CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1663

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) 2.1.10 and 2.1.11 on Linux and Windows allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jul 2008
    4.9
    Medium

    CVE-2008-3077

    Last Modified: 23 Apr 2026

    arch/x86/kernel/ptrace.c in the Linux kernel before 2.6.25.10 on the x86_64 platform leaks task_struct references into the sys32_ptrace function, which allows local users to cause a denial of service (system crash) or have unspecified other impact via unknown vectors, possibly a use-after-free vulnerability.

    Published: 9 Jul 2008
    5.1
    Medium

    CVE-2008-3080

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.

    Published: 9 Jul 2008
    5.1
    Medium

    CVE-2007-1899

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a viewuser action to index.php, and allow remote authenticated administrators to execute arbitrary SQL commands via (2) the post_id parameter in an edit action to admin.php.

    Published: 9 Jul 2008
    5.3
    Medium

    CVE-2007-3650

    Last Modified: 23 Apr 2026

    myWebland myBloggie 2.1.6 allow remote attackers to obtain sensitive information via (1) an invalid year parameter to calendar.php, reached through index.php; (2) a direct request to common.php; and (3) a mode array parameter in the query string to login.php, which reveal the installation path in various error messages.

    Published: 9 Jul 2008
    5.3
    Medium

    CVE-2007-3651

    Last Modified: 23 Apr 2026

    class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to obtain sensitive information via a '; (quote semicolon) sequence in the id parameter, which reveals the installation path in an error message.

    Published: 9 Jul 2008
    9.8
    Critical

    CVE-2007-3652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in class/page.php in Farsi Script (aka FaScript) FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: this might be the same issue as CVE-2008-0328.

    Published: 9 Jul 2008
    10
    Critical

    CVE-2008-3079

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors.

    Published: 9 Jul 2008
    4.3
    Medium

    CVE-2008-3082

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway 4 and 5 allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.

    Published: 9 Jul 2008
    7.5
    High

    CVE-2008-3083

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Brightcode Weblinks (com_brightweblinks) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 9 Jul 2008
    5
    Medium

    CVE-2008-3102

    Last Modified: 23 Apr 2026

    Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.

    Published: 9 Jul 2008
    7.8
    High

    CVE-2008-3078

    Last Modified: 23 Apr 2026

    Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a canvas image.

    Published: 9 Jul 2008
    6.5
    Medium

    CVE-2008-3081

    Last Modified: 23 Apr 2026

    Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form.

    Published: 9 Jul 2008
    9
    Critical

    CVE-2008-0086

    Last Modified: 23 Apr 2026

    Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

    Published: 8 Jul 2008
    4.3
    Medium

    CVE-2008-2248

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.

    Published: 8 Jul 2008
    9.4
    Critical

    CVE-2008-1454

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft DNS in Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 allows remote attackers to conduct cache poisoning attacks via unknown vectors related to accepting "records from a response that is outside the remote server's authority," aka "DNS Cache Poisoning Vulnerability," a different vulnerability than CVE-2008-1447.

    Published: 8 Jul 2008
    4.3
    Medium

    CVE-2008-2247

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability than CVE-2008-2248.

    Published: 8 Jul 2008
    5
    Medium

    CVE-2008-0085

    Last Modified: 23 Apr 2026

    SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 does not initialize memory pages when reallocating memory, which allows database operators to obtain sensitive information (database contents) via unknown vectors related to memory page reuse.

    Published: 8 Jul 2008
    9
    Critical

    CVE-2008-0107

    Last Modified: 23 Apr 2026

    Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."

    Published: 8 Jul 2008
    9.3
    Critical

    CVE-2008-1435

    Last Modified: 23 Apr 2026

    Windows Explorer in Microsoft Windows Vista up to SP1, and Server 2008, allows user-assisted remote attackers to execute arbitrary code via crafted saved-search (.search-ms) files that are not properly handled when saving, aka "Windows Saved Search Vulnerability."

    Published: 8 Jul 2008
    9
    Critical

    CVE-2008-0106

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft SQL Server 2005 SP1 and SP2, and 2005 Express Edition SP1 and SP2, allows remote authenticated users to execute arbitrary code via a crafted insert statement.

    Published: 8 Jul 2008
    4.3
    Medium

    CVE-2008-3069

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MyBB before 1.2.13 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) portal.php and (2) inc/functions_post.php.

    Published: 8 Jul 2008
    7.5
    High

    CVE-2008-3070

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in inc/datahandler/user.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $user['language'] variable, probably related to SQL injection.

    Published: 8 Jul 2008
    7.5
    High

    CVE-2008-3072

    Last Modified: 23 Apr 2026

    Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13, when running in PHP before 4.2.0, does not properly seed the random number generator, which has unknown impact and attack vectors.

    Published: 8 Jul 2008
    7.5
    High

    CVE-2008-3073

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Simple Machines Forum (SMF) 1.1.x before 1.1.5 and 1.0.x before 1.0.13 has unknown impact and attack vectors, probably cross-site scripting (XSS), related to "use of the html-tag."

    Published: 8 Jul 2008
    7.5
    High

    CVE-2008-3071

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in inc/class_language.php in MyBB before 1.2.13 has unknown impact and attack vectors related to the $language variable.

    Published: 8 Jul 2008
    6.8
    Medium

    CVE-2008-1447

    Last Modified: 23 Apr 2026

    The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."

    Published: 8 Jul 2008
    10
    Critical

    CVE-2008-3108

    Last Modified: 23 Apr 2026

    Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to font processing.

    Published: 8 Jul 2008
    4.3
    Medium

    CVE-2008-3110

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.

    Published: 8 Jul 2008
    10
    Critical

    CVE-2008-3113

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.

    Published: 8 Jul 2008
    5
    Medium

    CVE-2008-3114

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.

    Published: 8 Jul 2008
    4.3
    Medium

    CVE-2008-3106

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.

    Published: 8 Jul 2008
    10
    Critical

    CVE-2008-3111

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent attackers to gain privileges via an untrusted application, as demonstrated by (a) an application that grants itself privileges to (1) read local files, (2) write to local files, or (3) execute local programs; and as demonstrated by (b) a long value associated with a java-vm-args attribute in a j2se tag in a JNLP file, which triggers a stack-based buffer overflow in the GetVMArgsOption function; aka CR 6557220.

    Published: 8 Jul 2008
    6.8
    Medium

    CVE-2008-3104

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.

    Published: 8 Jul 2008
    10
    Critical

    CVE-2008-3107

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

    Published: 8 Jul 2008
    7.5
    High

    CVE-2008-3109

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

    Published: 8 Jul 2008
    10
    Critical

    CVE-2008-3112

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.

    Published: 8 Jul 2008
    7.8
    High

    CVE-2008-3196

    Last Modified: 23 Apr 2026

    skeleton.c in yacc does not properly handle reduction of a rule with an empty right hand side, which allows context-dependent attackers to cause an out-of-bounds stack access when the yacc stack pointer points to the end of the stack.

    Published: 8 Jul 2008
    9.3
    Critical

    CVE-2008-3103

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to "perform unauthorized operations" via unspecified vectors.

    Published: 8 Jul 2008
    8.3
    High

    CVE-2008-3105

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving "processing of XML data" by a trusted application.

    Published: 8 Jul 2008
    5.1
    Medium

    CVE-2008-2667

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Courier Authentication Library (aka courier-authlib) before 0.60.6 on SUSE openSUSE 10.3 and 11.0, and other platforms, when MySQL and a non-Latin character set are used, allows remote attackers to execute arbitrary SQL commands via the username and unspecified other vectors.

    Published: 7 Jul 2008
    9.3
    Critical

    CVE-2008-2430

    Last Modified: 23 Apr 2026

    Integer overflow in the Open function in modules/demux/wav.c in VLC Media Player 0.8.6h on Windows allows remote attackers to execute arbitrary code via a large fmt chunk in a WAV file.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-2806

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3068

    Last Modified: 23 Apr 2026

    Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.

    Published: 7 Jul 2008
    6.8
    Medium

    CVE-2008-2463

    Last Modified: 23 Apr 2026

    The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3025

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3026

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3030

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an urunler action.

    Published: 7 Jul 2008
    7.5
    High

    CVE-2008-3031

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 7 Jul 2008
    4.3
    Medium

    CVE-2008-3032

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the phpMyAdmin (phpmyadmin) extension 3.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jul 2008