CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-4454

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the lang parameter to actions.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Oct 2008
    4.3
    Medium

    CVE-2008-4450

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in adodb.php in XAMPP for Windows 1.6.8 allows remote attackers to inject arbitrary web script or HTML via the (1) dbserver, (2) host, (3) user, (4) password, (5) database, and (6) table parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Oct 2008
    9
    Critical

    CVE-2008-4452

    Last Modified: 23 Apr 2026

    Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (crash and hang) and possibly execute arbitrary code via a long CWD request.

    Published: 6 Oct 2008
    9.3
    Critical

    CVE-2008-4453

    Last Modified: 23 Apr 2026

    The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePro5S.Imaging ActiveX control (gdpicturepro5s.ocx) 5.7.0.1 allows remote attackers to create, overwrite, and modify arbitrary files via the SaveAsPDF method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.

    Published: 6 Oct 2008
    6.8
    Medium

    CVE-2008-4455

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to read and execute arbitrary files via a .. (dot dot) in the language cookie.

    Published: 6 Oct 2008
    4.3
    Medium

    CVE-2008-4447

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.

    Published: 6 Oct 2008
    6.8
    Medium

    CVE-2008-4448

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.

    Published: 6 Oct 2008
    9.3
    Critical

    CVE-2008-4449

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIVMSG message.

    Published: 6 Oct 2008
    2.1
    Low

    CVE-2008-4278

    Last Modified: 23 Apr 2026

    VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.

    Published: 6 Oct 2008
    6.8
    Medium

    CVE-2008-4279

    Last Modified: 23 Apr 2026

    The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000; Player 2.0.x before 2.0.5 build 109488 and 1.x before 1.0.8; Server 1.x before 1.0.7 build 108231; and ESX 2.5.4 through 3.5 allows authenticated guest OS users to gain additional guest OS privileges by triggering an exception that causes the virtual CPU to perform an indirect jump to a non-canonical address.

    Published: 6 Oct 2008
    4.3
    Medium

    CVE-2008-4446

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nucleus EUC-JP 3.31 SP1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Oct 2008
    7.5
    High

    CVE-2008-4577

    Last Modified: 23 Apr 2026

    The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.

    Published: 5 Oct 2008
    5
    Medium

    CVE-2008-4578

    Last Modified: 23 Apr 2026

    The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/child/child" mailboxes.

    Published: 5 Oct 2008
    6.5
    Medium

    CVE-2008-4423

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action.

    Published: 3 Oct 2008
    7.5
    High

    CVE-2008-4427

    Last Modified: 23 Apr 2026

    changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative authentication, which allows remote attackers to change arbitrary passwords.

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4429

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SOURCENEXT Virus Security ZERO 9.5.0173 and earlier and Virus Security 9.5.0173 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via malformed compressed files. NOTE: some of these details are obtained from third party information.

    Published: 3 Oct 2008
    Unknown

    CVE-2008-4430

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3699. Reason: This candidate is a duplicate of CVE-2008-3699. Notes: All CVE users should reference CVE-2008-3699 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4435

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the RMSOFT Downloads Plus (rmdp) module 1.5 and 1.7 for Xoops allow remote attackers to inject arbitrary web script or HTML via the (1) key parameter to search.php and the (2) id parameter to down.php.

    Published: 3 Oct 2008
    7.5
    High

    CVE-2008-4436

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4438

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Datafeed Studio 1.6.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4439

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4383

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 before 6.1.5.595.R01, and 6.3 before 6.3.1.966.R01 allows remote attackers to execute arbitrary code via a long Session cookie.

    Published: 3 Oct 2008
    7.5
    High

    CVE-2008-4433

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops might allow remote attackers to execute arbitrary SQL commands via the itemsxpag parameter.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4424

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inject arbitrary web script or HTML via the s parameter in a comments action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 3 Oct 2008
    8.8
    High

    CVE-2008-4425

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter within a delfile action.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4426

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote attackers to inject arbitrary web script or HTML via the date parameter in a new action.

    Published: 3 Oct 2008
    7.5
    High

    CVE-2008-4431

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in IceBB 1.0-rc9.3 and earlier allows remote attackers to execute arbitrary SQL commands via the skin parameter, probably related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

    Published: 3 Oct 2008
    9.3
    Critical

    CVE-2008-4434

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.

    Published: 3 Oct 2008
    7.1
    High

    CVE-2008-4437

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4428

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4432

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in the RMSOFT MiniShop module 1.0 for Xoops allows remote attackers to inject arbitrary web script or HTML via the itemsxpag parameter.

    Published: 3 Oct 2008
    7.2
    High

    CVE-2008-4440

    Last Modified: 23 Apr 2026

    The to-upgrade plugin in feta 1.4.16 allows local users to overwrite arbitrary files via a symlink on the (1) /tmp/feta.install.$USER and (2) /tmp/feta.avail.$USER temporary files.

    Published: 3 Oct 2008
    4.9
    Medium

    CVE-2008-4410

    Last Modified: 23 Apr 2026

    The vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual Machine Interface (VMI) in the Linux kernel 2.6.26.5 invokes write_idt_entry where write_ldt_entry was intended, which allows local users to cause a denial of service (persistent application failure) via crafted function calls, related to the Java Runtime Environment (JRE) experiencing improper LDT selector state, a different vulnerability than CVE-2008-3247.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-4408

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows remote attackers to inject arbitrary web script or HTML via the useskin parameter to an unspecified component.

    Published: 3 Oct 2008
    2.1
    Low

    CVE-2008-4407

    Last Modified: 23 Apr 2026

    XRunSabre in sabre (aka xsabre) 0.2.4b relies on the ability to create /tmp/sabre.log, which allows local users to cause a denial of service (application unavailability) by creating a /tmp/sabre.log file that cannot be overwritten.

    Published: 3 Oct 2008
    7.2
    High

    CVE-2008-4406

    Last Modified: 23 Apr 2026

    A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitrary files via a symlink attack on unspecified .tmp files.

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4402

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 3 Oct 2008
    5
    Medium

    CVE-2008-4403

    Last Modified: 23 Apr 2026

    The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 allow remote attackers to cause a denial of service (NULL pointer dereference and child process crash) via crafted HTTP headers, related to the "error handling mechanism."

    Published: 3 Oct 2008
    10
    Critical

    CVE-2008-4404

    Last Modified: 23 Apr 2026

    The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB), a related issue to CVE-2008-2476.

    Published: 3 Oct 2008
    4.3
    Medium

    CVE-2008-2236

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the flav parameter (flavour variable). NOTE: some of these details are obtained from third party information.

    Published: 3 Oct 2008
    5
    Medium

    CVE-2008-2439

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in the client in Trend Micro OfficeScan 7.3 Patch 4 build 1367 and other builds before 1372, OfficeScan 8.0 SP1 before build 1222, OfficeScan 8.0 SP1 Patch 1 before build 3087, and Worry-Free Business Security 5.0 before build 1220 allows remote attackers to read arbitrary files via directory traversal sequences in an HTTP request. NOTE: some of these details are obtained from third party information.

    Published: 3 Oct 2008
    9.3
    Critical

    CVE-2008-2476

    Last Modified: 23 Apr 2026

    The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) NetBSD, (4) Force10 FTOS before E7.7.1.1, (5) Juniper JUNOS, and (6) Wind River VxWorks 5.x through 6.4 does not validate the origin of Neighbor Discovery messages, which allows remote attackers to cause a denial of service (loss of connectivity) or read private network traffic via a spoofed message that modifies the Forward Information Base (FIB).

    Published: 3 Oct 2008
    9.3
    Critical

    CVE-2008-4396

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via an executable with malformed version data.

    Published: 2 Oct 2008
    3.5
    Low

    CVE-2008-2831

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the delegated spam management feature in the Spam Quarantine Management (SQM) component in MailMarshal SMTP 6.0.3.8 through 6.3.0.0 allow user-assisted remote authenticated users to inject arbitrary web script or HTML via (1) the list of blocked senders or (2) the list of safe senders.

    Published: 2 Oct 2008
    5
    Medium

    CVE-2008-4382

    Last Modified: 23 Apr 2026

    Konqueror in KDE 3.5.9 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.

    Published: 2 Oct 2008
    7.8
    High

    CVE-2008-3542

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 2 Oct 2008
    5
    Medium

    CVE-2008-4381

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 allows remote attackers to cause a denial of service (application crash) via Javascript that calls the alert function with a URL-encoded string of a large number of invalid characters.

    Published: 2 Oct 2008
    4.3
    Medium

    CVE-2008-4546

    Last Modified: 23 Apr 2026

    Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows remote web servers to cause a denial of service (NULL pointer dereference and browser crash) by returning a different response when an HTTP request is sent a second time, as demonstrated by two responses that provide SWF files with different SWF version numbers.

    Published: 2 Oct 2008
    4.9
    Medium

    CVE-2008-3832

    Last Modified: 23 Apr 2026

    A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system crash or hang) via a call to the utrace_control function.

    Published: 2 Oct 2008
    5
    Medium

    CVE-2008-4409

    Last Modified: 23 Apr 2026

    libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash), as demonstrated by use of xmllint on a certain XML document, a different vulnerability than CVE-2003-1564 and CVE-2008-3281.

    Published: 2 Oct 2008