CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2008-3792

    Last Modified: 23 Apr 2026

    net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (NULL pointer dereference and panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst, (7) sctp_getsockopt_active_key, (8) sctp_getsockopt_peer_auth_chunks, or (9) sctp_getsockopt_local_auth_chunks.

    Published: 21 Aug 2008
    7.2
    High

    CVE-2008-5702

    Last Modified: 23 Apr 2026

    Buffer underflow in the ibwdt_ioctl function in drivers/watchdog/ib700wdt.c in the Linux kernel before 2.6.28-rc1 might allow local users to have an unknown impact via a certain /dev/watchdog WDIOC_SETTIMEOUT IOCTL call.

    Published: 21 Aug 2008
    6.5
    Medium

    CVE-2008-3718

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) id parameter to show_topic.php and the (2) user parameter to profile.php.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3719

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL commands via the id parameter in a deadlink action.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3724

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Papoo before 3.7.2 allows remote attackers to execute arbitrary SQL commands via the suchanzahl parameter.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3725

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Aug 2008
    4.3
    Medium

    CVE-2008-3726

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 20 Aug 2008
    5
    Medium

    CVE-2008-3727

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 20 Aug 2008
    9.3
    Critical

    CVE-2008-3732

    Last Modified: 23 Apr 2026

    Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TTA file, which triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 20 Aug 2008
    9.3
    Critical

    CVE-2008-3733

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .eop (aka playlist) file with a ProjectElement element that contains a long Name element.

    Published: 20 Aug 2008
    9.3
    Critical

    CVE-2008-3734

    Last Modified: 23 Apr 2026

    Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP servers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in a connection greeting (response).

    Published: 20 Aug 2008
    4.3
    Medium

    CVE-2008-3735

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHPizabi before 848 Core HotFix Pack 3 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a blogs.search action.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3721

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the language_dir parameter.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3729

    Last Modified: 23 Apr 2026

    Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request with (1) an IsAdmin=true cookie value or (2) no cookie.

    Published: 20 Aug 2008
    4.3
    Medium

    CVE-2008-3730

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nordicwind Document Management System (NOAH) before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Aug 2008
    6.3
    Medium

    CVE-2008-3723

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a .. (dot dot), (2) a URL, or possibly (3) a full pathname in the id parameter in an admin.templates.edittemplate action. NOTE: some of these details are obtained from third party information.

    Published: 20 Aug 2008
    4
    Medium

    CVE-2008-3731

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3720

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3722

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/neu.asp in fipsCMS 2.1 allows remote attackers to execute arbitrary SQL commands via the kat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Aug 2008
    5
    Medium

    CVE-2008-3728

    Last Modified: 23 Apr 2026

    Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to determine the installation path, IP addresses, and error messages via direct requests to files under LOG/.

    Published: 20 Aug 2008
    6.5
    Medium

    CVE-2008-3281

    Last Modified: 23 Apr 2026

    libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.

    Published: 20 Aug 2008
    7.5
    High

    CVE-2008-3706

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL commands via the adid parameter.

    Published: 19 Aug 2008
    7.5
    High

    CVE-2008-3705

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the CLogger::WriteFormated function in echoware/Logger.cpp in EchoVNC Linux before 1.1.2 allows remote echoServers to execute arbitrary code via a large (1) group or (2) user list, aka a "very crowded echoServer" attack. NOTE: some of these details are obtained from third party information.

    Published: 19 Aug 2008
    7.5
    High

    CVE-2008-3711

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter in a browse action.

    Published: 19 Aug 2008
    2.6
    Low

    CVE-2008-3715

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in inc-core-admin-editor-previouscolorsjs.php in the FlexCMS 2.5 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the PreviousColorsString parameter.

    Published: 19 Aug 2008
    6
    Medium

    CVE-2008-3716

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Harmoni before 1.6.0 allows remote attackers to make administrative modifications via a (1) save or (2) delete action to an unspecified component.

    Published: 19 Aug 2008
    5
    Medium

    CVE-2008-3717

    Last Modified: 23 Apr 2026

    Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.

    Published: 19 Aug 2008
    7.5
    High

    CVE-2008-3713

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via the pro_id parameter.

    Published: 19 Aug 2008
    4.3
    Medium

    CVE-2008-3709

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to inject arbitrary web script or HTML via the (1) lOptionsOptions, (2) lNavAdminOptions, or (3) lNavReturn parameter to options.php; or the (4) lNavReturn parameter to subscribe.php.

    Published: 19 Aug 2008
    7.5
    High

    CVE-2008-3707

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the script_path parameter to (1) flat_read.php, (2) post.php, (3) process_post.php, (4) process_search.php, (5) forum.php, (6) process_subscribe.php, (7) read.php, (8) search.php, (9) subscribe.php in path/; and (10) add_ban.php, (11) add_ban_form.php, (12) add_board.php, (13) add_vip.php, (14) add_vip_form.php, (15) copy_ban.php, (16) copy_vip.php, (17) delete_ban.php, (18) delete_board.php, (19) delete_messages.php, (20) delete_vip.php, (21) edit_ban.php, (22) edit_board.php, (23) edit_vip.php, (24) index.php, (25) lock_messages.php, (26) login.php, (27) modify_ban_list.php, (28) modify_vip_list.php, (29) move_messages.php, (30) process_add_board.php, (31) process_ban.php, (32) process_delete_ban.php, (33) process_delete_board.php, (34) process_delete_messages.php, (35) process_delete_vip.php, (36) process_edit_board.php, (37) process_lock_messages.php, (38) process_login.php, (39) process_move_messages.php, (40) process_sticky_messages.php, (41) process_vip.php, and (42) sticky_messages.php in path/adminopts. NOTE: the include/common.php vector is covered by CVE-2006-2871. NOTE: some of these vectors might not be vulnerabilities under proper installation.

    Published: 19 Aug 2008
    4.3
    Medium

    CVE-2008-3708

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (dot dot) in the id parameter to (1) news/index.dot and (2) getting_started/macros/macros_detail.dot.

    Published: 19 Aug 2008
    5.1
    Medium

    CVE-2008-3710

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) script_path parameter to (a) options.php and the (2) lang_code parameter to (b) copy_vip.php and (c) process_edit_board.php in adminopts/. NOTE: some of these vectors might not be vulnerabilities under proper installation.

    Published: 19 Aug 2008
    2.6
    Low

    CVE-2008-3712

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mambo 4.6.2 and 4.6.5, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to mambots/editors/mostlyce/jscripts/tiny_mce/filemanager/connectors/php/connector.php and the (2) mosConfig_sitename parameter to administrator/popups/index3pop.php.

    Published: 19 Aug 2008
    Unknown

    CVE-2008-2737

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3558. Reason: This candidate is a duplicate of CVE-2008-3558. Notes: All CVE users should reference CVE-2008-3558 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Aug 2008
    9.3
    Critical

    CVE-2008-3704

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."

    Published: 18 Aug 2008
    7.5
    High

    CVE-2008-2233

    Last Modified: 23 Apr 2026

    The client in Openwsman 1.2.0 and 2.0.0, in unknown configurations, allows remote Openwsman servers to replay SSL sessions via unspecified vectors.

    Published: 18 Aug 2008
    8.1
    High

    CVE-2008-3324

    Last Modified: 23 Apr 2026

    The PartyGaming PartyPoker client program 121/120 does not properly verify the authenticity of updates, which allows remote man-in-the-middle attackers to execute arbitrary code via a Trojan horse update.

    Published: 18 Aug 2008
    10
    Critical

    CVE-2008-3703

    Last Modified: 23 Apr 2026

    The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.

    Published: 18 Aug 2008
    7.5
    High

    CVE-2008-2234

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Openwsman 1.2.0 and 2.0.0 allow remote attackers to execute arbitrary code via a crafted "Authorization: Basic" HTTP header.

    Published: 18 Aug 2008
    4.3
    Medium

    CVE-2008-3873

    Last Modified: 23 Apr 2026

    The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to populate the clipboard with a URL that is difficult to delete and does not require user interaction to populate the clipboard, as exploited in the wild in August 2008.

    Published: 18 Aug 2008
    6.5
    Medium

    CVE-2008-3701

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in staff/index.php in Kayako SupportSuite 3.20.02 and earlier allows remote authenticated users to execute arbitrary SQL commands via the customfieldlinkid parameter in a delcflink action.

    Published: 15 Aug 2008
    4.3
    Medium

    CVE-2008-3700

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Kayako SupportSuite 3.20.02 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the sessionid parameter in a livesupport startclientchat action to visitor/index.php; (2) the filter parameter in a news view action to index.php; or the Full Name field in a (3) account creation, (4) ticket opening, or (5) chat request operation.

    Published: 15 Aug 2008
    9.3
    Critical

    CVE-2008-3702

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.

    Published: 15 Aug 2008
    4.3
    Medium

    CVE-2008-3746

    Last Modified: 23 Apr 2026

    neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.

    Published: 15 Aug 2008
    4.9
    Medium

    CVE-2008-3686

    Last Modified: 23 Apr 2026

    The rt6_fill_node function in net/ipv6/route.c in Linux kernel 2.6.26-rc4, 2.6.26.2, and possibly other 2.6.26 versions, allows local users to cause a denial of service (kernel OOPS) via IPv6 requests when no IPv6 input device is in use, which triggers a NULL pointer dereference.

    Published: 14 Aug 2008
    6.8
    Medium

    CVE-2008-3687

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the flask_security_label function in Xen 3.3, when compiled with the XSM:FLASK module, allows unprivileged domain users (domU) to execute arbitrary code via the flask_op hypercall.

    Published: 14 Aug 2008
    7.5
    High

    CVE-2008-3688

    Last Modified: 23 Apr 2026

    sockethandler.cpp in HTTP Antivirus Proxy (HAVP) 0.88 allows remote attackers to cause a denial of service (hang) by connecting to a non-responsive server, which triggers an infinite loop due to an uninitialized variable.

    Published: 14 Aug 2008
    5
    Medium

    CVE-2008-3683

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.5 before SP6 allows remote attackers to cause a denial of service (failure to accept connections) via unknown vectors, probably related to exhaustion of file descriptors.

    Published: 14 Aug 2008
    4.3
    Medium

    CVE-2008-3676

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long series of IMAP commands.

    Published: 14 Aug 2008
    6.8
    Medium

    CVE-2008-3677

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in includes/events_application_top.php in Freeway before 1.4.2.197 allows remote attackers to include and execute arbitrary local files via unspecified vectors.

    Published: 14 Aug 2008