CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-2559

    Last Modified: 23 Apr 2026

    Integer overflow in Borland Interbase 2007 SP2 (8.1.0.256) allows remote attackers to execute arbitrary code via a malformed packet to TCP port 3050, which triggers a stack-based buffer overflow. NOTE: this issue might be related to CVE-2008-0467.

    Published: 5 Jun 2008
    7.5
    High

    CVE-2008-2554

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to template_permalink.asp and (2) cat parameter to template_archives_cat.asp.

    Published: 5 Jun 2008
    7.5
    High

    CVE-2008-2555

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via the mid parameter.

    Published: 5 Jun 2008
    7.5
    High

    CVE-2008-2556

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in PHP Visit Counter 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the datespan parameter in a read action.

    Published: 5 Jun 2008
    5
    Medium

    CVE-2008-2558

    Last Modified: 23 Apr 2026

    CRE Loaded 6.2.13.1 and earlier does not set the "Secure" attribute for cookies that are sent over HTTPS, which might allow remote attackers to sniff the cookies if they are sent over HTTP.

    Published: 5 Jun 2008
    4.3
    Medium

    CVE-2008-2557

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CRE Loaded 6.2.13.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) Links and (2) Links Submit pages.

    Published: 5 Jun 2008
    9
    Critical

    CVE-2008-2097

    Last Modified: 23 Apr 2026

    Buffer overflow in the openwsman management service in VMware ESXi 3.5 and ESX 3.5 allows remote authenticated users to gain privileges via an "invalid Content-Length."

    Published: 5 Jun 2008
    7.5
    High

    CVE-2008-2231

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.

    Published: 5 Jun 2008
    6.8
    Medium

    CVE-2008-2542

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file.

    Published: 5 Jun 2008
    4.9
    Medium

    CVE-2008-2552

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Service Tag Registry on Sun Solaris 10, and Sun Service Tag before 1.1.3, allows local users to cause a denial of service (disk consumption) via unspecified vectors.

    Published: 5 Jun 2008
    4.3
    Medium

    CVE-2008-2553

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to inject arbitrary web script or HTML via the userfield parameter.

    Published: 5 Jun 2008
    4.4
    Medium

    CVE-2007-5671

    Last Modified: 23 Apr 2026

    HGFS.sys in the VMware Tools package in VMware Workstation 5.x before 5.5.6 build 80404, VMware Player before 1.0.6 build 80404, VMware ACE before 1.0.5 build 79846, VMware Server before 1.0.5 build 80187, and VMware ESX 2.5.4 through 3.0.2 does not properly validate arguments in user-mode METHOD_NEITHER IOCTLs to the \\.\hgfs device, which allows guest OS users to modify arbitrary memory locations in guest kernel memory and gain privileges.

    Published: 5 Jun 2008
    6.9
    Medium

    CVE-2008-0967

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.

    Published: 5 Jun 2008
    7.2
    High

    CVE-2008-1518

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in kl1.sys in Kaspersky Anti-Virus 6.0 and 7.0 and Internet Security 6.0 and 7.0 allows local users to gain privileges via an IOCTL 0x800520e8 call.

    Published: 5 Jun 2008
    7.2
    High

    CVE-2008-2100

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to execute arbitrary code on the host OS via unspecified vectors.

    Published: 5 Jun 2008
    5
    Medium

    CVE-2008-2543

    Last Modified: 23 Apr 2026

    The ooh323 channel driver in Asterisk Addons 1.2.x before 1.2.9 and Asterisk-Addons 1.4.x before 1.4.7 creates a remotely accessible TCP port that is intended solely for localhost communication, and interprets some TCP application-data fields as addresses of memory to free, which allows remote attackers to cause a denial of service (daemon crash) via crafted TCP packets.

    Published: 5 Jun 2008
    9.3
    Critical

    CVE-2008-2551

    Last Modified: 23 Apr 2026

    The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set to "run."

    Published: 4 Jun 2008
    7.8
    High

    CVE-2008-2055

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.1.x before 7.1(2)70, 7.2.x before 7.2(4), and 8.0.x before 8.0(3)10 allows remote attackers to cause a denial of service via a crafted TCP ACK packet to the device interface.

    Published: 4 Jun 2008
    7.8
    High

    CVE-2008-2056

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 and 8.1.x before 8.1(1)1 allows remote attackers to cause a denial of service (device reload) via a crafted Transport Layer Security (TLS) packet to the device interface.

    Published: 4 Jun 2008
    5.4
    Medium

    CVE-2008-2057

    Last Modified: 23 Apr 2026

    The Instant Messenger (IM) inspection engine in Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(4), 8.0.x before 8.0(3)10, and 8.1.x before 8.1(1)2 allows remote attackers to cause a denial of service via a crafted packet.

    Published: 4 Jun 2008
    7.8
    High

    CVE-2008-2058

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 7.2.x before 7.2(3)2 and 8.0.x before 8.0(2)17 allows remote attackers to cause a denial of service (device reload) via a port scan against TCP port 443 on the device.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2008-1770

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.

    Published: 4 Jun 2008
    7.8
    High

    CVE-2008-2059

    Last Modified: 23 Apr 2026

    Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs for the device via unknown vectors.

    Published: 4 Jun 2008
    7.5
    High

    CVE-2007-5604

    Last Modified: 23 Apr 2026

    Buffer overflow in the ExtractCab function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5605, CVE-2007-5606, and CVE-2007-5607.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2007-5605

    Last Modified: 23 Apr 2026

    Buffer overflow in the GetFileTime function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5606, and CVE-2007-5607.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2007-5606

    Last Modified: 23 Apr 2026

    Buffer overflow in the MoveFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5607.

    Published: 4 Jun 2008
    7.5
    High

    CVE-2007-5607

    Last Modified: 23 Apr 2026

    Buffer overflow in the RegistryString function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary code via a long first argument, a different vulnerability than CVE-2007-5604, CVE-2007-5605, and CVE-2007-5606.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2008-0952

    Last Modified: 23 Apr 2026

    The AppendStringToFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to create files with arbitrary content via a full pathname in the first argument and the content in the second argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2008-0953

    Last Modified: 23 Apr 2026

    The StartApp function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to execute arbitrary programs via a .exe filename in the argument, a different vulnerability than CVE-2007-5608 and CVE-2008-0953.

    Published: 4 Jun 2008
    7.5
    High

    CVE-2008-2401

    Last Modified: 23 Apr 2026

    The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to append to arbitrary new or existing files via the first argument to a certain file that is included by multiple unspecified ASP applications.

    Published: 4 Jun 2008
    5
    Medium

    CVE-2008-2402

    Last Modified: 23 Apr 2026

    The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2008-2403

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.

    Published: 4 Jun 2008
    7.5
    High

    CVE-2008-2406

    Last Modified: 23 Apr 2026

    The administration application server in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to bypass authentication via direct requests on TCP port 5102.

    Published: 4 Jun 2008
    5
    Medium

    CVE-2008-2550

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2007-5610

    Last Modified: 23 Apr 2026

    The DeleteSingleFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to delete an arbitrary file via a full pathname in the argument.

    Published: 4 Jun 2008
    7.5
    High

    CVE-2008-2405

    Last Modified: 23 Apr 2026

    Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in HTTP requests to unspecified ASP applications.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2008-2541

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2007-5608

    Last Modified: 23 Apr 2026

    The DownloadFile function in the HPISDataManagerLib.Datamgr ActiveX control in HPISDataManager.dll in HP Instant Support before 1.0.0.24 allows remote attackers to force a download of an arbitrary file onto a client machine via a URL in the first argument and a destination filename in the second argument, a different vulnerability than CVE-2008-0952 and CVE-2008-0953.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2008-2404

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.

    Published: 4 Jun 2008
    10
    Critical

    CVE-2008-1661

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in DoubleTake.exe in HP StorageWorks Storage Mirroring (SWSM) before 4.5 SP2 allows remote attackers to execute arbitrary code via a crafted encoded authentication request.

    Published: 4 Jun 2008
    4.3
    Medium

    CVE-2008-2119

    Last Modified: 23 Apr 2026

    Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic parsing (aka pedanticsipchecking) is enabled, allows remote attackers to cause a denial of service (daemon crash) via a SIP INVITE message that lacks a From header, related to invocations of the ast_uri_decode function, and improper handling of (1) an empty const string and (2) a NULL pointer.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2008-2547

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross privilege boundaries if msiexec.exe is reachable via components such as ActiveX controls, and might additionally require a separate vulnerability in the control.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2008-2548

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers memory corruption.

    Published: 4 Jun 2008
    7.6
    High

    CVE-2008-1108

    Last Modified: 23 Apr 2026

    Buffer overflow in Evolution 2.22.1, when the ITip Formatter plugin is disabled, allows remote attackers to execute arbitrary code via a long timezone string in an iCalendar attachment.

    Published: 4 Jun 2008
    9.3
    Critical

    CVE-2008-1109

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).

    Published: 4 Jun 2008
    4.3
    Medium

    CVE-2008-1035

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to trigger memory corruption or possibly execute arbitrary code via an "ATTACH;VALUE=URI:S=osumi" line in a .ics file, which triggers a "resource liberation" bug. NOTE: CVE-2008-2007 was originally used for this issue, but this is the appropriate identifier.

    Published: 3 Jun 2008
    6.8
    Medium

    CVE-2008-0169

    Last Modified: 23 Apr 2026

    Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any account for which an OpenID identity is configured and a password is not configured, by specifying an empty password during the login sequence.

    Published: 3 Jun 2008
    6.5
    Medium

    CVE-2008-2521

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

    Published: 3 Jun 2008
    6.8
    Medium

    CVE-2008-2522

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the showmember parameter in a members action.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2523

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Autopatcher server plugin in RakNet before 3.23 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 3 Jun 2008