CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-4368

    Last Modified: 23 Apr 2026

    The default configuration of Java 1.5 on Apple Mac OS X 10.5.4 and 10.5.5 contains a jurisdiction policy that limits Java Cryptography Extension (JCE) key sizes to 128 bits, which makes it easier for attackers to decrypt ciphertext produced by JCE.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pics.php in Availscript Photo Album allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4373

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execute arbitrary SQL commands via the jid parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4374

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the id parameter in a playgame action.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4375

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewprofile.php in Availscript Classmate Script allows remote attackers to execute arbitrary SQL commands via the p parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4376

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4377

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the sideid parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4378

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Oct 2008
    4.3
    Medium

    CVE-2008-4372

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject arbitrary web script or HTML via the aIDS parameter.

    Published: 1 Oct 2008
    7.5
    High

    CVE-2008-4371

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in articles.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL commands via the aIDS parameter.

    Published: 1 Oct 2008
    7.8
    High

    CVE-2008-4380

    Last Modified: 23 Apr 2026

    The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, related to the filter for configuration properties and "/x" characters.

    Published: 1 Oct 2008
    4.3
    Medium

    CVE-2008-4370

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to pics.php and the (2) a parameter to view.php.

    Published: 1 Oct 2008
    4.3
    Medium

    CVE-2008-4379

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 1 Oct 2008
    4.4
    Medium

    CVE-2008-3825

    Last Modified: 23 Apr 2026

    pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incorrect privileges when reading a Kerberos credential cache, which allows local users to gain privileges by setting the KRB5CCNAME environment variable to an arbitrary cache filename and running the (1) su or (2) sudo program. NOTE: there may be a related vector involving sshd that has limited relevance.

    Published: 1 Oct 2008
    4.3
    Medium

    CVE-2008-4680

    Last Modified: 23 Apr 2026

    packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).

    Published: 1 Oct 2008
    5
    Medium

    CVE-2008-4682

    Last Modified: 23 Apr 2026

    wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.

    Published: 1 Oct 2008
    4.9
    Medium

    CVE-2008-4362

    Last Modified: 23 Apr 2026

    The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0.

    Published: 30 Sept 2008
    7.2
    High

    CVE-2008-4363

    Last Modified: 23 Apr 2026

    DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended.

    Published: 30 Sept 2008
    4.3
    Medium

    CVE-2008-4365

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Siteman 1.1.11 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4364

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL commands via the (1) id parameter in the "page" page and (2) txtSearch parameter in the "Search" page.

    Published: 30 Sept 2008
    6.5
    Medium

    CVE-2008-4366

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a user directory under images/photos/upload.

    Published: 30 Sept 2008
    7.8
    High

    CVE-2008-4361

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary files via a .. (dot dot) in the path parameter to the default URI.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4348

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in photo.php in PHPortfolio, possibly 1.3, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Sept 2008
    4.3
    Medium

    CVE-2008-4349

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) page parameter in a details action.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4350

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4351

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the p parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4352

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a viewprofile action to index.php.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4346

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to comments.php, a different vector than CVE-2008-3371.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4347

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands via the newsid parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4357

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Sept 2008
    10
    Critical

    CVE-2008-4358

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in class/theme.class.php in SPAW Editor PHP Edition before 2.0.8.1 has unknown impact and attack vectors, probably related to directory traversal sequences in the theme name.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4345

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4354

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4356

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result action to the Voting module; (3) the fid parameter to index.php in a ShowForum action to the Forum module; (4) the tid parameter to index.php in a ShowTopic action to the Forum module; (5) the uname parameter to index.php in a UserInfo action to the Account module; or (6) the module parameter to index.php, probably related to the TopSites module.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4355

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4353

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: although one component of Linkarity is distributable PHP code, this issue might be site-specific. If so, it should not be included in CVE.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4328

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL commands via the (1) item, (2) search_ordermethod, and (3) search_order parameters.

    Published: 30 Sept 2008
    10
    Critical

    CVE-2008-4329

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4332

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers to execute arbitrary SQL commands via the idcat parameter to showtopic.php.

    Published: 30 Sept 2008
    4.3
    Medium

    CVE-2008-4333

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web script or HTML via the isname parameter in a newtopic action.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4334

    Last Modified: 23 Apr 2026

    PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4335

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4341

    Last Modified: 23 Apr 2026

    add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=yes and login=admin.

    Published: 30 Sept 2008
    6.5
    Medium

    CVE-2008-4339

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7, 6.0 before MP7, and 6.5 before 6.5.2 allows remote authenticated users to gain privileges via unknown attack vectors related to "bpjava* binaries."

    Published: 30 Sept 2008
    4.3
    Medium

    CVE-2008-4340

    Last Modified: 23 Apr 2026

    Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an HTML document containing a carriage return ("\r\n\r\n") argument to the window.open function.

    Published: 30 Sept 2008
    6
    Medium

    CVE-2008-4338

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the brilliant_gallery_checklist_save function in the bgchecklist/save script in Brilliant Gallery 5.x and 6.x, a module for Drupal, allows remote authenticated users with "access brilliant_gallery" permissions to execute arbitrary SQL commands via the (1) nid, (2) qid, (3) state, and possibly (4) user parameters.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4094

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) :limit and (2) :offset parameters, related to ActiveRecord, ActiveSupport, ActiveResource, ActionPack, and ActionMailer.

    Published: 30 Sept 2008
    7.5
    High

    CVE-2008-4331

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to index.php.

    Published: 30 Sept 2008
    4.3
    Medium

    CVE-2008-4337

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Bitweaver 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the URL parameter to (1) edit.php and (2) list.php in articles/; (3) list_blogs.php and (4) rankings.php in blogs/; (5) calendar/index.php; (6) calendar.php, (7) index.php, and (8) list_events.php in events/; (9) index.php and (10) list_galleries.php in fisheye/; (11) liberty/list_content.php; (12) newsletters/edition.php; (13) pigeonholes/list.php; (14) recommends/index.php; (15) rss/index.php; (16) stars/index.php; (17) users/remind_password.php; (18) wiki/orphan_pages.php; and (19) stats/index.php, different vectors than CVE-2007-0526 and CVE-2005-4379. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Sept 2008
    9.3
    Critical

    CVE-2008-4342

    Last Modified: 23 Apr 2026

    NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used in CDBurnerXP 4.2.1.976, BurnAware 2.1.3, Blaze Media Pro 8.02 Special Edition, and possibly other products, allows remote attackers to overwrite and create arbitrary files via calls to the EnableLog and LogMessage methods. NOTE: this issue might only be exploitable in limited environments or non-default browser settings. NOTE: some of these details are obtained from third party information. NOTE: this can be leveraged for remote code execution by accessing files using hcp:// URLs.

    Published: 30 Sept 2008