CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2008-3801

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability than CVE-2008-3800 and CVE-2008-3802.

    Published: 26 Sept 2008
    8.5
    High

    CVE-2008-3806

    Last Modified: 23 Apr 2026

    Cisco IOS 12.0 through 12.4 on Cisco 10000, uBR10012 and uBR7200 series devices handles external UDP packets that are sent to 127.0.0.0/8 addresses intended for IPC communication within the device, which allows remote attackers to cause a denial of service (device or linecard reload) via crafted UDP packets, a different vulnerability than CVE-2008-3805.

    Published: 26 Sept 2008
    9.3
    Critical

    CVE-2008-3638

    Last Modified: 23 Apr 2026

    Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.

    Published: 26 Sept 2008
    7.1
    High

    CVE-2008-3804

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Multi Protocol Label Switching (MPLS) Forwarding Infrastructure (MFI) in Cisco IOS 12.2 and 12.4 allows remote attackers to cause a denial of service (memory corruption) via crafted packets for which the software path is used.

    Published: 26 Sept 2008
    7.8
    High

    CVE-2008-3811

    Last Modified: 23 Apr 2026

    Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote attackers to cause a denial of service (device reload) via segmented SCCP messages, aka Cisco Bug ID CSCsi17020, a different vulnerability than CVE-2008-3810.

    Published: 26 Sept 2008
    7.5
    High

    CVE-2008-4689

    Last Modified: 23 Apr 2026

    Mantis before 1.1.3 does not unset the session cookie during logout, which makes it easier for remote attackers to hijack sessions.

    Published: 26 Sept 2008
    7.5
    High

    CVE-2008-4241

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via an SID cookie.

    Published: 25 Sept 2008
    5
    Medium

    CVE-2008-4246

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Denora IRC Stats Server before 1.4.1 allows remote IRC servers to cause a denial of service (application crash) via a crafted CTCP response.

    Published: 25 Sept 2008
    7.5
    High

    CVE-2008-4244

    Last Modified: 23 Apr 2026

    Rianxosencabos CMS 0.9 allows remote attackers to bypass authentication and gain administrative access by setting the usuario and pass cookies to 1.

    Published: 25 Sept 2008
    7.8
    High

    CVE-2008-4243

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tournament 3 (UT3) 1.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 25 Sept 2008
    6.5
    Medium

    CVE-2008-4245

    Last Modified: 23 Apr 2026

    The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a user's privileges, (2) delete a user account, or perform unspecified other administrative actions via vectors involving an admin lista action to the default URI, possibly related to useradmin.php.

    Published: 25 Sept 2008
    7.5
    High

    CVE-2008-4247

    Last Modified: 23 Apr 2026

    ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

    Published: 25 Sept 2008
    10
    Critical

    CVE-2008-4070

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canceling [a] newsgroup message" and "cancelled newsgroup messages."

    Published: 25 Sept 2008
    6.8
    Medium

    CVE-2008-4242

    Last Modified: 23 Apr 2026

    ProFTPD 1.3.1 interprets long commands from an FTP client as multiple commands, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and execute arbitrary FTP commands via a long ftp:// URI that leverages an existing session from the FTP client implementation in a web browser.

    Published: 25 Sept 2008
    7.5
    High

    CVE-2008-4202

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL commands via the idd parameter in a deadlink action.

    Published: 24 Sept 2008
    7.5
    High

    CVE-2008-4203

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQL commands via a recook cookie.

    Published: 24 Sept 2008
    5
    Medium

    CVE-2008-4207

    Last Modified: 23 Apr 2026

    Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information.

    Published: 24 Sept 2008
    10
    Critical

    CVE-2008-4208

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OSADS Alliance Database before 2.1 has unknown impact and attack vectors, possibly related to includes/functions.php, a different issue than CVE-2006-2874.

    Published: 24 Sept 2008
    7.5
    High

    CVE-2008-4205

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 24 Sept 2008
    7.5
    High

    CVE-2008-4206

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter.

    Published: 24 Sept 2008
    4.3
    Medium

    CVE-2008-3098

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers to inject arbitrary web script or HTML via the user parameter to the login form.

    Published: 24 Sept 2008
    7.5
    High

    CVE-2008-4204

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute arbitrary SQL commands via the city parameter.

    Published: 24 Sept 2008
    10
    Critical

    CVE-2008-4193

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter.

    Published: 24 Sept 2008
    5
    Medium

    CVE-2008-4194

    Last Modified: 23 Apr 2026

    The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."

    Published: 24 Sept 2008
    9.3
    Critical

    CVE-2008-4201

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MPEG-4 (MP4) file.

    Published: 24 Sept 2008
    4.3
    Medium

    CVE-2008-4187

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in ProActive CMS allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.

    Published: 23 Sept 2008
    Unknown

    CVE-2008-4189

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1105. Reason: This candidate is a duplicate of CVE-2008-1105. Notes: All CVE users should reference CVE-2008-1105 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Sept 2008
    10
    Critical

    CVE-2008-4188

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TYPO3 Secure Directory (kw_secdir) extension before 1.0.2 allows remote attackers to execute arbitrary code via unknown vectors related to "injection of control characters."

    Published: 23 Sept 2008
    6.5
    Medium

    CVE-2008-4175

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Link Bid Script 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) ucat parameter to upgrade.php and the (2) id parameter to linkadmin/edit.php.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4176

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in izle.asp in FoT Video scripti 1.1 beta allows remote attackers to execute arbitrary SQL commands via the oyun parameter.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4177

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4179

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) page_id parameter to smileys.php and the (2) q parameter to search.php.

    Published: 23 Sept 2008
    5
    Medium

    CVE-2008-4180

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."

    Published: 23 Sept 2008
    5
    Medium

    CVE-2008-4183

    Last Modified: 23 Apr 2026

    IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a backup via a direct request to a backup/backup-yyyy-dd-mm.sql filename.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4185

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter in a documentos action, a different vector than CVE-2008-3213.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4186

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id_doc parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4184

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in webCMS Portal Edition allows remote attackers to inject arbitrary web script or HTML via the patron parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Sept 2008
    6.8
    Medium

    CVE-2008-4181

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4174

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) currentpath, (2) invert, (3) search, and (4) sort parameters.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4178

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and Downline Goldmine Builder allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 23 Sept 2008
    10
    Critical

    CVE-2008-0016

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

    Published: 23 Sept 2008
    9.3
    Critical

    CVE-2008-3837

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4059

    Last Modified: 23 Apr 2026

    The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4065

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

    Published: 23 Sept 2008
    10
    Critical

    CVE-2008-4061

    Last Modified: 23 Apr 2026

    Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.

    Published: 23 Sept 2008
    10
    Critical

    CVE-2008-4062

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

    Published: 23 Sept 2008
    9.3
    Critical

    CVE-2008-4063

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-3835

    Last Modified: 23 Apr 2026

    The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-3836

    Last Modified: 23 Apr 2026

    feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4060

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

    Published: 23 Sept 2008