CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-4064

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4066

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4067

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.

    Published: 23 Sept 2008
    7.8
    High

    CVE-2008-4068

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

    Published: 23 Sept 2008
    4.3
    Medium

    CVE-2008-4182

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in imp/test.php in Horde Turba Contact Manager H3 2.2.1 and other versions before 2.3.1, and possibly other Horde Project products, allows remote attackers to inject arbitrary web script or HTML via the User field in an IMAP session.

    Published: 23 Sept 2008
    7.5
    High

    CVE-2008-4058

    Last Modified: 23 Apr 2026

    The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.

    Published: 23 Sept 2008
    5
    Medium

    CVE-2008-4069

    Last Modified: 23 Apr 2026

    The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.

    Published: 23 Sept 2008
    6.4
    Medium

    CVE-2008-4167

    Last Modified: 23 Apr 2026

    useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allows remote attackers to (1) add or (2) remove an Administrator account.

    Published: 22 Sept 2008
    4.3
    Medium

    CVE-2008-4168

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in verify_login.jsp in Pro2col Stingray FTS allows remote attackers to inject arbitrary web script or HTML via the form_username parameter (aka user name field).

    Published: 22 Sept 2008
    5
    Medium

    CVE-2008-4170

    Last Modified: 23 Apr 2026

    create_account.php in osCommerce 2.2 RC 2a allows remote attackers to obtain sensitive information via an invalid dob parameter, which reveals the installation path in an error message.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4171

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in xmlout.php in Invision Power Board (IP.Board or IPB) 2.2.x and 2.3.x allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Published: 22 Sept 2008
    4
    Medium

    CVE-2008-4165

    Last Modified: 23 Apr 2026

    admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows local administrators, and possibly remote attackers, to obtain cleartext passwords by reading the ssl_access_log file or the referer string.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4173

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the random parameter to the default URI.

    Published: 22 Sept 2008
    4.3
    Medium

    CVE-2008-4166

    Last Modified: 23 Apr 2026

    Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a denial of service (application crash) by attempting to URL encode a string containing many instances of an invalid character.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4169

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute arbitrary SQL commands via the produid parameter.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4172

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute arbitrary SQL commands via the lnkid parameter.

    Published: 22 Sept 2008
    4.7
    Medium

    CVE-2008-4160

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the UFS module in Sun Solaris 8 through 10 and OpenSolaris allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via unknown vectors related to the Solaris Access Control List (ACL) implementation.

    Published: 22 Sept 2008
    6.8
    Medium

    CVE-2008-4161

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.

    Published: 22 Sept 2008
    7.8
    High

    CVE-2008-4163

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in ISC BIND 9.3.5-P2-W1, 9.4.2-P2-W1, and 9.5.0-P2-W1 on Windows allows remote attackers to cause a denial of service (UDP client handler termination) via unknown vectors.

    Published: 22 Sept 2008
    2.6
    Low

    CVE-2008-4164

    Last Modified: 23 Apr 2026

    cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Published: 22 Sept 2008
    4.3
    Medium

    CVE-2008-4162

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in admin/auth.php in NooMS 1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the g_site_url parameter.

    Published: 22 Sept 2008
    6.8
    Medium

    CVE-2008-4158

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) flag and (2) inc parameters.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4159

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitrary SQL commands via the page (pageid) parameter.

    Published: 22 Sept 2008
    7.5
    High

    CVE-2008-4157

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected.

    Published: 22 Sept 2008
    4.3
    Medium

    CVE-2008-3519

    Last Modified: 23 Apr 2026

    The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

    Published: 22 Sept 2008
    5
    Medium

    CVE-2008-4298

    Last Modified: 23 Apr 2026

    Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.

    Published: 20 Sept 2008
    6.8
    Medium

    CVE-2008-4156

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Sept 2008
    7.8
    High

    CVE-2008-4155

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in the (1) module or (2) action parameter in (a) www/index.php; the (3) module, (4) ss_module, or (5) ss_action parameter in (b) modules/Module/index.php or (c) modules/Themes/index.php; or the (6) module parameter in (d) inc/vmenu.php.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4154

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.

    Published: 19 Sept 2008
    2.6
    Low

    CVE-2008-4139

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 19 Sept 2008
    4.3
    Medium

    CVE-2008-4140

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4141

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4142

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via the es_id parameter.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4143

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4144

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4150

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.

    Published: 19 Sept 2008
    5
    Medium

    CVE-2008-4151

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (dot dot) in the neturl parameter.

    Published: 19 Sept 2008
    3.5
    Low

    CVE-2008-4152

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, allows remote authenticated users to inject arbitrary web script or HTML via a node title.

    Published: 19 Sept 2008
    5
    Medium

    CVE-2008-4153

    Last Modified: 23 Apr 2026

    The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments, which allows remote attackers to obtain sensitive information.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4148

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to composing queries without using the Drupal database API.

    Published: 19 Sept 2008
    4.3
    Medium

    CVE-2008-4149

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via the "Link page header" field.

    Published: 19 Sept 2008
    7.5
    High

    CVE-2008-4137

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PHP code via a URL in the footer_file parameter.

    Published: 19 Sept 2008
    5
    Medium

    CVE-2008-4146

    Last Modified: 23 Apr 2026

    Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field and (2) change the visit-counter value via a modified counter field.

    Published: 19 Sept 2008
    4.3
    Medium

    CVE-2008-4147

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an attached file that has a modified Content-Type.

    Published: 19 Sept 2008
    5
    Medium

    CVE-2008-4136

    Last Modified: 23 Apr 2026

    Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.

    Published: 19 Sept 2008
    10
    Critical

    CVE-2008-4138

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows remote attackers to execute arbitrary PHP code via a URL in the shop_this_skin_path parameter.

    Published: 19 Sept 2008
    6.8
    Medium

    CVE-2008-4145

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Published: 19 Sept 2008
    7.2
    High

    CVE-2008-4131

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1) the -t option and (2) the :tag command in the (a) vi, (b) ex, (c) vedit, (d) view, and (e) edit programs.

    Published: 19 Sept 2008
    9.3
    Critical

    CVE-2008-4132

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 19 Sept 2008
    4.3
    Medium

    CVE-2008-4133

    Last Modified: 23 Apr 2026

    The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with large URLs, which allows remote attackers to bypass web restriction filters.

    Published: 19 Sept 2008