CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2008-2969

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download.php in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the dfile parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2967

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) query string to login.php and the (2) glb_sid parameter to hta/htmlarea.js.php, and allow remote authenticated users to inject arbitrary web script or HTML via an unspecified field in room.php.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2963

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to (a) index.php, and the (2) id parameter to (b) member.php and (c) post.php.

    Published: 2 Jul 2008
    2.6
    Low

    CVE-2008-2960

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.11.7, when register_globals is enabled and .htaccess support is disabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving scripts in libraries/.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2985

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in load_language.php in CMReams CMS 1.3.1.1 Beta 2, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page_language parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2980

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary web script or HTML via the (1) error_meldung parameter to admin/features/register/register.php, the (2) feature_language[ueberschrift] parameter to admin/features/memberlist/memberlist.php, the (3) language_array[ueberschrift] parameter to admin/features/lostpassword/lostpassword.php, the (4) language_feature[titel] parameter to admin/features/kalender/eingabe.php, and the (5) language_feature[bildmenu] parameter to admin/features/fotogalerie/eingabe.php.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2977

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Ourvideo CMS 9.5 allow remote attackers to execute arbitrary PHP code via a URL in the include_connection parameter to (1) edit_top_feature.php and (2) edit_topics_feature.php in phpi/.

    Published: 2 Jul 2008
    5
    Medium

    CVE-2008-2961

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in view/index.php in CMS Mini 0.2.2 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) path and (2) p parameter.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2989

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via the go parameter.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2988

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/upload.php in Benja CMS 0.1 allows remote attackers to upload and execute arbitrary PHP files via unspecified vectors, followed by a direct request to the file in billeder/.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2987

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Benja CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin_edit_submenu.php, (2) admin_new_submenu.php, and (3) admin_edit_topmenu.php in admin/.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2964

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2965

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in viewforum.php in JaxUltraBB (JUBB) 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the forum parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2962

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or HTML via the (1) s and (2) sort parameters to index.php, and the (3) id parameter to post.php.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2966

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in viewprofile.php in JaxUltraBB 2.0 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the user parameter. party information.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2970

    Last Modified: 23 Apr 2026

    Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSID parameter to (1) index.php and (2) login.php in homepg/.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2971

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links-extern.php in CiBlog 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2972

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in KbLance allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a comment action.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2973

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) sitename and (2) wmessage parameters.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2974

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in chatconfig.php in MM Chat 1.5, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the currentlang parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2975

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2979

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpi/login.php in Ourvideo CMS 9.5 allow remote attackers to inject arbitrary web script or HTML via the (1) top_page and (2) end_page parameters.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2981

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the thumb_template parameter.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2982

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) thumb_template parameter to (a) admin/templates/template_thumbnail.php, and the (2) language parameter to (b) account/account.php, (c) downloads/downloads.php, (d) forum/forum.php, (e) fotogalerie/delete.php, and (f) fotogalerie/fotogalerie.php in admin/features/.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2983

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Jul 2008
    9.3
    Critical

    CVE-2008-2959

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2800

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2801

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly implement JAR signing, which allows remote attackers to execute arbitrary code via (1) injection of JavaScript into documents within a JAR archive or (2) a JAR archive that uses relative URLs to JavaScript files.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-2802

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via an XUL document that includes a script from a chrome: URI that points to a fastload file, related to this file's "privilege level."

    Published: 2 Jul 2008
    5
    Medium

    CVE-2008-2807

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly handle an invalid .properties file for an add-on, which allows remote attackers to read uninitialized memory, as demonstrated by use of ISO 8859 encoding instead of UTF-8 encoding in a French .properties file.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2810

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.

    Published: 2 Jul 2008
    7.5
    High

    CVE-2008-1676

    Last Modified: 23 Apr 2026

    Red Hat PKI Common Framework (rhpki-common) in Red Hat Certificate System (aka Certificate Server or RHCS) 7.1 through 7.3, and Netscape Certificate Management System 6.x, does not recognize Certificate Authority profile constraints on Extensions, which might allow remote attackers to bypass intended restrictions and conduct man-in-the-middle attacks by submitting a certificate signing request (CSR) and using the resulting certificate.

    Published: 2 Jul 2008
    5
    Medium

    CVE-2008-2805

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving originalTarget and DOM Range.

    Published: 2 Jul 2008
    4.3
    Medium

    CVE-2008-2808

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site scripting (XSS) attacks or have unspecified other impact via a crafted filename.

    Published: 2 Jul 2008
    4
    Medium

    CVE-2008-2809

    Last Modified: 23 Apr 2026

    Mozilla 1.9 M8 and earlier, Mozilla Firefox 2 before 2.0.0.15, SeaMonkey 1.1.5 and other versions before 1.1.10, Netscape 9.0, and other Mozilla-based web browsers, when a user accepts an SSL server certificate on the basis of the CN domain name in the DN field, regard the certificate as also accepted for all domain names in subjectAltName:dNSName fields, which makes it easier for remote attackers to trick a user into accepting an invalid certificate for a spoofed web site.

    Published: 2 Jul 2008
    10
    Critical

    CVE-2008-2811

    Last Modified: 23 Apr 2026

    The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.

    Published: 2 Jul 2008
    5.5
    Medium

    CVE-2008-3275

    Last Modified: 23 Apr 2026

    The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denial of service ("overflow" of the UBIFS orphan area) via a series of attempted file creations within deleted directories.

    Published: 2 Jul 2008
    6.8
    Medium

    CVE-2008-2803

    Last Modified: 23 Apr 2026

    The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.

    Published: 2 Jul 2008
    4.4
    Medium

    CVE-2008-2958

    Last Modified: 23 Apr 2026

    Race condition in (1) checkinstall 1.6.1 and (2) installwatch allows local users to overwrite arbitrary files and have other impacts via symlink and possibly other attacks on temporary working directories.

    Published: 1 Jul 2008
    7.8
    High

    CVE-2008-2954

    Last Modified: 23 Apr 2026

    client/NmdcHub.cpp in Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via an empty private message, which triggers an out-of-bounds read.

    Published: 1 Jul 2008
    5
    Medium

    CVE-2008-2953

    Last Modified: 23 Apr 2026

    Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via "partial file list requests" that trigger a NULL pointer dereference.

    Published: 1 Jul 2008
    7.6
    High

    CVE-2008-2311

    Last Modified: 23 Apr 2026

    Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.

    Published: 1 Jul 2008
    6.8
    Medium

    CVE-2008-2309

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.

    Published: 1 Jul 2008
    4.4
    Medium

    CVE-2008-2314

    Last Modified: 23 Apr 2026

    Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.

    Published: 1 Jul 2008
    4.6
    Medium

    CVE-2008-2313

    Last Modified: 23 Apr 2026

    Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.

    Published: 1 Jul 2008
    4.6
    Medium

    CVE-2008-2308

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.

    Published: 1 Jul 2008
    10
    Critical

    CVE-2008-2799

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.

    Published: 1 Jul 2008
    10
    Critical

    CVE-2008-2798

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.

    Published: 1 Jul 2008
    7.5
    High

    CVE-2008-2376

    Last Modified: 23 Apr 2026

    Integer overflow in the rb_ary_fill function in array.c in Ruby before revision 17756 allows context-dependent attackers to cause a denial of service (crash) or possibly have unspecified other impact via a call to the Array#fill method with a start (aka beg) argument greater than ARY_MAX_SIZE. NOTE: this issue exists because of an incomplete fix for other closely related integer overflows.

    Published: 1 Jul 2008
    6.8
    Medium

    CVE-2008-2947

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote attackers to access restricted information from other domains via JavaScript that uses the Object data type for the value of a (1) location or (2) location.href property, related to incorrect determination of the origin of web script, aka "Window Location Property Cross-Domain Vulnerability." NOTE: according to Microsoft, CVE-2008-2948 and CVE-2008-2949 are duplicates of this issue, probably different attack vectors.

    Published: 30 Jun 2008