CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-2649

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PHP code via a URL in the app_path parameter to (1) don3_requiem.don3app/don3_requiem.php and (2) frontpage.don3app/frontpage.php.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-2650

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-1583

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT image, a different vulnerability than CVE-2008-1581.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-1585

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.5 uses the url.dll!FileProtocolHandler handler for unrecognized URIs in qt:next attributes within SMIL text in video files, which sends these URIs to explorer.exe and thereby allows remote attackers to execute arbitrary programs, as originally demonstrated by crafted file: URLs.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2652

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2642

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in OtomiGenX 2.2 allows remote attackers to execute arbitrary SQL commands via the userAccount parameter (aka the User Name field) to index.php. NOTE: some of these details are obtained from third party information.

    Published: 10 Jun 2008
    6.8
    Medium

    CVE-2008-2648

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the files/ directory.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-1806

    Last Modified: 23 Apr 2026

    Integer overflow in FreeType2 before 2.3.6 allows context-dependent attackers to execute arbitrary code via a crafted set of 16-bit length values within the Private dictionary table in a Printer Font Binary (PFB) file, which triggers a heap-based buffer overflow.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-1807

    Last Modified: 23 Apr 2026

    FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via an invalid "number of axes" field in a Printer Font Binary (PFB) file, which triggers a free of arbitrary memory locations, leading to memory corruption.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-1808

    Last Modified: 23 Apr 2026

    Multiple off-by-one errors in FreeType2 before 2.3.6 allow context-dependent attackers to execute arbitrary code via (1) a crafted table in a Printer Font Binary (PFB) file or (2) a crafted SHC instruction in a TrueType Font (TTF) file, which triggers a heap-based buffer overflow.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2626

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary SQL commands via the entry parameter.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2629

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2630

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter in a category action to index.php.

    Published: 10 Jun 2008
    5
    Medium

    CVE-2008-2631

    Last Modified: 23 Apr 2026

    The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTTP POST request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2632

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the usage parameter in a subscribe action to index.php.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2633

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the EXP JoomRadio (com_joomradio) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) show_radio or (2) show_video action to index.php.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2634

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the eQuotes (com_equotes) component 0.9.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 10 Jun 2008
    10
    Critical

    CVE-2008-2638

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitrary PHP code via the message parameter in an HTML webform, which is written to data.php.

    Published: 10 Jun 2008
    5
    Medium

    CVE-2008-2364

    Last Modified: 23 Apr 2026

    The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.

    Published: 10 Jun 2008
    9.3
    Critical

    CVE-2008-2635

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in BitKinex 2.9.3 allow remote FTP and WebDAV servers to create or overwrite arbitrary files via a .. (dot dot) in (1) a response to a LIST command from the BitKinex FTP client and (2) a response to a PROPFIND command from the BitKinex WebDAV client. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 10 Jun 2008
    7.8
    High

    CVE-2008-2636

    Last Modified: 23 Apr 2026

    The HTTP service on the Cisco Linksys WRH54G with firmware 1.01.03 allows remote attackers to cause a denial of service (management interface outage) or possibly execute arbitrary code via a URI that begins with a "/./" sequence, contains many instances of a "front_page" sequence, and ends with a ".asp" sequence.

    Published: 10 Jun 2008
    9.3
    Critical

    CVE-2008-2152

    Last Modified: 23 Apr 2026

    Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

    Published: 10 Jun 2008
    4.3
    Medium

    CVE-2008-2637

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass SSL VPN 6.0.2 hotfix 3, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via quotes in (1) the css_exceptions parameter in vdesk/admincon/webyfiers.php and (2) the sql_matchscope parameter in vdesk/admincon/index.php.

    Published: 10 Jun 2008
    7.8
    High

    CVE-2008-2750

    Last Modified: 23 Apr 2026

    The pppol2tp_recvmsg function in drivers/net/pppol2tp.c in the Linux kernel 2.6 before 2.6.26-rc6 allows remote attackers to cause a denial of service (kernel heap memory corruption and system crash) and possibly have unspecified other impact via a crafted PPPOL2TP packet that results in a large value for a certain length variable.

    Published: 10 Jun 2008
    7.5
    High

    CVE-2008-2627

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the userid parameter in a userblog action to index.php.

    Published: 10 Jun 2008
    7.1
    High

    CVE-2008-1106

    Last Modified: 23 Apr 2026

    The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and force the client to download and execute arbitrary files.

    Published: 9 Jun 2008
    7.2
    High

    CVE-2008-2358

    Last Modified: 23 Apr 2026

    Integer overflow in the dccp_feat_change function in net/dccp/feat.c in the Datagram Congestion Control Protocol (DCCP) subsystem in the Linux kernel 2.6.18, and 2.6.17 through 2.6.20, allows local users to gain privileges via an invalid feature length, which leads to a heap-based buffer overflow.

    Published: 9 Jun 2008
    10
    Critical

    CVE-2008-0960

    Last Modified: 23 Apr 2026

    SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-SNMP; (3) eCos; (4) Juniper Session and Resource Control (SRC) C-series 1.0.0 through 2.0.0; (5) NetApp (aka Network Appliance) Data ONTAP 7.3RC1 and 7.3RC2; (6) SNMP Research before 16.2; (7) multiple Cisco IOS, CatOS, ACE, and Nexus products; (8) Ingate Firewall 3.1.0 and later and SIParator 3.1.0 and later; (9) HP OpenView SNMP Emanate Master Agent 15.x; and possibly other products relies on the client to specify the HMAC length, which makes it easier for remote attackers to bypass SNMP authentication via a length value of 1, which only checks the first byte.

    Published: 9 Jun 2008
    9.3
    Critical

    CVE-2008-1805

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is not covered by the blacklist.

    Published: 6 Jun 2008
    9.3
    Critical

    CVE-2008-2545

    Last Modified: 23 Apr 2026

    Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a dangerous extension that uses a different case.

    Published: 6 Jun 2008
    10
    Critical

    CVE-2008-2388

    Last Modified: 23 Apr 2026

    Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can be considered no security problem."

    Published: 6 Jun 2008
    4.9
    Medium

    CVE-2008-2389

    Last Modified: 23 Apr 2026

    opensuse-updater in openSUSE 10.2 allows local users to access arbitrary files via a symlink attack.

    Published: 6 Jun 2008
    Unknown

    CVE-2008-2546

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1805. Reason: This candidate is a reservation duplicate of CVE-2008-1805. Notes: All CVE users should reference CVE-2008-1805 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2574

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in tus_imagenes/.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2565

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) edit.php. NOTE: it was later reported that 4.0.x is also affected.

    Published: 6 Jun 2008
    4.3
    Medium

    CVE-2008-2561

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in 427BB 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to (a) register.php, (b) reminder.php, and (c) search.php; the (2) uname, (3) email, and (4) email2 parameters to register.php; the (5) email parameter to reminder.php; and the (6) keywords parameter to search.php.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2560

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showpost.php in 427BB 2.3.1 allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Published: 6 Jun 2008
    6.5
    Medium

    CVE-2008-2562

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute arbitrary SQL commands via the css_str parameter in an edit action.

    Published: 6 Jun 2008
    4.3
    Medium

    CVE-2008-2563

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in (1) dsp_main.php and (2) dsp_task_editor.php in SamTodo 1.1 allow remote attackers to inject arbitrary web script or HTML via the (a) tid parameter in a main.taskeditor edit action, and the (b) completed parameter in a main.default action, to index.php.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2564

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.

    Published: 6 Jun 2008
    4.3
    Medium

    CVE-2008-2567

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Fenriru Sleipnir 2.7.1 Release2 and earlier, Portable Sleipnir 2.7.1 Release2 and earlier, and Grani 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to a history mechanism and favorites search, a different vulnerability than CVE-2007-6002.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2568

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a browse action to index.php.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2569

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gbid parameter in a deleteentry action to index.php.

    Published: 6 Jun 2008
    9.3
    Critical

    CVE-2008-2570

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.

    Published: 6 Jun 2008
    4.3
    Medium

    CVE-2008-2571

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.

    Published: 6 Jun 2008
    7.5
    High

    CVE-2008-2572

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL commands via the articulo_id parameter.

    Published: 6 Jun 2008
    8.5
    High

    CVE-2008-2573

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a long directory name in an SSH_FXP_OPENDIR (aka opendir) command.

    Published: 6 Jun 2008
    4.3
    Medium

    CVE-2008-2566

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the group parameter to (1) index.php or (2) the default URI.

    Published: 6 Jun 2008
    10
    Critical

    CVE-2008-1673

    Last Modified: 23 Apr 2026

    The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 before 2.6.25.5, as used in the cifs and ip_nat_snmp_basic modules; and (b) the gxsnmp package; does not properly validate length values during decoding of ASN.1 BER data, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a length greater than the working buffer, which can lead to an unspecified overflow; (2) an oid length of zero, which can lead to an off-by-one error; or (3) an indefinite length for a primitive encoding.

    Published: 6 Jun 2008