CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2008-3814

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Unity 4.x before 4.2(1)ES161, 5.x before 5.0(1)ES53, and 7.x before 7.0(2)ES8, when using anonymous authentication (aka native Unity authentication), allows remote attackers to bypass authentication and read or modify system configuration parameters by going to a specific link more than once.

    Published: 8 Oct 2008
    6.8
    Medium

    CVE-2008-4493

    Last Modified: 23 Apr 2026

    Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Edition, allows remote attackers to force the upload of arbitrary files by using the AddString and Post methods and a modified PostURL to construct an HTTP POST request. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.

    Published: 8 Oct 2008
    5
    Medium

    CVE-2008-4491

    Last Modified: 23 Apr 2026

    Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores draft copies of S/MIME email in plaintext on the email server, which allows server owners and remote man-in-the-middle attackers to read sensitive mail.

    Published: 8 Oct 2008
    7.5
    High

    CVE-2008-4492

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands via the usNick cookie.

    Published: 8 Oct 2008
    4.3
    Medium

    CVE-2008-4481

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Redmine 0.7.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Oct 2008
    7.8
    High

    CVE-2008-4482

    Last Modified: 23 Apr 2026

    The XML parser in Xerces-C++ before 3.0.0 allows context-dependent attackers to cause a denial of service (stack consumption and crash) via an XML schema definition with a large maxOccurs value, which triggers excessive memory consumption during validation of an XML file.

    Published: 8 Oct 2008
    4.3
    Medium

    CVE-2008-4485

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the ICAP patience page in Blue Coat Security Gateway OS (SGOS) 4.2 before 4.2.9, 5.2 before 5.2.5, and 5.3 before 5.3.1.7 allows remote attackers to inject arbitrary web script or HTML via the URL.

    Published: 8 Oct 2008
    4.3
    Medium

    CVE-2008-4488

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ap-pages.php in Atarone CMS 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Oct 2008
    10
    Critical

    CVE-2008-4489

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme_chosen parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Oct 2008
    5.1
    Medium

    CVE-2008-4490

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in config.inc.php in phpAbook 0.8.8b and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the userInfo cookie.

    Published: 8 Oct 2008
    6.8
    Medium

    CVE-2008-4484

    Last Modified: 23 Apr 2026

    main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstrated via index.php.

    Published: 8 Oct 2008
    6.8
    Medium

    CVE-2008-4487

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Oct 2008
    6.8
    Medium

    CVE-2008-4483

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Crux Gallery 1.32 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the theme parameter.

    Published: 8 Oct 2008
    10
    Critical

    CVE-2008-4486

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

    Published: 8 Oct 2008
    4.3
    Medium

    CVE-2008-4582

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

    Published: 8 Oct 2008
    8.5
    High

    CVE-2008-4555

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the push_subg function in parser.y (lib/graph/parser.c) in Graphviz 2.20.2, and possibly earlier versions, allows user-assisted remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a DOT file with a large number of Agraph_t elements.

    Published: 8 Oct 2008
    1.9
    Low

    CVE-2008-4579

    Last Modified: 23 Apr 2026

    The (1) fence_apc and (2) fence_apc_snmp programs, as used in (a) fence 2.02.00-r1 and possibly (b) cman, when running in verbose mode, allows local users to append to arbitrary files via a symlink attack on the apclog temporary file.

    Published: 8 Oct 2008
    4.3
    Medium

    CVE-2008-3061

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the to parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-3063

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter.

    Published: 7 Oct 2008
    7.2
    High

    CVE-2008-4477

    Last Modified: 23 Apr 2026

    alert.d/test.alert in mon 0.99.2 allows local users to overwrite arbitrary files via a symlink attack on the test.alert.log temporary file.

    Published: 7 Oct 2008
    5
    Medium

    CVE-2008-3060

    Last Modified: 23 Apr 2026

    V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message.

    Published: 7 Oct 2008
    7.2
    High

    CVE-2008-4475

    Last Modified: 23 Apr 2026

    ibackup 2.27 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 7 Oct 2008
    6.9
    Medium

    CVE-2008-4476

    Last Modified: 23 Apr 2026

    sympa.pl in sympa 5.3.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sympa_aliases.$$ temporary file. NOTE: wwsympa.fcgi was also reported, but the issue occurred in a dead function, so it is not a vulnerability.

    Published: 7 Oct 2008
    Unknown

    CVE-2008-4422

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-4409. Reason: This candidate is a duplicate of CVE-2008-4409. Notes: All CVE users should reference CVE-2008-4409 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Oct 2008
    4.3
    Medium

    CVE-2008-4393

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.

    Published: 7 Oct 2008
    7.8
    High

    CVE-2008-4421

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the URL.

    Published: 7 Oct 2008
    7.8
    High

    CVE-2008-3543

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NFS / ONCplus B.11.31_04 and earlier on HP-UX B.11.31 allows remote attackers to cause a denial of service via unknown attack vectors.

    Published: 7 Oct 2008
    9.3
    Critical

    CVE-2008-4384

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and iseemedia, allow remote attackers to execute arbitrary code via the (1) url, (2) toolbar, and (3) enableZoomPastMax methods.

    Published: 7 Oct 2008
    9.3
    Critical

    CVE-2008-4471

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via "..\" sequences in the argument to the SaveAS method.

    Published: 7 Oct 2008
    9.3
    Critical

    CVE-2008-4472

    Last Modified: 23 Apr 2026

    The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to execute arbitrary programs via the second argument to the ApplyPatch method.

    Published: 7 Oct 2008
    5
    Medium

    CVE-2008-3829

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of service (crash) via unknown vectors.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4460

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the game_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4461

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote attackers to execute arbitrary SQL commands via the fage parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4462

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4463

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4464

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_mags.php in Vastal I-Tech Mag Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4465

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4469

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the coder_id parameter.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4458

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute arbitrary SQL commands via the cid parameter in a product action.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4467

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 7 Oct 2008
    4.6
    Medium

    CVE-2008-3826

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Condor before 7.0.5 allows attackers to execute jobs as other users via unknown vectors.

    Published: 7 Oct 2008
    4.6
    Medium

    CVE-2008-3828

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the condor_ schedd daemon in Condor before 7.0.5 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4459

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pick_users.php in the groups module in eXtrovert Thyme 1.3 allows remote attackers to execute arbitrary SQL commands via the uname_search parameter. NOTE: some of these details are obtained from third party information.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4468

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_news.php in Vastal I-Tech Share Zone allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 7 Oct 2008
    6.8
    Medium

    CVE-2008-4503

    Last Modified: 23 Apr 2026

    The Settings Manager in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to cause victims to unknowingly click on a link or dialog via access control dialogs disguised as normal graphical elements, as demonstrated by hijacking the camera or microphone, and related to "clickjacking."

    Published: 7 Oct 2008
    7.2
    High

    CVE-2008-3830

    Last Modified: 23 Apr 2026

    Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to be ignored and allows attackers to bypass intended access restrictions.

    Published: 7 Oct 2008
    6.8
    Medium

    CVE-2008-4457

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php.

    Published: 7 Oct 2008
    7.5
    High

    CVE-2008-4466

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 7 Oct 2008
    9.3
    Critical

    CVE-2008-4470

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname.

    Published: 7 Oct 2008
    7.2
    High

    CVE-2008-4451

    Last Modified: 23 Apr 2026

    The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer.

    Published: 6 Oct 2008