CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-2529

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbitrary SQL commands via the catId parameter.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2530

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQL commands via the (1) nr parameter to (a) frontend/news.php, the (2) id parameter to (b) events3.php and (c) videos2.php in frontend/, the (3) y parameter to (d) frontend/events2.php, and the (4) ser parameter to (e) frontend/fotos2.php.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2531

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search script in Build A Niche Store (BANS) 3.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2526

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the WT Gallery (aka wt_gallery) extension 2.6.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2536

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2537

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cat.php in HispaH Model Search allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 3 Jun 2008
    6.9
    Medium

    CVE-2008-2538

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in crontab on Sun Solaris 8 through 10, and OpenSolaris before snv_93, allows local users to insert cron jobs into the crontab files of arbitrary users via unspecified vectors.

    Published: 3 Jun 2008
    7.2
    High

    CVE-2008-2539

    Last Modified: 23 Apr 2026

    The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users to read data from arbitrary deleted files, or corrupt files in global filesystems, via unspecified vectors.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2535

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbitrary SQL commands via the del parameter to (1) gbuch.admin.php, (2) links.admin.php, (3) menue.admin.php, (4) news.admin.php, and (5) todo.admin.php in admin/module/.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2527

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in ActualScripts ActualAnalyzer Server 8.37 and earlier, ActualAnalyzer Gold 7.74 and earlier, ActualAnalyzer Pro 6.95 and earlier, and ActualAnalyzer Lite 2.78 and earlier allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2534

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ltarget parameter.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2520

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[_BIGACE][DIR][addon] parameter to (a) addon/smarty/plugins/function.captcha.php and (b) system/classes/sql/AdoDBConnection.php; and the (2) GLOBALS[_BIGACE][DIR][admin] parameter to (c) item_information.php and (d) jstree.php in system/application/util/, and (e) system/admin/plugins/menu/menuTree/plugin.php, different vectors than CVE-2006-4423.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2525

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Event Database (aka rlmp_eventdb) extension before 1.1.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jun 2008
    10
    Critical

    CVE-2008-2528

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.

    Published: 3 Jun 2008
    9.3
    Critical

    CVE-2008-2540

    Last Modified: 23 Apr 2026

    Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, which allows remote attackers to place malware into the (1) Desktop directory on Windows or (2) Downloads directory on Mac OS X, and subsequently allows remote attackers to execute arbitrary code on Windows by leveraging an untrusted search path vulnerability in (a) Internet Explorer 7 on Windows XP or (b) the SearchPath function in Windows XP, Vista, and Server 2003 and 2008, aka a "Carpet Bomb" and a "Blended Threat Elevation of Privilege Vulnerability," a different issue than CVE-2008-1032. NOTE: Apple considers this a vulnerability only because the Microsoft products can load application libraries from the desktop and, as of 20080619, has not covered the issue in an advisory for Mac OS X.

    Published: 3 Jun 2008
    5
    Medium

    CVE-2008-2524

    Last Modified: 23 Apr 2026

    BlogPHP 2.0 allows remote attackers to bypass authentication, and post (1) messages or (2) comments as an arbitrary user, via a modified blogphp_username field in a cookie.

    Published: 3 Jun 2008
    7.5
    High

    CVE-2008-2532

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in forum/topic_detail.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2533

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget parameter to (a) admin/admin_frame.php and the (2) conf parameter to (b) gbuch.admin.php, (c) links.admin.php, (d) menue.admin.php, (e) news.admin.php, and (f) todo.admin.php in admin/module/.

    Published: 3 Jun 2008
    6.8
    Medium

    CVE-2008-2519

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Core FTP client 2.1 Build 1565 allows remote FTP servers to create or overwrite arbitrary files via .. (dot dot) sequences in responses to LIST commands, a related issue to CVE-2002-1345. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 3 Jun 2008
    4.6
    Medium

    CVE-2008-2516

    Last Modified: 23 Apr 2026

    pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal when this function is executing, as demonstrated by a CTRL-C sequence at a sudo password prompt in an "auth sufficient pam_pgsql.so" configuration.

    Published: 3 Jun 2008
    2.1
    Low

    CVE-2008-2517

    Last Modified: 23 Apr 2026

    The sarab.sh script in SaraB before 0.2.4 places the dar program's encryption key on the command line, which allows local users to obtain sensitive information by listing the process.

    Published: 3 Jun 2008
    4.3
    Medium

    CVE-2008-2518

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the advanced search mechanism (webapps/search/advanced.jsp) in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably related to the next parameter.

    Published: 3 Jun 2008
    9.3
    Critical

    CVE-2008-1028

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.

    Published: 2 Jun 2008
    10
    Critical

    CVE-2008-1030

    Last Modified: 23 Apr 2026

    Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-1031

    Last Modified: 23 Apr 2026

    CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.

    Published: 2 Jun 2008
    6.8
    Medium

    CVE-2008-1032

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine feature in Mac OS X 10.5.

    Published: 2 Jun 2008
    5
    Medium

    CVE-2008-1571

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-1575

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing.

    Published: 2 Jun 2008
    6.8
    Medium

    CVE-2008-1576

    Last Modified: 23 Apr 2026

    Mail in Apple Mac OS X before 10.5, when an IPv6 SMTP server is used, does not properly initialize memory, which might allow remote attackers to execute arbitrary code or cause a denial of service (application crash), or obtain sensitive information (memory contents) in opportunistic circumstances, by sending an e-mail message.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-1577

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."

    Published: 2 Jun 2008
    2.1
    Low

    CVE-2008-1578

    Last Modified: 23 Apr 2026

    The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.

    Published: 2 Jun 2008
    5
    Medium

    CVE-2008-1579

    Last Modified: 23 Apr 2026

    Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.

    Published: 2 Jun 2008
    6.9
    Medium

    CVE-2008-2099

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in VMCI in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, and VMware ACE 2 before 2.0.2 build 93057 on Windows allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.

    Published: 2 Jun 2008
    7.2
    High

    CVE-2008-2359

    Last Modified: 23 Apr 2026

    The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console to gain privileges and change the network configuration.

    Published: 2 Jun 2008
    5
    Medium

    CVE-2008-2512

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Symantec Backup Exec System Recovery Manager 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 2 Jun 2008
    7.2
    High

    CVE-2008-2513

    Last Modified: 23 Apr 2026

    Buffer overflow in the kernel in IBM AIX 5.2, 5.3, and 6.1 allows local users to execute arbitrary code in kernel mode via unknown attack vectors.

    Published: 2 Jun 2008
    4.6
    Medium

    CVE-2008-2514

    Last Modified: 23 Apr 2026

    Buffer overflow in errpt in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown attack vectors.

    Published: 2 Jun 2008
    7.2
    High

    CVE-2008-2515

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment variable handling error."

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-2511

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEventCli.dll in CA Internet Security Suite 2008 allows remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the argument to the SaveToFile method. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: some of these details are obtained from third party information.

    Published: 2 Jun 2008
    4.3
    Medium

    CVE-2008-1027

    Last Modified: 23 Apr 2026

    Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-1034

    Last Modified: 23 Apr 2026

    Integer underflow in Help Viewer in Apple Mac OS X before 10.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted help:topic URL that triggers a buffer overflow.

    Published: 2 Jun 2008
    7.1
    High

    CVE-2008-1573

    Last Modified: 23 Apr 2026

    The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-1574

    Last Modified: 23 Apr 2026

    Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.

    Published: 2 Jun 2008
    4.3
    Medium

    CVE-2008-1580

    Last Modified: 23 Apr 2026

    CFNetwork in Safari in Apple Mac OS X before 10.5.3 automatically sends an SSL client certificate in response to a web server's certificate request, which allows remote web sites to obtain sensitive information (Subject data) from personally identifiable certificates, and use arbitrary certificates to track user activities across domains, a related issue to CVE-2007-4879.

    Published: 2 Jun 2008
    6.9
    Medium

    CVE-2008-2098

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used, allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.

    Published: 2 Jun 2008
    9.3
    Critical

    CVE-2008-2363

    Last Modified: 23 Apr 2026

    The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that triggers a heap-based buffer overflow.

    Published: 2 Jun 2008
    4.6
    Medium

    CVE-2008-1572

    Last Modified: 23 Apr 2026

    Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application.

    Published: 2 Jun 2008
    5
    Medium

    CVE-2008-3144

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the PyOS_vsnprintf function in Python/mysnprintf.c in Python 2.5.2 and earlier allow context-dependent attackers to cause a denial of service (memory corruption) or have unspecified other impact via crafted input to string formatting operations. NOTE: the handling of certain integer values is also affected by related integer underflows and an off-by-one error.

    Published: 2 Jun 2008
    4.3
    Medium

    CVE-2008-1947

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.

    Published: 2 Jun 2008
    5.8
    Medium

    CVE-2008-7159

    Last Modified: 23 Apr 2026

    The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string.

    Published: 31 May 2008