CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2008-2946

    Last Modified: 23 Apr 2026

    The SNMP-DMI mapper subagent daemon (aka snmpXdmid) in Solstice Enterprise Agents in Sun Solaris 8 through 10 allows remote attackers to cause a denial of service (daemon crash) via malformed packets.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2949

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to change the location property of a frame via the String data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2945

    Last Modified: 23 Apr 2026

    Sun Java System Access Manager 6.3 through 7.1 and Sun Java System Identity Server 6.1 and 6.2 do not properly process XSLT stylesheets in XSLT transforms in XML signatures, which allows context-dependent attackers to execute arbitrary code via a crafted stylesheet, a related issue to CVE-2007-3715, CVE-2007-3716, and CVE-2007-4289.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-2462

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the viewfile documentation command in Caucho Resin before 3.0.25, and 3.1.x before 3.1.4, allows remote attackers to inject arbitrary web script or HTML via the file parameter.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2948

    Last Modified: 23 Apr 2026

    Cross-domain vulnerability in Microsoft Internet Explorer 7 and 8 allows remote attackers to change the location property of a frame via the Object data type, and use a frame from a different domain to observe domain-independent events, as demonstrated by observing onkeydown events with caballero-listener. NOTE: according to Microsoft, this is a duplicate of CVE-2008-2947, possibly a different attack vector.

    Published: 30 Jun 2008
    6
    Medium

    CVE-2008-2943

    Last Modified: 23 Apr 2026

    Double free vulnerability in IBM Tivoli Directory Server (TDS) 6.1.0.0 through 6.1.0.15 allows remote authenticated administrators to cause a denial of service (ABEND) and possibly execute arbitrary code by using ldapadd to attempt to create a duplicate ibm-globalAdminGroup LDAP database entry. NOTE: the vendor states "There is no real risk of a vulnerability," although there are likely scenarios in which a user is allowed to make administrative LDAP requests but does not have the privileges to stop the server.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2922

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2914

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the (1) kw or (2) position parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-2924

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Webmatic before 2.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2913

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in func.php in Devalcms 1.4a, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the currentpath parameter, in conjunction with certain ... (triple dot) and ..... sequences in the currentfile parameter, to index.php.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2912

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the (1) contenido_path parameter to (a) contenido/backend_search.php; the (2) cfg[path][contenido] parameter to (b) move_articles.php, (c) move_old_stats.php, (d) optimize_database.php, (e) run_newsletter_job.php, (f) send_reminder.php, (g) session_cleanup.php, and (h) setfrontenduserstate.php in contenido/cronjobs/, and (i) includes/include.newsletter_jobs_subnav.php and (j) plugins/content_allocation/includes/include.right_top.php in contenido/; the (3) cfg[path][templates] parameter to (k) includes/include.newsletter_jobs_subnav.php and (l) plugins/content_allocation/includes/include.right_top.php in contenido/; and the (4) cfg[templates][right_top_blank] parameter to (m) plugins/content_allocation/includes/include.right_top.php and (n) contenido/includes/include.newsletter_jobs_subnav.php in contenido/, different vectors than CVE-2006-5380.

    Published: 30 Jun 2008
    9.3
    Critical

    CVE-2008-2910

    Last Modified: 23 Apr 2026

    Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting property value.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2907

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the eml parameter.

    Published: 30 Jun 2008
    6.5
    Medium

    CVE-2008-2901

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated users to execute arbitrary SQL commands via the (1) address parameter to addressbook.php, the (2) getnews parameter to familynews.php, and the (3) poll_id parameter to home.php in a results action.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-2923

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in read/search/results in Lyris ListManager 8.8, 8.95, and 9.3d allows remote attackers to inject arbitrary web script or HTML via the words parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2909

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the searchtype parameter.

    Published: 30 Jun 2008
    9.3
    Critical

    CVE-2008-2908

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2902

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-2911

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) contenido, (2) Belang, and (3) username parameters.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2916

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter to showcategory.php and the (2) id parameter to software-description.php.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2917

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_id parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2919

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in listing.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the sort parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2920

    Last Modified: 23 Apr 2026

    admin/filemanager/ (aka the File Manager) in EZTechhelp EZCMS 1.2 and earlier does not require authentication, which allows remote attackers to create, modify, read, and delete files.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2921

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2915

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execute arbitrary SQL commands via the (1) position or (2) kw parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2925

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Webmatic before 2.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2906

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2905

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 30 Jun 2008
    7.5
    High

    CVE-2008-2904

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 30 Jun 2008
    6.8
    Medium

    CVE-2008-2903

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the viewnews parameter.

    Published: 30 Jun 2008
    5
    Medium

    CVE-2008-3139

    Last Modified: 23 Apr 2026

    The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.

    Published: 30 Jun 2008
    9.3
    Critical

    CVE-2008-3916

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.

    Published: 30 Jun 2008
    4.9
    Medium

    CVE-2008-3141

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the RMI dissector in Wireshark (formerly Ethereal) 0.9.5 through 1.0.0 allows remote attackers to read system memory via unspecified vectors.

    Published: 30 Jun 2008
    5
    Medium

    CVE-2008-3140

    Last Modified: 23 Apr 2026

    The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors, possibly related to an "incomplete SS7 MSU syslog encapsulated packet."

    Published: 30 Jun 2008
    5
    Medium

    CVE-2008-3138

    Last Modified: 23 Apr 2026

    The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-3137

    Last Modified: 23 Apr 2026

    The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 30 Jun 2008
    4.3
    Medium

    CVE-2008-2955

    Last Modified: 23 Apr 2026

    Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function.

    Published: 28 Jun 2008
    7.5
    High

    CVE-2008-2892

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_payment action to index.php.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2890

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.

    Published: 27 Jun 2008
    10
    Critical

    CVE-2008-2888

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2) content_image.class.php in lib/obj/.

    Published: 27 Jun 2008
    9.3
    Critical

    CVE-2008-2885

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the CLASSES_ROOT parameter.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2893

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.

    Published: 27 Jun 2008
    6.8
    Medium

    CVE-2008-2887

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 27 Jun 2008
    9.3
    Critical

    CVE-2008-2886

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.

    Published: 27 Jun 2008
    9.3
    Critical

    CVE-2008-2884

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: some of these details are obtained from third party information.

    Published: 27 Jun 2008
    9.3
    Critical

    CVE-2008-2894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2895

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2896

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 27 Jun 2008
    7.5
    High

    CVE-2008-2897

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 27 Jun 2008