CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-2175

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2176

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/category.php in Zomplog 3.8.2 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.

    Published: 13 May 2008
    6.8
    Medium

    CVE-2008-2180

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) admin_username parameter (aka the username field) to admin/index.php and the (2) search_text and (3) search_category parameters to search.php. NOTE: some of these details are obtained from third party information.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2181

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in cpLinks 1.03 allow remote attackers to inject arbitrary web script or HTML via the (1) search_text and (2) search_category parameters. NOTE: the XSS reportedly occurs in a forced SQL error message. NOTE: some of these details are obtained from third party information.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2182

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the powermail extension before 1.1.10 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-2183

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to execute arbitrary SQL commands via the idt parameter.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-2184

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in SMartBlog (aka SMBlog) 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) mois, (2) an, (3) jour, and (4) id parameters to index.php, and the (5) login parameter to gestion/logon.php, different vectors than CVE-2008-2183. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 May 2008
    9.3
    Critical

    CVE-2008-1091

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via a Rich Text Format (.rtf) file with a malformed string that triggers a "memory calculation error" and a heap-based buffer overflow, aka "Object Parsing Vulnerability."

    Published: 13 May 2008
    7.1
    High

    CVE-2008-2171

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in AlaxalA AX routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

    Published: 13 May 2008
    5
    Medium

    CVE-2008-1438

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-2169

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Avici routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-2170

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Century routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

    Published: 13 May 2008
    7.1
    High

    CVE-2008-2172

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi GR routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-2173

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Yamaha routers allows remote attackers to cause a denial of service (dropped session) via crafted BGP UPDATE messages, leading to route flapping, possibly a related issue to CVE-2007-6372.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2178

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the searchTerms parameter in an editArticleCategories operation (aka an admin category search).

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2179

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SystemList.jsp in SysAid 5.1.08 allows remote attackers to inject arbitrary web script or HTML via the searchField parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2185

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in SMartBlog (aka SMBlog) 1.3 allows remote attackers to include arbitrary local files via directory traversal sequences in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2186

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2187

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mjguest.php in Mjguest 6.7 GT Rev.01 allows remote attackers to inject arbitrary web script or HTML via the level parameter in a redirect action, possibly involving interface/redirect.htm.php.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2188

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in EJ3 BlackBook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) bookCopyright and (2) ver parameters to (a) footer.php, and the (3) bookName, (4) bookMetaTags, and (5) estiloCSS parameters to (b) header.php.

    Published: 13 May 2008
    9.3
    Critical

    CVE-2008-1434

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) selectors, related to a "memory handling error" that triggers memory corruption.

    Published: 13 May 2008
    6.8
    Medium

    CVE-2008-2177

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in phpDirectorySource 1.1.06, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) lid parameter to show.php and the (2) login parameter to admin.php.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2166

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the search module in Sun Java System Web Server 6.1 before SP9 and 7.0 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unknown parameters in index.jsp.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2167

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or HTML via the Referer header, which is not properly handled in a 404 Error page.

    Published: 13 May 2008
    7.8
    High

    CVE-2008-0322

    Last Modified: 23 Apr 2026

    The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the "\\.\I2OExc" device interface, which allows local users to gain privileges. NOTE: this issue can be leveraged to overwrite arbitrary memory and execute code via an IOCTL call with a crafted DeviceObject pointer.

    Published: 13 May 2008
    6.8
    Medium

    CVE-2008-0713

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the FTP server for HP-UX B.11.11, B.11.23, and B.11.31 allows remote authenticated users to cause a denial of service (FTP server outage) via unknown attack vectors.

    Published: 13 May 2008
    7.5
    High

    CVE-2008-0166

    Last Modified: 23 Apr 2026

    OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.

    Published: 13 May 2008
    4.3
    Medium

    CVE-2008-2163

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in IBM Lotus Quickr 8.1 before Hotfix 5 for Windows and AIX, and before Hotfix 3 for i5/OS, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to "WYSIWYG editors."

    Published: 13 May 2008
    7.2
    High

    CVE-2008-1944

    Last Modified: 23 Apr 2026

    Buffer overflow in the backend framebuffer of XenSource Xen Para-Virtualized Framebuffer (PVFB) Message 3.0 through 3.0.3 allows local users to cause a denial of service (SDL crash) and possibly execute arbitrary code via "bogus screen updates," related to missing validation of the "format of messages."

    Published: 13 May 2008
    2.1
    Low

    CVE-2008-1943

    Last Modified: 23 Apr 2026

    Buffer overflow in the backend of XenSource Xen Para Virtualized Frame Buffer (PVFB) 3.0 through 3.1.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted description of a shared framebuffer.

    Published: 13 May 2008
    2.1
    Low

    CVE-2008-2159

    Last Modified: 23 Apr 2026

    Microsoft Internet Explorer 7 can save encrypted pages in the cache even when the DisableCachingOfSSLPages registry setting is enabled, which might allow local users to obtain sensitive information.

    Published: 12 May 2008
    9.3
    Critical

    CVE-2008-2160

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.

    Published: 12 May 2008
    4.3
    Medium

    CVE-2008-2162

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-existent web page, which is not properly sanitized in an error page.

    Published: 12 May 2008
    10
    Critical

    CVE-2008-2161

    Last Modified: 23 Apr 2026

    Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a long TFTP error packet. NOTE: some of these details are obtained from third party information.

    Published: 12 May 2008
    7.5
    High

    CVE-2008-2149

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the searchwn function in Wordnet 2.0, 2.1, and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end.

    Published: 12 May 2008
    7.5
    High

    CVE-2008-2146

    Last Modified: 23 Apr 2026

    wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

    Published: 12 May 2008
    4.6
    Medium

    CVE-2008-2147

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

    Published: 12 May 2008
    10
    Critical

    CVE-2008-2144

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or execute arbitrary code via unknown vectors.

    Published: 12 May 2008
    7.2
    High

    CVE-2008-2145

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Novell Client 4.91 SP4 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long username in the "forgotten password" dialog.

    Published: 12 May 2008
    1.9
    Low

    CVE-2008-2143

    Last Modified: 23 Apr 2026

    Unspecified versions of Microsoft Outlook Web Access (OWA) use the Cache-Control: no-cache HTTP directive instead of no-store, which might cause web browsers that follow RFC-2616 to cache sensitive information.

    Published: 12 May 2008
    6.5
    Medium

    CVE-2008-2139

    Last Modified: 23 Apr 2026

    The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.

    Published: 12 May 2008
    2.6
    Low

    CVE-2008-2140

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.

    Published: 12 May 2008
    4.3
    Medium

    CVE-2008-2071

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allow remote attackers to perform unauthorized actions as cPanel administrators via requests to cpanel/whm/webmail and other unspecified vectors.

    Published: 12 May 2008
    5
    Medium

    CVE-2008-2138

    Last Modified: 23 Apr 2026

    Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.

    Published: 12 May 2008
    5
    Medium

    CVE-2008-1880

    Last Modified: 23 Apr 2026

    The default configuration of Firebird before 2.0.3.12981.0-r6 on Gentoo Linux sets the ISC_PASSWORD environment variable before starting Firebird, which allows remote attackers to bypass SYSDBA authentication and obtain sensitive database information via an empty password.

    Published: 12 May 2008
    4.3
    Medium

    CVE-2008-2070

    Last Modified: 23 Apr 2026

    The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase, (2) user parameter to scripts2/changeip, (3) search parameter to scripts2/listaccts, and other unspecified vectors.

    Published: 12 May 2008
    4.3
    Medium

    CVE-2007-5803

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CGI programs in Nagios before 2.12 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-5624 and CVE-2008-1360.

    Published: 12 May 2008
    4.3
    Medium

    CVE-2008-2123

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers to inject arbitrary web script or HTML via (1) a "<>" sequence in the ~service parameter to wgate.dll, or (2) Javascript splicing in the query string, a different vector than CVE-2006-5114.

    Published: 9 May 2008
    4.3
    Medium

    CVE-2008-2127

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arbitrary web script or HTML via the what parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2128

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/header.php in CMS Faethon 2.2 Ultimate allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter, a different vulnerability than CVE-2006-5588 and CVE-2006-3185.

    Published: 9 May 2008