CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-3956

    Last Modified: 23 Apr 2026

    orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.

    Published: 9 Sept 2008
    5
    Medium

    CVE-2008-3912

    Last Modified: 23 Apr 2026

    libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.

    Published: 9 Sept 2008
    9.3
    Critical

    CVE-2008-3957

    Last Modified: 23 Apr 2026

    The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Sept 2008
    7.5
    High

    CVE-2008-3951

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.

    Published: 9 Sept 2008
    7.5
    High

    CVE-2008-3952

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

    Published: 9 Sept 2008
    7.5
    High

    CVE-2008-3953

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.

    Published: 9 Sept 2008
    7.5
    High

    CVE-2008-3955

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.

    Published: 9 Sept 2008
    7.5
    High

    CVE-2008-3954

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.

    Published: 9 Sept 2008
    7.2
    High

    CVE-2008-7002

    Last Modified: 23 Apr 2026

    PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.

    Published: 9 Sept 2008
    7.8
    High

    CVE-2010-0437

    Last Modified: 11 Apr 2025

    The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.

    Published: 9 Sept 2008
    9.3
    Critical

    CVE-2008-3520

    Last Modified: 23 Apr 2026

    Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.

    Published: 8 Sept 2008
    10
    Critical

    CVE-2008-3522

    Last Modified: 23 Apr 2026

    Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.

    Published: 8 Sept 2008
    7.2
    High

    CVE-2008-3521

    Last Modified: 23 Apr 2026

    Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was incorrect. NOTE: some vendors dispute the severity of this issue, but it satisfies CVE's requirements for inclusion.

    Published: 8 Sept 2008
    7.1
    High

    CVE-2008-3530

    Last Modified: 23 Apr 2026

    sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1, NetBSD 3.0 through 4.0, and possibly other operating systems does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3948

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified vectors.

    Published: 5 Sept 2008
    7.2
    High

    CVE-2008-3947

    Last Modified: 23 Apr 2026

    DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.

    Published: 5 Sept 2008
    6.3
    Medium

    CVE-2008-1144

    Last Modified: 23 Apr 2026

    The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted "advertised length."

    Published: 5 Sept 2008
    6.3
    Medium

    CVE-2008-1197

    Last Modified: 23 Apr 2026

    The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse the SSID information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a "Null SSID."

    Published: 5 Sept 2008
    9.3
    Critical

    CVE-2008-2436

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.

    Published: 5 Sept 2008
    4.3
    Medium

    CVE-2008-3664

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the case_title parameter to cases/some.php, (9) the file_id parameter to files/some.php, or (10) the starting parameter to reports/custom/mileage.php, a related issue to CVE-2008-1129.

    Published: 5 Sept 2008
    6.3
    Medium

    CVE-2007-5474

    Last Modified: 23 Apr 2026

    The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via an Atheros information element with an invalid length, as demonstrated by an element that is too long.

    Published: 5 Sept 2008
    7.2
    High

    CVE-2008-3890

    Last Modified: 23 Apr 2026

    The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call.

    Published: 5 Sept 2008
    4.9
    Medium

    CVE-2008-3946

    Last Modified: 23 Apr 2026

    The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file.

    Published: 5 Sept 2008
    6.9
    Medium

    CVE-2008-3531

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of "user defined data" in "certain error conditions."

    Published: 5 Sept 2008
    7.8
    High

    CVE-2008-3936

    Last Modified: 23 Apr 2026

    The web interface in Dreambox DM500C allows remote attackers to cause a denial of service (application hang) via a long URI.

    Published: 5 Sept 2008
    4.4
    Medium

    CVE-2008-3940

    Last Modified: 23 Apr 2026

    Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3942

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3943

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3944

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.

    Published: 5 Sept 2008
    8.8
    High

    CVE-2008-3938

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.

    Published: 5 Sept 2008
    6.1
    Medium

    CVE-2008-3935

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Sept 2008
    6.1
    Medium

    CVE-2008-3937

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3939

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.

    Published: 5 Sept 2008
    4.3
    Medium

    CVE-2008-3941

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI.

    Published: 5 Sept 2008
    7.5
    High

    CVE-2008-3945

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.

    Published: 5 Sept 2008
    4.3
    Medium

    CVE-2008-3964

    Last Modified: 23 Apr 2026

    Multiple off-by-one errors in libpng before 1.2.32beta01, and 1.4 before 1.4.0beta34, allow context-dependent attackers to cause a denial of service (crash) or have unspecified other impact via a PNG image with crafted zTXt chunks, related to (1) the png_push_read_zTXt function in pngread.c, and possibly related to (2) pngtest.c.

    Published: 5 Sept 2008
    3.5
    Low

    CVE-2008-3903

    Last Modified: 23 Apr 2026

    Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled, generates different responses depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames.

    Published: 4 Sept 2008
    4.3
    Medium

    CVE-2008-3917

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.

    Published: 4 Sept 2008
    9.3
    Critical

    CVE-2008-3919

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as exploited in the wild in August 2008.

    Published: 4 Sept 2008
    4.3
    Medium

    CVE-2008-3925

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.

    Published: 4 Sept 2008
    7.2
    High

    CVE-2008-3927

    Last Modified: 23 Apr 2026

    genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.

    Published: 4 Sept 2008
    6.9
    Medium

    CVE-2008-3928

    Last Modified: 23 Apr 2026

    test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 4 Sept 2008
    7.5
    High

    CVE-2008-3918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Sept 2008
    4.3
    Medium

    CVE-2008-3921

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.

    Published: 4 Sept 2008
    6.9
    Medium

    CVE-2008-3930

    Last Modified: 23 Apr 2026

    migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 4 Sept 2008
    4.3
    Medium

    CVE-2008-3923

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.

    Published: 4 Sept 2008
    4.3
    Medium

    CVE-2008-3924

    Last Modified: 23 Apr 2026

    The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.

    Published: 4 Sept 2008
    7.2
    High

    CVE-2008-3929

    Last Modified: 23 Apr 2026

    gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

    Published: 4 Sept 2008
    7.5
    High

    CVE-2008-3920

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.

    Published: 4 Sept 2008
    9.3
    Critical

    CVE-2008-3922

    Last Modified: 23 Apr 2026

    awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.

    Published: 4 Sept 2008