CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-2595

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2600

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to MDSYS.SDO_TOPO_MAP.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2615

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.

    Published: 15 Jul 2008
    4
    Medium

    CVE-2008-2621

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2622.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-2578

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 and 9.2 MP1 has unknown impact and local attack vectors.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2591

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Database Vault component in Oracle Database 9.2.0.8DV, 10.2.0.3, and 11.1.0.6 has unknown impact and remote authenticated attack vectors.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-2599

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TimesTen Client/Server component in Oracle Times Ten In-Memory Database 7.0.3.0.0 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2597 and CVE-2008-2598.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-2607

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 has unknown impact and remote authenticated attack vectors related to SYS.DBMS_AQELM. NOTE: the previous information was obtained from the Oracle July 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a buffer overflow that allows attackers to cause a denial of service (database corruption) and possibly execute arbitrary code via a long argument to an unspecified procedure.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-2614

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.3.3 has unknown impact and remote attack vectors.

    Published: 15 Jul 2008
    6.8
    Medium

    CVE-2008-3185

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-3186

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blog (Blogger) allow remote attackers to inject arbitrary web script or HTML via the membername parameter to (1) members.php, (2) comments.php, (3) photos.php, (4) archive.php, or (5) cat.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Jul 2008
    9.3
    Critical

    CVE-2008-3182

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL.

    Published: 15 Jul 2008
    5
    Medium

    CVE-2008-3177

    Last Modified: 23 Apr 2026

    Sophos virus detection engine 2.75 on Linux and Unix, as used in Sophos Email Appliance, Pure Message for Unix, and Sophos Anti-Virus Interface (SAVI), allows remote attackers to cause a denial of service (engine crash) via zero-length MIME attachments.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-3179

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-3180

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) pageid parameter or (2) PATH_INFO.

    Published: 15 Jul 2008
    6.5
    Medium

    CVE-2008-3181

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-3183

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the dirDepth parameter.

    Published: 15 Jul 2008
    4.3
    Medium

    CVE-2008-3184

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x versions, allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO (PHP_SELF) or (2) the do parameter, as demonstrated by requests to upload/admincp/faq.php. NOTE: this issue can be leveraged to execute arbitrary PHP code.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-3178

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg content type, then accessing it via a direct request to the file in upload/.

    Published: 15 Jul 2008
    7.5
    High

    CVE-2008-3198

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arbitrary web script into a chrome document via unspecified vectors, as demonstrated by injection into a XUL error page. NOTE: this can be leveraged to execute arbitrary code using CVE-2008-2933.

    Published: 15 Jul 2008
    9.3
    Critical

    CVE-2008-6235

    Last Modified: 23 Apr 2026

    The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename used by the (1) "D" (delete) command or (2) b:netrw_curdir variable, as demonstrated using the netrw.v4 and netrw.v5 test cases.

    Published: 15 Jul 2008
    9.3
    Critical

    CVE-2008-3075

    Last Modified: 23 Apr 2026

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a ZIP archive and possibly (2) the filename of the first file in a ZIP archive, which is not properly handled by zip.vim in the VIM ZIP plugin (zipPlugin.vim) v.11 through v.21, as demonstrated by the zipplugin and zipplugin.v2 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3074. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

    Published: 15 Jul 2008
    2.6
    Low

    CVE-2008-2933

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.

    Published: 15 Jul 2008
    9.3
    Critical

    CVE-2008-3074

    Last Modified: 23 Apr 2026

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the first file in a tar archive, which is not properly handled by the VIM TAR plugin (tar.vim) v.10 through v.22, as demonstrated by the shellescape, tarplugin.v2, tarplugin, and tarplugin.updated test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3075. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.

    Published: 15 Jul 2008
    9.3
    Critical

    CVE-2008-3076

    Last Modified: 23 Apr 2026

    The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712.

    Published: 15 Jul 2008
    6.8
    Medium

    CVE-2008-3165

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter, as demonstrated using content.php, a different vector than CVE-2007-4805.

    Published: 14 Jul 2008
    9.3
    Critical

    CVE-2008-3166

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter.

    Published: 14 Jul 2008
    5
    Medium

    CVE-2008-3168

    Last Modified: 23 Apr 2026

    The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers to determine the PRNG seed.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-3173

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot character, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking." NOTE: this issue may exist because of an insufficient fix for CVE-2004-0866.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-3170

    Last Modified: 23 Apr 2026

    Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking," a related issue to CVE-2004-0746, CVE-2004-0866, and CVE-2004-0867.

    Published: 14 Jul 2008
    5
    Medium

    CVE-2008-3171

    Last Modified: 23 Apr 2026

    Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to obtain potentially sensitive information by reading Referer log data.

    Published: 14 Jul 2008
    9.3
    Critical

    CVE-2008-3162

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-3163

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dodosmail_header_file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jul 2008
    7.6
    High

    CVE-2008-3164

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter. NOTE: it was later reported that 3.01a is also affected.

    Published: 14 Jul 2008
    9.3
    Critical

    CVE-2008-3167

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c) ray/modules/global/inc/content.inc.php. NOTE: vector 1 might be a problem in SafeHTML instead of Dolphin.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-3172

    Last Modified: 23 Apr 2026

    Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session, aka "Cross-Site Cooking."

    Published: 14 Jul 2008
    10
    Critical

    CVE-2008-3169

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in Empire Server before 4.3.15 allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors, related to a "coordinate normalization bug." NOTE: some of these details are obtained from third party information.

    Published: 14 Jul 2008
    4.3
    Medium

    CVE-2008-1588

    Last Modified: 23 Apr 2026

    Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode ideographic spaces in the URL.

    Published: 14 Jul 2008
    10
    Critical

    CVE-2008-2303

    Last Modified: 23 Apr 2026

    Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving JavaScript array indices that trigger an out-of-bounds access, a different vulnerability than CVE-2008-2307.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-2304

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a .funhouse file with a string XML element that contains many characters.

    Published: 14 Jul 2008
    5
    Medium

    CVE-2008-2318

    Last Modified: 23 Apr 2026

    The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.

    Published: 14 Jul 2008
    6.8
    Medium

    CVE-2008-1590

    Last Modified: 23 Apr 2026

    JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors that trigger memory corruption, a different vulnerability than CVE-2008-2317.

    Published: 14 Jul 2008
    9.3
    Critical

    CVE-2008-2317

    Last Modified: 23 Apr 2026

    WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.

    Published: 14 Jul 2008
    10
    Critical

    CVE-2008-3159

    Last Modified: 23 Apr 2026

    Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to "flawed arithmetic."

    Published: 14 Jul 2008
    4.3
    Medium

    CVE-2008-3161

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Accept, (2) Accept-Language, (3) UA-CPU, (4) Accept-Encoding, (5) User-Agent, or (6) Cookie HTTP header. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jul 2008
    4.3
    Medium

    CVE-2008-1589

    Last Modified: 23 Apr 2026

    Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for visiting a web site with a (1) self-signed or (2) invalid certificate, which makes it easier for remote attackers to spoof web sites.

    Published: 14 Jul 2008
    10
    Critical

    CVE-2008-1809

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."

    Published: 14 Jul 2008
    10
    Critical

    CVE-2008-3160

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer and IBM System Storage N series Gateway, have unknown impact and attack vectors.

    Published: 14 Jul 2008
    7.2
    High

    CVE-2008-3247

    Last Modified: 23 Apr 2026

    The LDT implementation in the Linux kernel 2.6.25.x before 2.6.25.11 on x86_64 platforms uses an incorrect size for ldt_desc, which allows local users to cause a denial of service (system crash) or possibly gain privileges via unspecified vectors.

    Published: 14 Jul 2008
    7.5
    High

    CVE-2008-4359

    Last Modified: 23 Apr 2026

    lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data.

    Published: 14 Jul 2008