CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-4095

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Importer in Flip4Mac WMV before 2.2.1 have unknown impact and attack vectors, different vulnerabilities than CVE-2007-6713.

    Published: 16 Sept 2008
    9.3
    Critical

    CVE-2009-4257

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10 and 11.0.0, and Helix Player 10.x and 11.0.0 allows remote attackers to execute arbitrary code via an SMIL file with crafted string lengths.

    Published: 16 Sept 2008
    4.6
    Medium

    CVE-2008-4082

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.

    Published: 15 Sept 2008
    4.4
    Medium

    CVE-2008-4085

    Last Modified: 23 Apr 2026

    plaiter in Plait before 1.6 allows local users to overwrite arbitrary files via a symlink attack on (1) cut.$$, (2) head.$$, (3) awk.$$, and (4) ps.$$ temporary files in /tmp/.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4086

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Reciprocal Links Manager 1.1 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 15 Sept 2008
    4.3
    Medium

    CVE-2008-4089

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4090

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4092

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4084

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in staticpages/easyclassifields/index.php in MyioSoft EasyClassifields 3.0 allows remote attackers to execute arbitrary SQL commands via the go parameter in a browse action.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4087

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of service or execute arbitrary code via a Beatcraft Project (aka bcproj) file with a long string in a certain instruments title field.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4091

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Web Directory Script 1.5.3 allows remote attackers to execute arbitrary SQL commands via the site parameter in an open action.

    Published: 15 Sept 2008
    3.5
    Low

    CVE-2008-4083

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the name parameter in an addItemPost action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4073

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the pageid parameter in a DBpAGE action.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4074

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4075

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in D-iscussion Board 3.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the topic parameter.

    Published: 15 Sept 2008
    6.8
    Medium

    CVE-2008-4080

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4081

    Last Modified: 23 Apr 2026

    admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by setting a bsm cookie.

    Published: 15 Sept 2008
    4.3
    Medium

    CVE-2008-4076

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) Tor World Tor Board 1.3 and earlier, (2) Topics BBS 1.11 and earlier, (3) Simple BBS 1.86 and earlier, and (4) Interactive BBS 1.57 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2008-0917.

    Published: 15 Sept 2008
    7.8
    High

    CVE-2008-4077

    Last Modified: 23 Apr 2026

    The CGI scripts in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allow remote attackers to cause a denial of service (resource exhaustion) via an HTTP POST request with a large Content-Length.

    Published: 15 Sept 2008
    5
    Medium

    CVE-2008-4071

    Last Modified: 23 Apr 2026

    A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows remote attackers to cause a denial of service (browser crash) via an src property value with an invalid acroie:// URL.

    Published: 15 Sept 2008
    6.5
    Medium

    CVE-2008-4078

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the AR/AP transaction report in (1) LedgerSMB (LSMB) before 1.2.15 and (2) SQL-Ledger 2.8.17 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Sept 2008
    4.3
    Medium

    CVE-2008-4079

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Solution allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Sept 2008
    7.5
    High

    CVE-2008-4072

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in phsBlog 0.2 allow remote attackers to execute arbitrary SQL commands via (1) the sid parameter in a pickup action or (2) the sql_cid parameter, different vectors than CVE-2008-3588.

    Published: 15 Sept 2008
    7.2
    High

    CVE-2008-4108

    Last Modified: 23 Apr 2026

    Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrite arbitrary files via a symlink attack on a tmp$RANDOM.tmp temporary file. NOTE: there may not be common usage scenarios in which tmp$RANDOM.tmp is located in an untrusted directory.

    Published: 14 Sept 2008
    5
    Medium

    CVE-2008-4685

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via certain packets that trigger an exception.

    Published: 13 Sept 2008
    2.1
    Low

    CVE-2008-3528

    Last Modified: 23 Apr 2026

    The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux kernel 2.6.26.5 does not limit the number of printk console messages that report directory corruption, which allows physically proximate attackers to cause a denial of service (temporary system hang) by mounting a filesystem that has corrupted dir->i_size and dir->i_blocks values and performing (a) read or (b) write operations. NOTE: there are limited scenarios in which this crosses privilege boundaries.

    Published: 13 Sept 2008
    4.3
    Medium

    CVE-2008-3823

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.

    Published: 12 Sept 2008
    4.3
    Medium

    CVE-2008-3824

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.

    Published: 12 Sept 2008
    9.3
    Critical

    CVE-2008-3584

    Last Modified: 23 Apr 2026

    NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.

    Published: 11 Sept 2008
    4
    Medium

    CVE-2008-4041

    Last Modified: 23 Apr 2026

    The IMAP server in Softalk Mail Server (formerly WorkgroupMail) 8.5.1.431 allows remote authenticated users to cause a denial of service (resource consumption and daemon crash) via a long IMAP APPEND command with certain repeated parameters.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4043

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4044

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in article/readarticle.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the artid parameter.

    Published: 11 Sept 2008
    4.3
    Medium

    CVE-2008-4045

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in @Mail 5.42 allow remote attackers to inject arbitrary web script or HTML via the (1) file and (2) HelpFile parameters to parse.php, the (3) Folder and (4) start parameters to showmail.php, and the (5) abookview parameter to abook.php.

    Published: 11 Sept 2008
    4.3
    Medium

    CVE-2008-4051

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in surveyresults.asp in Smart Survey 1.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Sept 2008
    4.3
    Medium

    CVE-2008-4053

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Bluemoon PopnupBLOG module 3.20 and 3.30 for XOOPS allow remote attackers to inject arbitrary web script or HTML via the (1) param, (2) cat_id, and (3) view parameters.

    Published: 11 Sept 2008
    10
    Critical

    CVE-2008-4057

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Objective Development Sharity 3 before 3.5 has unknown impact and attack vectors, related to a "serious security problem."

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4055

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4039

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4047

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Novell Forum (formerly SiteScape Forum) 7.0, 7.1, 7.2, 7.3, and 8.0 allows remote attackers to execute arbitrary TCL code via a modified URL. NOTE: this might overlap CVE-2007-6515.

    Published: 11 Sept 2008
    6.8
    Medium

    CVE-2008-4048

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.

    Published: 11 Sept 2008
    6.8
    Medium

    CVE-2008-4049

    Last Modified: 23 Apr 2026

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method.

    Published: 11 Sept 2008
    4.3
    Medium

    CVE-2008-4056

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/login.php in Matterdaddy Market 1.1 allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4054

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 11 Sept 2008
    Unknown

    CVE-2008-4042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3889. Reason: This candidate is a duplicate of CVE-2008-3889. Notes: All CVE users should reference CVE-2008-3889 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 11 Sept 2008
    7.8
    High

    CVE-2008-4040

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Kyocera Command Center in Kyocera FS-118MFP allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 11 Sept 2008
    7.5
    High

    CVE-2008-4046

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eliteCMS 1.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 11 Sept 2008
    9.3
    Critical

    CVE-2008-4050

    Last Modified: 23 Apr 2026

    A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.

    Published: 11 Sept 2008
    7.2
    High

    CVE-2008-4052

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local users to cause a denial of service (crash) or gain privileges via unspecified vectors.

    Published: 11 Sept 2008