CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-2327

    Last Modified: 23 Apr 2026

    Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in the LZW decoder in LibTIFF 3.8.2 and earlier allow context-dependent attackers to execute arbitrary code via a crafted TIFF file, related to improper handling of the CODE_CLEAR code.

    Published: 26 Aug 2008
    7.8
    High

    CVE-2008-3526

    Last Modified: 23 Apr 2026

    Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows remote attackers to cause a denial of service (panic) or possibly have unspecified other impact via a crafted sca_keylength field associated with the SCTP_AUTH_KEY option.

    Published: 26 Aug 2008
    7.5
    High

    CVE-2008-3778

    Last Modified: 23 Apr 2026

    The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, proceeds with Core router updates even when a login is invalid, which allows remote attackers to cause a denial of service (messaging outage) or gain privileges via an update request.

    Published: 25 Aug 2008
    5
    Medium

    CVE-2008-3776

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Fujitsu Web-Based Admin View 2.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 25 Aug 2008
    2.1
    Low

    CVE-2008-3777

    Last Modified: 23 Apr 2026

    The SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on the S8300C with SES enabled, writes account names and passwords to the (1) alarm and (2) system logs during failed login attempts, which allows local users to obtain login credentials by reading these logs.

    Published: 25 Aug 2008
    Unknown

    CVE-2008-6800

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: None. Reason: this candidate is not a security issue. It was originally created based on one vendor's misinterpretation of an upstream changelog comment that referred to a race condition in the winbind daemon (aka winbindd) in Samba before 3.0.32. The upstream vendor states: "The Samba Team sees no way to exploit this race condition by a user of the system or an external attacker. In order to be able to trigger the race condition a privileged user (root) need to intentionally kill a winbind child process and carefully time the killing to trigger the race condition. Although, if the user is already privileged, it can more easily just kill the parent process directly." CVE concurs with the dispute. Notes: CVE users should not use this identifier

    Published: 25 Aug 2008
    6.9
    Medium

    CVE-2008-4993

    Last Modified: 23 Apr 2026

    qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.

    Published: 24 Aug 2008
    6.9
    Medium

    CVE-2008-4987

    Last Modified: 23 Apr 2026

    xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/ldconfig.tmp, (b) /tmp/ldconf.tmp, and (c) /tmp/ld.so.conf temporary files, related to the (1) get-maptools.sh and (2) get_shapelib.sh scripts.

    Published: 24 Aug 2008
    6.9
    Medium

    CVE-2008-4982

    Last Modified: 23 Apr 2026

    rkhunter in rkhunter 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rkhunter-debug temporary file. NOTE: this is probably a different vulnerability than CVE-2005-1270.

    Published: 24 Aug 2008
    2.6
    Low

    CVE-2008-4937

    Last Modified: 23 Apr 2026

    senddoc in OpenOffice.org (OOo) 2.4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/log.obr.##### temporary file.

    Published: 24 Aug 2008
    7.2
    High

    CVE-2008-4474

    Last Modified: 23 Apr 2026

    freeradius-dialupadmin in freeradius 2.0.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files in (1) backup_radacct, (2) clean_radacct, (3) monthly_tot_stats, (4) tot_stats, and (5) truncate_radacct.

    Published: 24 Aug 2008
    6.6
    Medium

    CVE-2008-4191

    Last Modified: 23 Apr 2026

    extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extract-table.csv temporary file.

    Published: 24 Aug 2008
    4.4
    Medium

    CVE-2008-4190

    Last Modified: 23 Apr 2026

    The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.

    Published: 24 Aug 2008
    7.2
    High

    CVE-2008-3949

    Last Modified: 23 Apr 2026

    emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file.

    Published: 24 Aug 2008
    6.9
    Medium

    CVE-2008-3931

    Last Modified: 23 Apr 2026

    javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    Published: 24 Aug 2008
    6.9
    Medium

    CVE-2008-4192

    Last Modified: 23 Apr 2026

    The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/eglog temporary file.

    Published: 24 Aug 2008
    6.9
    Medium

    CVE-2008-5007

    Last Modified: 23 Apr 2026

    create_lazarus_export_tgz.sh in lazarus 0.9.24 allows local users to overwrite or delete arbitrary files via a symlink attack on a (1) /tmp/lazarus.tgz temporary file or a (2) /tmp/lazarus temporary directory.

    Published: 24 Aug 2008
    5
    Medium

    CVE-2008-3790

    Last Modified: 23 Apr 2026

    The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."

    Published: 23 Aug 2008
    7.5
    High

    CVE-2008-3768

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in an edit_registry action to index.php, (2) a vector involving the check_email function, and other vectors.

    Published: 22 Aug 2008
    7.5
    High

    CVE-2008-3772

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 22 Aug 2008
    4.4
    Medium

    CVE-2008-3775

    Last Modified: 23 Apr 2026

    Folder Lock 5.9.5 and earlier uses weak encryption (ROT-25) for the password, which allows local administrators to obtain sensitive information by reading and decrypting the QualityControl\_pack registry value.

    Published: 22 Aug 2008
    6.8
    Medium

    CVE-2008-3769

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/create_order_new.php in Freeway 1.4.1.171, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the include_page parameter.

    Published: 22 Aug 2008
    7.5
    High

    CVE-2008-3774

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Aug 2008
    6.8
    Medium

    CVE-2008-3770

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Freeway 1.4.1.171, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter to (1) includes/events_application_top.php; (2) english/account.php, (3) french/account.php, and (4) french/account_newsletters.php in includes/languages/; (5) includes/modules/faqdesk/faqdesk_article_require.php; (6) includes/modules/newsdesk/newsdesk_article_require.php; (7) card1.php, (8) loginbox.php, and (9) whos_online.php in templates/Freeway/boxes/; and (10) templates/Freeway/mainpage_modules/mainpage.php. NOTE: vector 1 may be the same as CVE-2008-3677.

    Published: 22 Aug 2008
    4.3
    Medium

    CVE-2008-3773

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in vBulletin 3.7.2 PL1 and 3.6.10 PL3, when "Show New Private Message Notification Pop-Up" is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a private message subject (aka newpm[title]).

    Published: 22 Aug 2008
    4.3
    Medium

    CVE-2008-3771

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in members.php in Pars4u Videosharing 1 allows remote attackers to inject arbitrary web script or HTML via the PageNo parameter.

    Published: 22 Aug 2008
    7.5
    High

    CVE-2008-3767

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in classified.php in phpBazar 2.0.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Published: 22 Aug 2008
    5
    Medium

    CVE-2008-3766

    Last Modified: 23 Apr 2026

    Realtime Internet Band Rehearsal Low-Latency (Internet) Connection tool (llcon) before 2.1.2 allows remote attackers to cause a denial of service (application crash) via malformed protocol messages.

    Published: 22 Aug 2008
    9.3
    Critical

    CVE-2008-4101

    Last Modified: 23 Apr 2026

    Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.

    Published: 22 Aug 2008
    9.3
    Critical

    CVE-2008-3844

    Last Modified: 23 Apr 2026

    Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.

    Published: 22 Aug 2008
    2.1
    Low

    CVE-2008-3789

    Last Modified: 23 Apr 2026

    Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows local users to modify the membership of Unix groups.

    Published: 22 Aug 2008
    4.9
    Medium

    CVE-2008-3761

    Last Modified: 23 Apr 2026

    hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, which allows local users to cause a denial of service via a crafted IOCTL request.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3753

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details.php in YourFreeWorld Programs Rating Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    6.8
    Medium

    CVE-2008-3763

    Last Modified: 23 Apr 2026

    Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is enabled, allows remote attackers to overwrite arbitrary variables related to the db config file. NOTE: this can be leveraged for code injection by overwriting the language file.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3765

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3762

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the dep parameter, related to lack of input sanitization in the get function in global.php.

    Published: 21 Aug 2008
    4.3
    Medium

    CVE-2008-3758

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Lussumo Vanilla 1.1.4 and earlier (1) allow remote attackers to inject arbitrary web script or HTML via the NewPassword parameter to people.php, and allow remote authenticated users to inject arbitrary web script or HTML via the (2) Account picture and (3) Icon fields in account.php. NOTE: some of these details are obtained from third party information.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3764

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via the test parameter, and probably arbitrary parameters, to chat.php.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3748

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3749

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld URL Rotator Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3751

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Short Url & Url Tracker Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3755

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3756

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3757

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in tr1.php in YourFreeWorld Forced Matrix Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3759

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in ajax/UpdateCheck.php in Vanilla 1.1.4 and earlier has unknown impact and remote attack vectors.

    Published: 21 Aug 2008
    4.3
    Medium

    CVE-2008-3760

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the sign-out page in Vanilla 1.1.4 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout via a SignOutNow action to people.php.

    Published: 21 Aug 2008
    7.5
    High

    CVE-2008-3754

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in trl.php in YourFreeWorld Stylish Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 21 Aug 2008
    4.7
    Medium

    CVE-2008-4113

    Last Modified: 23 Apr 2026

    The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.

    Published: 21 Aug 2008