CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-2841

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

    Published: 13 Jun 2008
    7.5
    High

    CVE-2008-2673

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.

    Published: 12 Jun 2008
    4.3
    Medium

    CVE-2008-2677

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in edit1.php in Telephone Directory 2008 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2679

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the KeyWordsList function in _includes/inc_routines.asp in Realm CMS 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the kwrd parameter in a kwl action to the default URI.

    Published: 12 Jun 2008
    5
    Medium

    CVE-2008-2681

    Last Modified: 23 Apr 2026

    Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.asp, which reveals the database path in an error message.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2676

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2685

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in article.asp in Battle Blog 1.25 Build 4 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter, a different vector than CVE-2008-2626.

    Published: 12 Jun 2008
    4.3
    Medium

    CVE-2008-2675

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-2683

    Last Modified: 23 Apr 2026

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, and the local filename in the second argument. NOTE: some of these details are obtained from third party information.

    Published: 12 Jun 2008
    6.4
    Medium

    CVE-2008-2674

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Interstage Management Console, as used in Fujitsu Interstage Application Server 6.0 through 9.0.0A, Apworks Modelers-J 6.0 through 7.0, and Studio 8.0.1 and 9.0.0, allows remote attackers to read or delete arbitrary files via unspecified vectors.

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-2684

    Last Modified: 23 Apr 2026

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: some of these details are obtained from third party information.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2678

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to view_more.php.

    Published: 12 Jun 2008
    4.3
    Medium

    CVE-2008-2680

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in _db/compact.asp in Realm CMS 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) CmpctedDB and (2) Boyut parameters.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2682

    Last Modified: 23 Apr 2026

    _RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cookies, probably including (1) cUserRole, (2) cUserName, and (3) cUserID.

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-0011

    Last Modified: 23 Apr 2026

    Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJPEG stream in a (1) AVI or (2) ASF file, aka the "MJPEG Decoder Vulnerability."

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-1442

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory Corruption Vulnerability."

    Published: 12 Jun 2008
    7.2
    High

    CVE-2008-1451

    Last Modified: 23 Apr 2026

    The WINS service on Microsoft Windows 2000 SP4, and Server 2003 SP1 and SP2, does not properly validate data structures in WINS network packets, which allows local users to gain privileges via a crafted packet, aka "Memory Overwrite Vulnerability."

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2670

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter, or (2) the term parameter in a search action. NOTE: the current_subsection parameter is already covered by CVE-2007-3889.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2671

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in DCFM Blog 0.9.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Jun 2008
    8.3
    High

    CVE-2008-1453

    Last Modified: 23 Apr 2026

    The Bluetooth stack in Microsoft Windows XP SP2 and SP3, and Vista Gold and SP1, allows physically proximate attackers to execute arbitrary code via a large series of Service Discovery Protocol (SDP) packets.

    Published: 12 Jun 2008
    5.4
    Medium

    CVE-2008-1441

    Last Modified: 23 Apr 2026

    Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system hang) via a series of Pragmatic General Multicast (PGM) packets with invalid fragment options, aka the "PGM Malformed Fragment Vulnerability."

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2669

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php.

    Published: 12 Jun 2008
    7.5
    High

    CVE-2008-2672

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) ewiki_id and (2) ewiki_action parameters to fragments/css.php, and possibly the (3) id parameter to the default URI. NOTE: the default URI is site-specific but often performs an include_once of ewiki.php.

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-0956

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 12 Jun 2008
    7.1
    High

    CVE-2008-1440

    Last Modified: 23 Apr 2026

    Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."

    Published: 12 Jun 2008
    9.3
    Critical

    CVE-2008-1444

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Format Parsing Vulnerability."

    Published: 12 Jun 2008
    7.1
    High

    CVE-2008-1445

    Last Modified: 23 Apr 2026

    Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.

    Published: 12 Jun 2008
    4.3
    Medium

    CVE-2008-2668

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in yBlog 0.2.2.2 allow remote attackers to inject arbitrary web script or HTML via (1) the q parameter to search.php, or the n parameter to (2) user.php or (3) uss.php.

    Published: 12 Jun 2008
    7.8
    High

    CVE-2008-3278

    Last Modified: 21 Nov 2024

    frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the ELF header of multiple binaries in /usr/bin/f* (e.g. fcore, fcatch, fstack, fstep, ...) shipped in the package. A local attacker can exploit this vulnerability by running arbitrary code as another user.

    Published: 12 Jun 2008
    6.9
    Medium

    CVE-2008-3279

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in libbrlttybba.so in brltty 3.7.2 allows local users to gain privileges via a crafted library, related to an incorrect RPATH setting.

    Published: 12 Jun 2008
    5
    Medium

    CVE-2008-6504

    Last Modified: 23 Apr 2026

    ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and other products, does not properly restrict # (pound sign) references to context objects, which allows remote attackers to execute Object-Graph Navigation Language (OGNL) statements and modify server-side context objects, as demonstrated by use of a \u0023 representation for the # character.

    Published: 12 Jun 2008
    4.4
    Medium

    CVE-2008-3277

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in refix/lib/, related to an incorrect RPATH setting in the ELF header.

    Published: 12 Jun 2008
    4.4
    Medium

    CVE-2008-2366

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in a certain Red Hat build script for OpenOffice.org (OOo) 1.1.x on Red Hat Enterprise Linux (RHEL) 3 and 4 allows local users to gain privileges via a malicious library in the current working directory, related to incorrect quoting of the ORIGIN symbol for use in the RPATH library path.

    Published: 12 Jun 2008
    4.3
    Medium

    CVE-2008-2720

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Menalto Gallery before 2.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) host and (2) path components of a URL.

    Published: 12 Jun 2008
    4.6
    Medium

    CVE-2008-2230

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.

    Published: 11 Jun 2008
    9
    Critical

    CVE-2008-1377

    Last Modified: 23 Apr 2026

    The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length values that specify an arbitrary number of bytes to be swapped on the heap, which triggers heap corruption.

    Published: 11 Jun 2008
    9
    Critical

    CVE-2008-2360

    Last Modified: 23 Apr 2026

    Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow.

    Published: 11 Jun 2008
    6.8
    Medium

    CVE-2008-2361

    Last Modified: 23 Apr 2026

    Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped memory.

    Published: 11 Jun 2008
    6.8
    Medium

    CVE-2008-1379

    Last Modified: 23 Apr 2026

    Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height.

    Published: 11 Jun 2008
    10
    Critical

    CVE-2008-2362

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number of bytes to swap in the request data, which triggers heap memory corruption.

    Published: 11 Jun 2008
    5
    Medium

    CVE-2008-3134

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.

    Published: 11 Jun 2008
    6.8
    Medium

    CVE-2008-1584

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Indeo.qtx in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted Indeo video codec content in a movie file.

    Published: 10 Jun 2008
    4.3
    Medium

    CVE-2008-2646

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web script or HTML via the (1) sql parameter to dbadd.inc.php, (2) InsertJournal parameter to add_journal_mask.inc.php, (3) InsertBibliography parameter to insert_mask.inc.php, and (4) LabelYear parameter to search_mask.inc.php.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2651

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the forum parameter in a forum action to index.php.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2647

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute arbitrary SQL commands via the JID parameter.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-1581

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.5 on Windows allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted packed scanlines in PixData structures in a PICT image.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2643

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a mediaplayer action to index.php.

    Published: 10 Jun 2008
    4.3
    Medium

    CVE-2008-2644

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in SMEWeb 1.4b and 1.4f allow remote attackers to inject arbitrary web script or HTML via the (1) data parameter to catalog.php, the (2) keyword parameter to search.php, the (3) page parameter to bb.php, and the (4) new_s parameter to order.php.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-1582

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AAC-encoded file that triggers memory corruption.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2645

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter to template.tpl.php in (1) barrel/, (2) barry/, (3) mylook/, (4) oerdec/, (5) penguin/, (6) sidebar/, (7) slashdot/, and (8) text-only/ in templates/. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Published: 10 Jun 2008