CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2743

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the embedded web server in Xerox 4110, 4590, and 4595 Copier/Printers allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.

    Published: 17 Jun 2008
    9.3
    Critical

    CVE-2008-2745

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows remote attackers to execute arbitrary code via a long parameter to the AnnoSaveToTiff method.

    Published: 17 Jun 2008
    4.3
    Medium

    CVE-2008-2744

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in vBulletin 3.6.10 and 3.7.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors and an "obscure method." NOTE: the vector is probably in the redirect parameter to the Admin Control Panel (admincp/index.php).

    Published: 17 Jun 2008
    7.5
    High

    CVE-2008-2742

    Last Modified: 23 Apr 2026

    Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled.

    Published: 17 Jun 2008
    7.5
    High

    CVE-2008-2746

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL commands via the detail parameter.

    Published: 17 Jun 2008
    7.5
    High

    CVE-2008-3333

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in core/lang_api.php in Mantis before 1.1.2 allows remote attackers to include and execute arbitrary files via the language parameter to the user preferences page (account_prefs_update.php).

    Published: 17 Jun 2008
    7.5
    High

    CVE-2008-2722

    Last Modified: 23 Apr 2026

    Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2723

    Last Modified: 23 Apr 2026

    embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2724

    Last Modified: 23 Apr 2026

    Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2721

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the album-select module in Menalto Gallery before 2.2.5 allows remote attackers to obtain titles of hidden albums by attempting to add a new album to a hidden album.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2715

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.5 allows remote attackers to read cross-domain images via HTML CANVAS elements that use the images as patterns.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2716

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of trusted frames on the same parent page by modifying the location, which can facilitate phishing attacks.

    Published: 16 Jun 2008
    4.3
    Medium

    CVE-2008-2718

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in fe_adminlib.inc in TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, as used in extensions such as (1) direct_mail_subscription, (2) feuser_admin, and (3) kb_md5fepw, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jun 2008
    6.5
    Medium

    CVE-2008-2717

    Last Modified: 23 Apr 2026

    TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which allows remote attackers to bypass security restrictions and upload configuration files such as .htaccess, or conduct file upload attacks using multiple extensions.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2714

    Last Modified: 23 Apr 2026

    Opera before 9.26 allows remote attackers to misrepresent web page addresses using "certain characters" that "cause the page address text to be misplaced."

    Published: 16 Jun 2008
    4.9
    Medium

    CVE-2008-2708

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Sun (1) UltraSPARC T2 and (2) UltraSPARC T2+ kernel modules in Sun Solaris 10, and OpenSolaris before snv_93, allows local users to cause a denial of service (panic) via unspecified vectors, probably related to core files.

    Published: 16 Jun 2008
    4.7
    Medium

    CVE-2008-2709

    Last Modified: 23 Apr 2026

    Buffer overflow in the BrSmRcvAndCheck function in the RCHMGR module on IBM OS/400 V5R4M0, V5R4M5, and V6R1M0 allows local users to cause a denial of service (task halt and main storage dump) via unspecified vectors involving the running of diagnostics on a modem port. NOTE: there might be limited attack scenarios.

    Published: 16 Jun 2008
    7.2
    High

    CVE-2008-2710

    Last Modified: 23 Apr 2026

    Integer signedness error in the ip_set_srcfilter function in the IP Multicast Filter in uts/common/inet/ip/ip_multi.c in the kernel in Sun Solaris 10 and OpenSolaris before snv_92 allows local users to execute arbitrary code in other Solaris Zones via an SIOCSIPMSFILTER IOCTL request with a large value of the imsf->imsf_numsrc field, which triggers an out-of-bounds write of kernel memory. NOTE: this was reported as an integer overflow, but the root cause involves the bypass of a signed comparison.

    Published: 16 Jun 2008
    7.6
    High

    CVE-2008-2639

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to execute arbitrary code via a long string in the second application packet in a TCP session on port 20222.

    Published: 16 Jun 2008
    9.3
    Critical

    CVE-2008-2705

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Access Manager (AM) 7.1, when used with certain versions and configurations of Sun Directory Server Enterprise Edition (DSEE), allows remote attackers to bypass authentication via unspecified vectors.

    Published: 16 Jun 2008
    4.3
    Medium

    CVE-2008-0071

    Last Modified: 23 Apr 2026

    The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a malformed Range header.

    Published: 16 Jun 2008
    4.9
    Medium

    CVE-2008-2706

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the event port implementation in Sun Solaris 10 allows local users to cause a denial of service (panic) by submitting and retrieving user-defined events, probably related to a NULL dereference.

    Published: 16 Jun 2008
    7.8
    High

    CVE-2008-2707

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (network connectivity loss) via unknown vectors.

    Published: 16 Jun 2008
    9.8
    Critical

    CVE-2008-2374

    Last Modified: 23 Apr 2026

    src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer over-read.

    Published: 16 Jun 2008
    5
    Medium

    CVE-2008-2713

    Last Modified: 23 Apr 2026

    libclamav/petite.c in ClamAV before 0.93.1 allows remote attackers to cause a denial of service via a crafted Petite file that triggers an out-of-bounds read.

    Published: 15 Jun 2008
    9.3
    Critical

    CVE-2008-2712

    Last Modified: 23 Apr 2026

    Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw. NOTE: the originally reported version was 7.1.314, but the researcher actually found this set of issues in 7.1.298. NOTE: the zipplugin issue (originally vector 2 in this identifier) has been subsumed by CVE-2008-3075.

    Published: 15 Jun 2008
    10
    Critical

    CVE-2008-2689

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter.

    Published: 13 Jun 2008
    9.3
    Critical

    CVE-2008-2693

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via a long first argument to the SetByteOrder method.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-2694

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2695

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in entry.php in phpInv 0.8.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2700

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2691

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrary SQL commands via the fID parameter.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2697

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the recipe_id parameter in a viewrecipe action to index.php.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2699

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Galatolo WebManager (GWM) 1.0 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in (1) the plugin parameter to admin/plugins.php or (2) the com parameter to index.php.

    Published: 13 Jun 2008
    6.8
    Medium

    CVE-2008-2701

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a page action to index.php.

    Published: 13 Jun 2008
    9.3
    Critical

    CVE-2008-2690

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) contact_view.php, and (5) contact.php in pub/, different vectors than CVE-2008-2689. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2692

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the ArticleID parameter in a comment action to index.php.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-2698

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in photo_add-c.php (aka the "add comment" section) in WEBalbum 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) id, or (3) category parameter.

    Published: 13 Jun 2008
    9.3
    Critical

    CVE-2008-2702

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 13 Jun 2008
    10
    Critical

    CVE-2008-2703

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-2696

    Last Modified: 23 Apr 2026

    Exiv2 0.16 allows user-assisted remote attackers to cause a denial of service (divide-by-zero and application crash) via a zero value in Nikon lens information in the metadata of an image, related to "pretty printing" and the RationalValue::toLong function.

    Published: 13 Jun 2008
    5
    Medium

    CVE-2008-2704

    Last Modified: 23 Apr 2026

    Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2687

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in inc/config.php in ProManager 0.73 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2688

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.

    Published: 13 Jun 2008
    10
    Critical

    CVE-2008-2654

    Last Modified: 23 Apr 2026

    Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a long request to a Motion HTTP Control interface, which triggers a stack-based buffer overflow with some combinations of processor architecture and compiler.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2686

    Last Modified: 23 Apr 2026

    webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overwriting a PHP file in webinc/bxe/scripts/ via a filename in the XML parameter and PHP sequences in the request body, then making a direct request for this filename.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-6746

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-3330

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in services/obrowser/index.php in Horde 3.2 and Turba 2.2 allows remote attackers to inject arbitrary web script or HTML via the contact name.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-3328

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 13 Jun 2008
    4.3
    Medium

    CVE-2008-2711

    Last Modified: 23 Apr 2026

    fetchmail 6.3.8 and earlier, when running in -v -v (aka verbose) mode, allows remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed mail message with long headers, which triggers an erroneous dereference when using vsnprintf to format log messages.

    Published: 13 Jun 2008