CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-2129

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Galleristic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2130

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in poll_vote.php in iGaming CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 May 2008
    4.3
    Medium

    CVE-2008-2131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mvnForum 1.1 GA allows remote authenticated users to inject arbitrary web script or HTML via the topic field, which is later displayed by user/viewthread.jsp through use of the "quick reply button."

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2132

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL commands via the cat_fldAuto parameter.

    Published: 9 May 2008
    4.3
    Medium

    CVE-2008-2126

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to index.php and the (2) returnURL parameter to tux-login.php.

    Published: 9 May 2008
    6.8
    Medium

    CVE-2008-2134

    Last Modified: 23 Apr 2026

    The Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to obtain access to arbitrary user accounts, and alter or delete data, via a modified username in an unspecified cookie.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2135

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) contentname parameter to showdetails.php and the (2) article parameter to printer.php.

    Published: 9 May 2008
    4.3
    Medium

    CVE-2008-2133

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Journal module in Tru-Zone Nuke ET 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter in a new entry, as demonstrated by a CSS property in the STYLE attribute of a DIV element, a different vulnerability than CVE-2008-1873.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2124

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL commands via the lg parameter.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2125

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.

    Published: 9 May 2008
    7.5
    High

    CVE-2008-2122

    Last Modified: 23 Apr 2026

    IBM Rational Build Forge 7.0.2 allows remote attackers to cause a denial of service (CPU consumption) via a port scan, which spawns multiple bfagent server processes that attempt to read data from closed sockets.

    Published: 9 May 2008
    7.8
    High

    CVE-2008-2121

    Last Modified: 23 Apr 2026

    The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of service (CPU consumption and new connection timeouts) via a TCP SYN flood attack.

    Published: 9 May 2008
    5
    Medium

    CVE-2008-2120

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.

    Published: 9 May 2008
    6.8
    Medium

    CVE-2008-2142

    Last Modified: 23 Apr 2026

    Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

    Published: 9 May 2008
    7.8
    High

    CVE-2008-2136

    Last Modified: 23 Apr 2026

    Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT) tunnel interface, related to the pskb_may_pull and kfree_skb functions, and management of an skb reference count.

    Published: 9 May 2008
    4.4
    Medium

    CVE-2008-2116

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to read arbitrary local files via a .. (dot dot) in the (1) te and (2) dir parameters in a tempedit action.

    Published: 8 May 2008
    4.3
    Medium

    CVE-2008-2117

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pages/news.page.inc in Project Alumni 1.0.9 allows remote attackers to inject arbitrary web script or HTML via the year parameter in a news action to index.php, a different vector than CVE-2007-6126.

    Published: 8 May 2008
    7.5
    High

    CVE-2008-2118

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in info.php in Project Alumni 1.0.9 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 8 May 2008
    4.3
    Medium

    CVE-2008-2115

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) te and (2) dir parameters in a tempedit action.

    Published: 8 May 2008
    7.5
    High

    CVE-2008-2114

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the search parameter.

    Published: 8 May 2008
    7.5
    High

    CVE-2008-2113

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 8 May 2008
    8.5
    High

    CVE-2008-2112

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Ray Kiosk Mode 4.0 allows local and remote authenticated Sun Ray administrators to gain root privileges via unknown vectors related to utconfig.

    Published: 8 May 2008
    4.3
    Medium

    CVE-2008-2168

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

    Published: 8 May 2008
    7.2
    High

    CVE-2008-1659

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in HP LDAP-UX vB.04.10 through vB.04.15 allows local users to gain privileges via unknown vectors.

    Published: 8 May 2008
    9.3
    Critical

    CVE-2008-2042

    Last Modified: 23 Apr 2026

    The Javascript API in Adobe Acrobat Professional 7.0.9 and possibly 8.1.1 exposes a dangerous method, which allows remote attackers to execute arbitrary commands or trigger a buffer overflow via a crafted PDF file that invokes app.checkForUpdate with a malicious callback function.

    Published: 8 May 2008
    7.5
    High

    CVE-2008-2110

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request.

    Published: 7 May 2008
    9.3
    Critical

    CVE-2008-2111

    Last Modified: 23 Apr 2026

    The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.

    Published: 7 May 2008
    6.8
    Medium

    CVE-2008-2106

    Last Modified: 23 Apr 2026

    Call of Duty 4 (CoD4) 1.5 and earlier allows remote authenticated users to cause a denial of service (crash) via a type 7 stats packet, which triggers a memcpy with a negative value.

    Published: 7 May 2008
    6.8
    Medium

    CVE-2008-2096

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to a site-specific component name such as link.php or backlinkspider.php.

    Published: 7 May 2008
    4.9
    Medium

    CVE-2007-5001

    Last Modified: 23 Apr 2026

    Linux kernel before 2.4.21 allows local users to cause a denial of service (kernel panic) via asynchronous input or output on a FIFO special file.

    Published: 7 May 2008
    9.3
    Critical

    CVE-2008-1802

    Last Modified: 23 Apr 2026

    Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields.

    Published: 7 May 2008
    9.3
    Critical

    CVE-2008-1803

    Last Modified: 23 Apr 2026

    Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified by the original researcher.

    Published: 7 May 2008
    9.3
    Critical

    CVE-2008-1801

    Last Modified: 23 Apr 2026

    Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.

    Published: 7 May 2008
    7.5
    High

    CVE-2008-2094

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2093

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.

    Published: 6 May 2008
    7.8
    High

    CVE-2008-2092

    Last Modified: 23 Apr 2026

    Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2095

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the book_id parameter.

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2091

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.

    Published: 6 May 2008
    7.8
    High

    CVE-2008-2089

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

    Published: 6 May 2008
    6.8
    Medium

    CVE-2008-2087

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2080

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

    Published: 6 May 2008
    7.8
    High

    CVE-2008-2090

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (CPU consumption and network traffic amplification) via a crafted SCTP packet.

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2088

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.

    Published: 6 May 2008
    5
    Medium

    CVE-2008-2005

    Last Modified: 23 Apr 2026

    The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, allows remote attackers to cause a denial of service (NULL pointer dereference and service shutdown) and possibly execute arbitrary code via a large length value in a Registration packet to TCP port 5413, which causes a memory allocation failure.

    Published: 6 May 2008
    9.3
    Critical

    CVE-2008-5235

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 allows remote attackers to execute arbitrary code via a crafted Real Media file. NOTE: some of these details are obtained from third party information.

    Published: 6 May 2008
    9.8
    Critical

    CVE-2008-2108

    Last Modified: 23 Apr 2026

    The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.

    Published: 6 May 2008
    6.9
    Medium

    CVE-2008-1669

    Last Modified: 23 Apr 2026

    Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in parallel or (2) exploit a race condition to obtain "re-ordered access to the descriptor table."

    Published: 6 May 2008
    7.5
    High

    CVE-2008-2107

    Last Modified: 23 Apr 2026

    The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 32-bit systems, performs a multiplication using values that can produce a zero seed in rare circumstances, which allows context-dependent attackers to predict subsequent values of the rand and mt_rand functions and possibly bypass protection mechanisms that rely on an unknown initial seed.

    Published: 6 May 2008
    6.8
    Medium

    CVE-2008-2083

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in directory.php in Prozilla Hosting Index, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Published: 5 May 2008
    7.5
    High

    CVE-2008-2084

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the topic_id parameter in a listarticles action.

    Published: 5 May 2008