CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-3454

    Last Modified: 23 Apr 2026

    JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value to 1.

    Published: 4 Aug 2008
    10
    Critical

    CVE-2008-3455

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the rd parameter.

    Published: 4 Aug 2008
    7.6
    High

    CVE-2008-3459

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr and (2) iproute configuration directives, probably related to shell metacharacters.

    Published: 4 Aug 2008
    10
    Critical

    CVE-2008-3453

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."

    Published: 4 Aug 2008
    7.2
    High

    CVE-2008-3450

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service (panic) via unspecified vectors.

    Published: 4 Aug 2008
    6.8
    Medium

    CVE-2008-3446

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 4 Aug 2008
    5
    Medium

    CVE-2008-3447

    Last Modified: 23 Apr 2026

    The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop) via a malformed ZIP archive, probably related to invalid offsets.

    Published: 4 Aug 2008
    4.3
    Medium

    CVE-2008-3448

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to inject arbitrary web script or HTML via the letter parameter.

    Published: 4 Aug 2008
    5
    Medium

    CVE-2008-3449

    Last Modified: 23 Apr 2026

    MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests to the same folder.

    Published: 4 Aug 2008
    7.5
    High

    CVE-2008-3445

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter.

    Published: 4 Aug 2008
    4.3
    Medium

    CVE-2008-3444

    Last Modified: 23 Apr 2026

    The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

    Published: 4 Aug 2008
    9.3
    Critical

    CVE-2008-2320

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API.

    Published: 4 Aug 2008
    9.3
    Critical

    CVE-2008-2321

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments."

    Published: 4 Aug 2008
    4.6
    Medium

    CVE-2008-2324

    Last Modified: 23 Apr 2026

    The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.

    Published: 4 Aug 2008
    9.3
    Critical

    CVE-2008-2325

    Last Modified: 23 Apr 2026

    QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."

    Published: 4 Aug 2008
    9.3
    Critical

    CVE-2008-2322

    Last Modified: 23 Apr 2026

    Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF file with a long Type 1 font, which triggers a heap-based buffer overflow.

    Published: 4 Aug 2008
    7.1
    High

    CVE-2008-2323

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Data Detectors Engine in Apple Mac OS X 10.5.4 allows attackers to cause a denial of service (resource consumption) via crafted textual content in messages.

    Published: 4 Aug 2008
    7.5
    High

    CVE-2008-3423

    Last Modified: 23 Apr 2026

    IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

    Published: 4 Aug 2008
    2.1
    Low

    CVE-2008-3272

    Last Modified: 23 Apr 2026

    The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.

    Published: 2 Aug 2008
    10
    Critical

    CVE-2008-1662

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify arbitrary files, related to an "empty systems list."

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3433

    Last Modified: 23 Apr 2026

    SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3434

    Last Modified: 23 Apr 2026

    Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3435

    Last Modified: 23 Apr 2026

    LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3436

    Last Modified: 23 Apr 2026

    The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3440

    Last Modified: 23 Apr 2026

    Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3441

    Last Modified: 23 Apr 2026

    Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    9.3
    Critical

    CVE-2007-2952

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the filter service (aka k9filter.exe) in Blue Coat K9 Web Protection 3.2.44 with Filter 3.2.32 allow (1) remote attackers to execute arbitrary code via a long HTTP Referer header to the K9 Web Protection Administration interface and (2) man-in-the-middle attackers to execute arbitrary code via an HTTP response with a long HTTP version field.

    Published: 1 Aug 2008
    4.4
    Medium

    CVE-2008-1810

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable.

    Published: 1 Aug 2008
    10
    Critical

    CVE-2008-3175

    Last Modified: 23 Apr 2026

    Integer underflow in rxRPC.dll in the LGServer service in the server in CA ARCserve Backup for Laptops and Desktops 11.0 through 11.5 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted message that triggers a buffer overflow.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3437

    Last Modified: 23 Apr 2026

    OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    8.1
    High

    CVE-2008-3438

    Last Modified: 23 Apr 2026

    Apple Mac OS X does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3439

    Last Modified: 23 Apr 2026

    SpeedBit Video Acceleration before 2.2.1.8 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    7.5
    High

    CVE-2008-3442

    Last Modified: 23 Apr 2026

    WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.

    Published: 1 Aug 2008
    4.3
    Medium

    CVE-2008-1232

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.

    Published: 1 Aug 2008
    5
    Medium

    CVE-2008-2370

    Last Modified: 23 Apr 2026

    Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.

    Published: 1 Aug 2008
    6.5
    Medium

    CVE-2008-3428

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid parameter.

    Published: 31 Jul 2008
    2.1
    Low

    CVE-2008-3426

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Solaris Platform Information and Control Library daemon (picld) in Sun Solaris 8 through 10, and OpenSolaris builds snv_01 through snv_95, allows local users to cause a denial of service via unknown vectors that prevent operation of utilities such as prtdiag, prtpicl, and prtfru.

    Published: 31 Jul 2008
    Unknown

    CVE-2008-3427

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3420. Reason: This candidate is a duplicate of CVE-2008-3420. Notes: All CVE users should reference CVE-2008-3420 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 31 Jul 2008
    6.5
    Medium

    CVE-2008-3425

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Sun Java System Web Server 7.0 plugin in Sun N1 Service Provisioning System (SPS) 5.2 and 6.0 allows remote authenticated SPS users to gain administrative access to the web server via unknown attack vectors.

    Published: 31 Jul 2008
    6.8
    Medium

    CVE-2008-3429

    Last Modified: 23 Apr 2026

    Buffer overflow in URI processing in HTTrack and WinHTTrack before 3.42-3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long URL.

    Published: 31 Jul 2008
    9.3
    Critical

    CVE-2008-3430

    Last Modified: 23 Apr 2026

    Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: this might only be a vulnerability in certain insecure configurations of Internet Explorer.

    Published: 31 Jul 2008
    5
    Medium

    CVE-2008-3410

    Last Modified: 23 Apr 2026

    Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a certain size field is greater than the total packet length, aka attack 2 in ut3mendo.c.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3412

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a (1) pro_show or (2) disppro action to the default URI.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3413

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3414

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in line2.php in SiteAdmin allows remote attackers to execute arbitrary SQL commands via the art parameter.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3417

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the r parameter, a different vector than CVE-2006-6115 and CVE-2007-2561.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3418

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.php in TriO 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3419

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands via the UID parameter.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3420

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to browse.php or (2) the s parameter in an exhibitions action to detail.php.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3421

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Blackboard Academic Suite 8.0.260.7 allow remote attackers to hijack the authentication of student users for requests that change configuration and enrollments via unspecified input to (1) update_module.jsp, (2) enroll_course.pl, and (3) unenroll.jsp.

    Published: 31 Jul 2008