

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4479

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4480

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netware Core Protocol opcode 0x24 message that triggers a calculation error that under-allocates a heap buffer.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4478

    Last Modified: 23 Apr 2026

    Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.

    Published: 14 Oct 2008
    2.1
    Low

    CVE-2008-2588

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 allows local users to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    1.7
    Low

    CVE-2008-2619

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors.

    Published: 14 Oct 2008
    6.5
    Medium

    CVE-2008-2624

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Oct 2008
    4.9
    Medium

    CVE-2008-3980

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Upgrade component in Oracle Database 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Oct 2008
    5.5
    Medium

    CVE-2008-3984

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3983.

    Published: 14 Oct 2008
    1
    Low

    CVE-2008-3986

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Discoverer Administrator component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows local users to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    1
    Low

    CVE-2008-3987

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Discoverer Desktop component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    5
    Medium

    CVE-2008-3988

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the iSupplier Portal component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    5.5
    Medium

    CVE-2008-3992

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Data Mining component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity, related to DMSYS.DBMS_DM_EXP_INTERNAL.

    Published: 14 Oct 2008
    3.5
    Low

    CVE-2008-3993

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 14 Oct 2008
    5.5
    Medium

    CVE-2008-3994

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to WMSYS.LTADM.

    Published: 14 Oct 2008
    5.5
    Medium

    CVE-2008-3995

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_CDC_PUBLISH.

    Published: 14 Oct 2008
    5.5
    Medium

    CVE-2008-3996

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_IPUBLISH.

    Published: 14 Oct 2008
    4.9
    Medium

    CVE-2008-4001

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne EP 8.9 and EP 9.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Oct 2008
    3.5
    Low

    CVE-2008-4002

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    4.3
    Medium

    CVE-2008-4003

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Oct 2008
    3.2
    Low

    CVE-2008-4004

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JDE EnterpriseOne Business Service Server component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.2 and 8.98.0.1 allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Oct 2008
    10
    Critical

    CVE-2008-4008

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.

    Published: 14 Oct 2008
    5.1
    Medium

    CVE-2008-4009

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 9.1, when configuring multiple authorizers, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Oct 2008