CVE Feed

    Dashboard / CVE

    3.6
    Low

    CVE-2008-2288

    Last Modified: 23 Apr 2026

    Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information.

    Published: 18 May 2008
    7.2
    High

    CVE-2008-2290

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Agent user interface in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2293

    Last Modified: 23 Apr 2026

    admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the CommentSystemAdmin cookie to 1.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2294

    Last Modified: 23 Apr 2026

    Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "admin."

    Published: 18 May 2008
    4.3
    Medium

    CVE-2008-2295

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the s_text parameter and other unspecified vectors.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2296

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2301

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.php and (2) top_view.php.

    Published: 18 May 2008
    4.6
    Medium

    CVE-2008-0167

    Last Modified: 23 Apr 2026

    The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2282

    Last Modified: 23 Apr 2026

    admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentication by setting the login_admin cookie to true.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2291

    Last Modified: 23 Apr 2026

    axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 generates credentials with a fixed salt or without any salt, which makes it easier for remote attackers to guess encrypted domain credentials.

    Published: 18 May 2008
    9.3
    Critical

    CVE-2008-2283

    Last Modified: 23 Apr 2026

    IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the IDAuto.Datamatrix.1 ActiveX control in IDAutomationDMATRIX6.DLL (aka IDautomation Datamatrix Barcode) 1.6.0.6, (c) the IDAuto.PDF417.1 ActiveX control in IDAutomationPDF417_6.dll (aka IDautomation PDF417 Barcode) 1.6.0.6, and (d) the IDAuto.Aztec.1 ActiveX control in IDAutomationAZTEC.dll (aka IDautomation Aztec Barcode) 1.7.1.0.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2284

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fusebox5.php in Fusebox 5.5.1 allows remote attackers to execute arbitrary PHP code via a URL in the FUSEBOX_APPLICATION_PATH parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 May 2008
    7.2
    High

    CVE-2008-2289

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in a tooltip element in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2298

    Last Modified: 23 Apr 2026

    Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1.

    Published: 18 May 2008
    5
    Medium

    CVE-2008-2299

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SecureICA and ICA Basic encryption of Citrix Presentation Server 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 can cause clients to use weaker encryption settings than configured by the administrator, which might allow attackers to bypass intended restrictions.

    Published: 18 May 2008
    6.5
    Medium

    CVE-2008-2300

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors.

    Published: 18 May 2008
    9.3
    Critical

    CVE-2008-2281

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2297

    Last Modified: 23 Apr 2026

    The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", which is present in the password file and probably passes an insufficient comparison.

    Published: 18 May 2008
    7.5
    High

    CVE-2008-2277

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2278

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter in a pdetails action.

    Published: 16 May 2008
    5
    Medium

    CVE-2008-2279

    Last Modified: 23 Apr 2026

    Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain privileges by reading the table.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2280

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/index.php in Script PHP PicEngine 1.0 allows remote attackers to inject arbitrary web script or HTML via the l parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1158

    Last Modified: 23 Apr 2026

    The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via malformed packets, aka Bug ID CSCsh50164.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1740

    Last Modified: 23 Apr 2026

    The Presence Engine (PE) service in Cisco Unified Presence before 6.0(1) allows remote attackers to cause a denial of service (core dump and service interruption) via an unspecified "stress test," aka Bug ID CSCsh20972.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1741

    Last Modified: 23 Apr 2026

    The SIP Proxy (SIPD) service in Cisco Unified Presence before 6.0(3) allows remote attackers to cause a denial of service (core dump and service interruption) via a TCP port scan, aka Bug ID CSCsj64533.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1742

    Last Modified: 23 Apr 2026

    Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1746

    Last Modified: 23 Apr 2026

    The SNMP Trap Agent service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (core dump and service restart) via a series of malformed UDP packets, as demonstrated by the IP Stack Integrity Checker (ISIC), aka Bug ID CSCsj24113.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1747

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1748

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1745

    Last Modified: 23 Apr 2026

    Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (service interruption) via a SIP JOIN message with a malformed header, aka Bug ID CSCsi48115.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2165

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2263

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2264

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CyrixMED 1.4 allows remote attackers to inject arbitrary web script or HTML via the msg_erreur parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2268

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in interface/redirect.htm.php in Mjguest 6.7 GT Rev.01 allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter in a redirect action to mjguest.php. NOTE: this is user-assisted because there is a delay and a notification before redirection occurs.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2269

    Last Modified: 23 Apr 2026

    AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by setting the gastracker_admin cookie to TRUE.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2270

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to execute arbitrary PHP code via a URL in the (1) main_page_directory and (2) page_to_include parameters in template\index.php.

    Published: 16 May 2008
    5
    Medium

    CVE-2008-2271

    Last Modified: 23 Apr 2026

    The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by leveraging the "access content" permission to list tables and obtain session IDs from the database.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2272

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in Aruba Mobility Controller 2.4.8.x-FIPS, 2.5.5.x, 2.5.6.x, 3.1.1.x, 3.2.0.x, and 3.3.1.x allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 May 2008
    4.4
    Medium

    CVE-2008-2266

    Last Modified: 23 Apr 2026

    uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1743

    Last Modified: 23 Apr 2026

    Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.

    Published: 16 May 2008
    7.8
    High

    CVE-2008-1744

    Last Modified: 23 Apr 2026

    The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2267

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and earlier allows remote attackers to execute arbitrary code by uploading a file with a name ending in (1) .jsp, (2) .php3, (3) .cgi, (4) .dhtml, (5) .phtml, (6) .php5, or (7) .jar, then accessing it via a direct request to the file in modules/FileManager/postlet/.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-2274

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2265

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter.

    Published: 16 May 2008
    9
    Critical

    CVE-2008-2273

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TACACS authentication component in Aruba Mobility Controller 3.1.x, 3.2.x, and 3.3.x allows remote authenticated users to gain privileges via unknown vectors.

    Published: 16 May 2008
    7.5
    High

    CVE-2008-2275

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in sr_feuser_register 1.4.0, 1.6.0, 2.2.1 to 2.2.7, 2.3.0 to 2.3.6, 2.4.0, and 2.5.0 to 2.5.9 extension for TYPO3 allows remote attackers to execute arbitrary code and delete arbitrary files via unspecified attack vectors.

    Published: 16 May 2008
    4.3
    Medium

    CVE-2008-4684

    Last Modified: 23 Apr 2026

    packet-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle exceptions thrown by post dissectors, which allows remote attackers to cause a denial of service (application crash) via a certain series of packets, as demonstrated by enabling the (1) PRP or (2) MATE post dissector.

    Published: 16 May 2008
    1.2
    Low

    CVE-2008-3259

    Last Modified: 23 Apr 2026

    OpenSSH before 5.1 sets the SO_REUSEADDR socket option when the X11UseLocalhost configuration setting is disabled, which allows local users on some platforms to hijack the X11 forwarding port via a bind to a single IP address, as demonstrated on the HP-UX platform.

    Published: 16 May 2008
    7.5
    High

    CVE-2009-0688

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via strings that are used as input to the sasl_encode64 function in lib/saslutil.c.

    Published: 15 May 2008
    2.1
    Low

    CVE-2008-1952

    Last Modified: 23 Apr 2026

    The backend for XenSource Xen Para Virtualized Frame Buffer (PVFB) in Xen ioemu does not properly restrict the frame buffer size, which allows attackers to cause a denial of service (crash) by mapping an arbitrary amount of guest memory.

    Published: 15 May 2008