CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2008-4214

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.

    Published: 10 Oct 2008
    4.3
    Medium

    CVE-2008-4533

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Kantan WEB Server 1.8 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 10 Oct 2008
    6.8
    Medium

    CVE-2008-3646

    Last Modified: 23 Apr 2026

    The Postfix configuration file in Mac OS X 10.5.5 causes Postfix to be network-accessible when mail is sent from a local command-line tool, which allows remote attackers to send mail to local Mac OS X users.

    Published: 10 Oct 2008
    9.3
    Critical

    CVE-2008-3647

    Last Modified: 23 Apr 2026

    Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.

    Published: 10 Oct 2008
    7.5
    High

    CVE-2008-4519

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Fastpublish CMS 1.9999 d allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the target parameter to (1) index2.php and (2) index.php.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4521

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4522

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the src parameter to (1) listen.php and (2) download.php.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4523

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the user_name parameter.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4524

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3 allows remote attackers to execute arbitrary SQL commands via the user_name parameter.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4527

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in recept.php in the Recepies (Recept) module 1.1 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the kat_id parameter in a kategorier action. NOTE: some of these details are obtained from third party information.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4528

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id parameter in an edit action.

    Published: 9 Oct 2008
    3.5
    Low

    CVE-2008-4530

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote authenticated users with permissions to inject arbitrary web script or HTML via unspecified vectors related to posting of answers.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4531

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Brilliant Gallery 5.x before 5.x-4.2, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to queries. NOTE: this might be the same issue as CVE-2008-4338.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4529

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP code via a URL in the _ENV[asicms][path] parameter to (1) Association.php, (2) BigMath.php, (3) DiffieHellman.php, (4) DumbStore.php, (5) Extension.php, (6) FileStore.php, (7) HMAC.php, (8) MemcachedStore.php, (9) Message.php, (10) Nonce.php, (11) SQLStore.php, (12) SReg.php, (13) TrustRoot.php, and (14) URINorm.php in classes/Auth/OpenID/; and (15) XRDS.php, (16) XRI.php and (17) XRIRes.php in classes/Auth/Yadis/.

    Published: 9 Oct 2008
    4.3
    Medium

    CVE-2008-4532

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MaxiScript Website Directory allows remote attackers to inject arbitrary web script or HTML via the keyword parameter in a search action.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4517

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4518

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbitrary SQL commands via the (1) sprache parameter to index2.php and the (2) artikel parameter to index.php.

    Published: 9 Oct 2008
    4.3
    Medium

    CVE-2008-4520

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in bulk_update.pl in AutoNessus before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the remark parameter.

    Published: 9 Oct 2008
    10
    Critical

    CVE-2008-4526

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and (6) pages/poll.php.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4525

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.

    Published: 9 Oct 2008
    6.8
    Medium

    CVE-2008-4504

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Mplayer.exe in Herosoft Inc. Hero DVD Player 3.0.8 allows user-assisted remote attackers to execute arbitrary code via an M3u file with a "long entry." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Oct 2008
    7.8
    High

    CVE-2008-4505

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) might allow attackers to cause a denial of service (system crash) via a "nonstandard URL argument" to the OpenDocument command. NOTE: due to lack of details from the vendor, it is not clear whether this is a vulnerability.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4506

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" via unknown vectors.

    Published: 9 Oct 2008
    5
    Medium

    CVE-2008-4512

    Last Modified: 23 Apr 2026

    ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.

    Published: 9 Oct 2008
    4.3
    Medium

    CVE-2008-4513

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BBcode API module in Phorum 5.2.8 allows remote attackers to inject arbitrary web script or HTML via nested BBcode image tags.

    Published: 9 Oct 2008
    5
    Medium

    CVE-2008-4514

    Last Modified: 23 Apr 2026

    The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a font tag with a long color value, which triggers an assertion error.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4515

    Last Modified: 23 Apr 2026

    Blue Coat K9 Web Protection 4.0.230 Beta relies on client-side JavaScript as a protection mechanism, which allows remote attackers to bypass authentication and access the (1) summary, (2) detail, (3) overrides, and (4) pwemail pages by disabling JavaScript.

    Published: 9 Oct 2008
    7.8
    High

    CVE-2008-4508

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. NOTE: this is probably a different vulnerability than CVE-2005-2210.

    Published: 9 Oct 2008
    10
    Critical

    CVE-2008-4509

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the root directory.

    Published: 9 Oct 2008
    5
    Medium

    CVE-2008-4511

    Last Modified: 23 Apr 2026

    Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4516

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4507

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author via unknown vectors.

    Published: 9 Oct 2008
    4.9
    Medium

    CVE-2008-4510

    Last Modified: 23 Apr 2026

    Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.

    Published: 9 Oct 2008
    4.3
    Medium

    CVE-2008-3271

    Last Modified: 23 Apr 2026

    Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.

    Published: 9 Oct 2008
    9.3
    Critical

    CVE-2008-5101

    Last Modified: 23 Apr 2026

    Buffer overflow in the BMP reader in OptiPNG 0.6 and 0.6.1 allows user-assisted attackers to execute arbitrary code via a crafted BMP image, related to an "array overflow."

    Published: 9 Oct 2008
    10
    Critical

    CVE-2008-3641

    Last Modified: 23 Apr 2026

    The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via crafted pen width and pen color opcodes that overwrite arbitrary memory.

    Published: 9 Oct 2008
    10
    Critical

    CVE-2008-4690

    Last Modified: 23 Apr 2026

    lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-3639

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the read_rle16 function in imagetops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via an SGI image with malformed Run Length Encoded (RLE) data containing a small image and a large row count.

    Published: 9 Oct 2008
    4.6
    Medium

    CVE-2008-4554

    Last Modified: 23 Apr 2026

    The do_splice_from function in fs/splice.c in the Linux kernel before 2.6.27 does not reject file descriptors that have the O_APPEND flag set, which allows local users to bypass append mode and make arbitrary changes to other locations in the file.

    Published: 9 Oct 2008
    2.6
    Low

    CVE-2010-0650

    Last Modified: 11 Apr 2025

    WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.

    Published: 9 Oct 2008
    6.8
    Medium

    CVE-2008-3640

    Last Modified: 23 Apr 2026

    Integer overflow in the WriteProlog function in texttops in CUPS before 1.3.9 allows remote attackers to execute arbitrary code via a crafted PostScript file that triggers a heap-based buffer overflow.

    Published: 9 Oct 2008
    7.5
    High

    CVE-2008-4496

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.

    Published: 8 Oct 2008
    7.5
    High

    CVE-2008-4497

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.

    Published: 8 Oct 2008
    7.5
    High

    CVE-2008-4498

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 8 Oct 2008
    9.3
    Critical

    CVE-2008-4499

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) refer parameter to main.php and the (2) file parameter to edit.php.

    Published: 8 Oct 2008
    4
    Medium

    CVE-2008-4500

    Last Modified: 23 Apr 2026

    Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted stou command, probably related to MS-DOS device names, as demonstrated using "con:1".

    Published: 8 Oct 2008
    7.5
    High

    CVE-2008-4495

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL commands via the v_cat parameter.

    Published: 8 Oct 2008
    7.5
    High

    CVE-2008-4494

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 Oct 2008
    10
    Critical

    CVE-2008-4502

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to execute arbitrary PHP code via a URL in the DFF_config[dir_include] parameter to (1) DFF_affiliate_client_API.php, (2) DFF_featured_prdt.func.php, (3) DFF_mer.func.php, (4) DFF_mer_prdt.func.php, (5) DFF_paging.func.php, (6) DFF_rss.func.php, and (7) DFF_sku.func.php in include/.

    Published: 8 Oct 2008
    9
    Critical

    CVE-2008-4501

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite or create arbitrary files via a ..\ (dot dot backslash) in the RNTO command.

    Published: 8 Oct 2008