CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-3408

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a crafted m3u file.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3409

    Last Modified: 23 Apr 2026

    Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a UDP packet containing a large value in a certain size field, followed by a data string of that size, aka attack 1 in ut3mendo.c.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3416

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrary SQL commands via the username parameter in a members action to index.php, related to an incorrect protection mechanism in the clean_string function in includes/functions.php.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3415

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bit parameter, as demonstrated by an upload to avatar/ of a .jpg file containing PHP sequences.

    Published: 31 Jul 2008
    10
    Critical

    CVE-2008-3411

    Last Modified: 23 Apr 2026

    The Axesstel AXW-D800 modem with D2_ETH_109_01_VEBR Jun-14-2006 software does not require authentication for (1) etc/config/System.html, (2) etc/config/Network.html, (3) etc/config/Security.html, (4) cgi-bin/sysconf.cgi, and (5) cgi-bin/route.cgi, which allows remote attackers to change the modem's configuration via direct requests.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3406

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 31 Jul 2008
    6.8
    Medium

    CVE-2008-3405

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Ricardo Amaral nzFotolog 0.4.1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action_file parameter.

    Published: 31 Jul 2008
    5
    Medium

    CVE-2008-3396

    Last Modified: 23 Apr 2026

    Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malformed packets.

    Published: 31 Jul 2008
    5
    Medium

    CVE-2008-3407

    Last Modified: 23 Apr 2026

    phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a login=right cookie.

    Published: 31 Jul 2008
    2.6
    Low

    CVE-2008-3398

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129.

    Published: 31 Jul 2008
    6.1
    Medium

    CVE-2008-3397

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS before 3_1.4_0.9 allows remote attackers to inject arbitrary web script or HTML via a cerberus_user cookie.

    Published: 31 Jul 2008
    5
    Medium

    CVE-2008-3395

    Last Modified: 23 Apr 2026

    Calacode @Mail 5.41 on Linux uses weak world-readable permissions for (1) webmail/libs/Atmail/Config.php and (2) webmail/webadmin/.htpasswd, which allows local users to obtain sensitive information by reading these files. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Jul 2008
    6.8
    Medium

    CVE-2008-3399

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3400

    Last Modified: 23 Apr 2026

    XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3401

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the hm parameter.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3402

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3403

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3404

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitrary web script or HTML via the link parameter.

    Published: 31 Jul 2008
    6.8
    Medium

    CVE-2008-3390

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3394

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.cfm in BookMine allow remote attackers to inject arbitrary web script or HTML via the (1) gallery and (2) search_string parameters.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3393

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events.cfm in BookMine allows remote attackers to execute arbitrary SQL commands via the events_id parameter.

    Published: 31 Jul 2008
    5.8
    Medium

    CVE-2008-3392

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in Web Wiz Forum 9.5 allows remote attackers to log out a user via a link or IMG tag to log_off_user.asp.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3391

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web script or HTML via the mode parameter to (1) admin_group_details.asp and (2) admin_category_details.asp.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-2935

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (aka exsltCryptoRc4DecryptFunction) functions in crypto.c in libexslt in libxslt 1.1.8 through 1.1.24 allow context-dependent attackers to execute arbitrary code via an XML file containing a long string as "an argument in the XSL input."

    Published: 31 Jul 2008
    4.9
    Medium

    CVE-2008-3535

    Last Modified: 23 Apr 2026

    Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrated by testcases/kernel/fs/ftest/ftest03 from the Linux Test Project.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-2315

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Python 2.5.2 and earlier allow context-dependent attackers to have an unknown impact via vectors related to the (1) stringobject, (2) unicodeobject, (3) bufferobject, (4) longobject, (5) tupleobject, (6) stropmodule, (7) gcmodule, and (8) mmapmodule modules. NOTE: The expandtabs integer overflows in stringobject and unicodeobject in 2.5.2 are covered by CVE-2008-5031.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-1376

    Last Modified: 23 Apr 2026

    A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allow remote attackers to bypass intended access restrictions.

    Published: 31 Jul 2008
    4.9
    Medium

    CVE-2008-2235

    Last Modified: 23 Apr 2026

    OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

    Published: 31 Jul 2008
    4.3
    Medium

    CVE-2008-3422

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the ASP.net class libraries in Mono 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted attributes related to (1) HtmlControl.cs (PreProcessRelativeReference), (2) HtmlForm.cs (RenderAttributes), (3) HtmlInputButton (RenderAttributes), (4) HtmlInputRadioButton (RenderAttributes), and (5) HtmlSelect (RenderChildren).

    Published: 31 Jul 2008
    10
    Critical

    CVE-2008-3496

    Last Modified: 23 Apr 2026

    Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.

    Published: 31 Jul 2008
    7.5
    High

    CVE-2008-3388

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Def-Blog 1.0.3 allow remote attackers to execute arbitrary SQL commands via the article parameter to (1) comaddok.php and (2) comlook.php.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3382

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_a parameter.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3384

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) module and (2) file parameters.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3386

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute arbitrary SQL commands via the UID parameter, a different vector than CVE-2007-4086.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3387

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3383

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via the cat_a parameter in a browse action.

    Published: 30 Jul 2008
    4.3
    Medium

    CVE-2008-3380

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows remote attackers to inject arbitrary web script or HTML via the rs parameter.

    Published: 30 Jul 2008
    6.8
    Medium

    CVE-2008-3385

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3366

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might overlap CVE-2008-1774.

    Published: 30 Jul 2008
    4.3
    Medium

    CVE-2008-3367

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RTE_popup_link.asp in Web Wiz Rich Text Editor (RTE) 3.x and 4.x before 4.03 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Published: 30 Jul 2008
    6.5
    Medium

    CVE-2008-3368

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3369

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in products_rss.php in ViArt Shop 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Published: 30 Jul 2008
    5
    Medium

    CVE-2008-3373

    Last Modified: 23 Apr 2026

    The files parsing engine in Grisoft AVG Anti-Virus before 8.0.156 allows remote attackers to cause a denial of service (engine crash) via a crafted UPX compressed file, which triggers a divide-by-zero error.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3374

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3375

    Last Modified: 23 Apr 2026

    The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authentication and gain administrative access via a boolean value within serialized data in a JMU_Cookie cookie.

    Published: 30 Jul 2008
    10
    Critical

    CVE-2008-3376

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in JamRoom before 3.4.0 have unknown impact and attack vectors.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3377

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands via the image_id parameter.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3378

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 30 Jul 2008
    7.5
    High

    CVE-2008-3371

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Published: 30 Jul 2008
    4.3
    Medium

    CVE-2008-3379

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Snark VisualPic 0.3.1 allows remote attackers to inject arbitrary web script or HTML via the pic parameter to the default URI. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 30 Jul 2008