CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-3886

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.

    Published: 2 Sept 2008
    10
    Critical

    CVE-2008-3882

    Last Modified: 23 Apr 2026

    Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.

    Published: 2 Sept 2008
    7.2
    High

    CVE-2008-3883

    Last Modified: 23 Apr 2026

    configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.

    Published: 2 Sept 2008
    4.3
    Medium

    CVE-2008-3881

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified "zm_html_view_*.php" files.

    Published: 2 Sept 2008
    1.9
    Low

    CVE-2008-3876

    Last Modified: 23 Apr 2026

    Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact's blue arrow.

    Published: 2 Sept 2008
    10
    Critical

    CVE-2008-3146

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in packet_ncp2222.inc in Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted NCP packet that causes an invalid pointer to be used.

    Published: 2 Sept 2008
    9
    Critical

    CVE-2008-3538

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP Enterprise Discovery 2.0 through 2.52 on Windows allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the initial description of this CVE was inadvertently associated with libxml2, but it should be for HP Enterprise Discovery.

    Published: 2 Sept 2008
    7.2
    High

    CVE-2008-3875

    Last Modified: 23 Apr 2026

    The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.

    Published: 2 Sept 2008
    2.1
    Low

    CVE-2008-3889

    Last Modified: 23 Apr 2026

    Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.

    Published: 2 Sept 2008
    9.3
    Critical

    CVE-2008-3915

    Last Modified: 23 Apr 2026

    Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.

    Published: 1 Sept 2008
    9.3
    Critical

    CVE-2008-3480

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.

    Published: 29 Aug 2008
    3.5
    Low

    CVE-2008-3874

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote authenticated users to inject arbitrary web script or HTML via the Value field (aka Label ==> Value pairs). NOTE: some of these details are obtained from third party information.

    Published: 29 Aug 2008
    5
    Medium

    CVE-2008-3859

    Last Modified: 23 Apr 2026

    Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php.

    Published: 29 Aug 2008
    7.5
    High

    CVE-2008-3861

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.

    Published: 29 Aug 2008
    4.3
    Medium

    CVE-2008-3860

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) during HTML redirects, (4) in the HTML import, (5) in the Rich text editor, and (6) in link-page in IBM Lotus Quickr 8.1 services for Lotus Domino before Hotfix 15 allow remote attackers to inject arbitrary web script or HTML via unknown vectors, including (7) the Imported Page. NOTE: the vulnerability in the WYSIWYG editors may exist because of an incomplete fix for CVE-2008-2163.

    Published: 29 Aug 2008
    6.5
    Medium

    CVE-2008-3852

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 28 Aug 2008
    9.3
    Critical

    CVE-2008-3853

    Last Modified: 23 Apr 2026

    Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before FP1 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via unspecified vectors. NOTE: this might be related to CVE-2007-3676.

    Published: 28 Aug 2008
    7.8
    High

    CVE-2008-3854

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to cause a denial of service (system outage) via vectors related to (1) use of XQuery to issue statements; the (2) XMLQUERY, (3) XMLEXISTS, and (4) XMLTABLE statements; and the (5) sqlrlaka function.

    Published: 28 Aug 2008
    4.3
    Medium

    CVE-2008-3858

    Last Modified: 23 Apr 2026

    The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.

    Published: 28 Aug 2008
    7.5
    High

    CVE-2008-3856

    Last Modified: 23 Apr 2026

    The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of the db2fmp process, which has unknown impact and attack vectors.

    Published: 28 Aug 2008
    4.6
    Medium

    CVE-2008-3857

    Last Modified: 23 Apr 2026

    The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.

    Published: 28 Aug 2008
    4.6
    Medium

    CVE-2008-3855

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.

    Published: 28 Aug 2008
    7.5
    High

    CVE-2008-3845

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3846

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3847

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Aug 2008
    5
    Medium

    CVE-2008-3851

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php; and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php. NOTE: the issue involving vectors 1 through 3 reportedly exists because of an incomplete fix for CVE-2008-3194.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3849

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the calendar controller in Civic Website Manager before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving (1) month, (2) day, and (3) year fields.

    Published: 27 Aug 2008
    7.5
    High

    CVE-2008-3848

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3850

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html.

    Published: 27 Aug 2008
    6
    Medium

    CVE-2008-3736

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (a) change passwords or (b) change configurations.

    Published: 27 Aug 2008
    4.7
    Medium

    CVE-2008-3839

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when configured as an NFS server without the nodevices option, allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3843

    Last Modified: 23 Apr 2026

    Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.

    Published: 27 Aug 2008
    9.1
    Critical

    CVE-2008-3738

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3841

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway eCommerce 1.4.1.171 allows remote attackers to inject arbitrary web script or HTML via the search_link parameter.

    Published: 27 Aug 2008
    10
    Critical

    CVE-2008-3737

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to execute arbitrary PHP scripts, and delete files, read files, and possibly have unknown other impact.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3739

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly involving upload of files containing XSS sequences.

    Published: 27 Aug 2008
    9.8
    Critical

    CVE-2008-2433

    Last Modified: 23 Apr 2026

    The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution through an unspecified "manipulation of the configuration."

    Published: 27 Aug 2008
    7.2
    High

    CVE-2008-3838

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris before snv_88 allows local administrators of non-global zones to read and modify NFS traffic for arbitrary non-global zones, possibly leading to file modifications or a denial of service.

    Published: 27 Aug 2008
    9.3
    Critical

    CVE-2007-1682

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to the (1) BuildPath, (2) GetDriveName, (3) DriveExists, or (4) DeleteFile method.

    Published: 27 Aug 2008
    5
    Medium

    CVE-2008-3840

    Last Modified: 23 Apr 2026

    Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3842

    Last Modified: 23 Apr 2026

    Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "</" (less-than slash) sequence.

    Published: 27 Aug 2008
    4.3
    Medium

    CVE-2008-3740

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Aug 2008
    3.5
    Low

    CVE-2008-3741

    Last Modified: 23 Apr 2026

    The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading files containing arbitrary web script or HTML.

    Published: 27 Aug 2008
    6.5
    Medium

    CVE-2008-3742

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, which is not validated.

    Published: 27 Aug 2008
    5.8
    Medium

    CVE-2008-3743

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to perform unspecified actions via unknown vectors, related to improper token validation for (1) cached forms and (2) forms with AHAH elements.

    Published: 27 Aug 2008
    10
    Critical

    CVE-2008-3795

    Last Modified: 23 Apr 2026

    Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response."

    Published: 27 Aug 2008
    5.5
    Medium

    CVE-2008-3745

    Last Modified: 23 Apr 2026

    The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors.

    Published: 27 Aug 2008
    7.5
    High

    CVE-2008-3747

    Last Modified: 23 Apr 2026

    The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL communication in the intended situations, which might allow remote attackers to gain administrative access by sniffing the network for a cookie.

    Published: 27 Aug 2008
    5.8
    Medium

    CVE-2008-3744

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) delete user access rules.

    Published: 27 Aug 2008
    5
    Medium

    CVE-2008-3796

    Last Modified: 23 Apr 2026

    Swfdec 0.6 before 0.6.8 allows remote attackers to cause a denial of service (application crash) via a 1x1 JPEG image.

    Published: 27 Aug 2008