CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-2022

    Last Modified: 23 Apr 2026

    Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) toid parameter to send-private-message.asp and the (2) redirect parameter to admin/impersonate.asp. NOTE: vector 2 requires authentication.

    Published: 30 Apr 2008
    4.3
    Medium

    CVE-2008-2024

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the glang[] parameter in a registernew action.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2023

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) invisible and (2) timeoffset parameters to profile/controlpanel.asp and the (3) attachmentid parameter to forums/attach-file.asp.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2021

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Lhaplus before 1.57 allows remote attackers to execute arbitrary code via a long comment field in a ZOO archive.

    Published: 30 Apr 2008
    4
    Medium

    CVE-2008-2018

    Last Modified: 23 Apr 2026

    The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authenticated users to obtain sensitive information via a comment containing a macro, as demonstrated by a "{user.password}" comment in the profile of the admin user.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2020

    Last Modified: 23 Apr 2026

    The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 123tkShop) 0.9.1, (3) phpMyBitTorrent 1.2.2, (4) TorrentFlux 2.3, (5) e107 0.7.11, (6) WebZE 0.5.9, (7) Open Media Collectors Database (aka OpenDb) 1.5.0b4, and (8) Labgab 1.1 uses a code_bg.jpg background image and the PHP ImageString function in a way that produces an insufficient number of different images, which allows remote attackers to pass the CAPTCHA test via an automated attack using a table of all possible image checksums and their corresponding digit strings.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2019

    Last Modified: 23 Apr 2026

    Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA, which allows remote attackers to pass the CAPTCHA test via an automated attack that considers Hamming distances. NOTE: this issue reportedly exists because of an insufficient fix for CVE-2007-3308.

    Published: 30 Apr 2008
    9.3
    Critical

    CVE-2008-2015

    Last Modified: 23 Apr 2026

    Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in one control, and the (3) saveRecordedExploreToFile method in a different control. NOTE: this can be leveraged for code execution by writing to a Startup folder.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2017

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the operation parameter to the default URI under install/.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2016

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter to the default URI under install/. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Published: 30 Apr 2008
    5
    Medium

    CVE-2008-2014

    Last Modified: 23 Apr 2026

    Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls document.write in an infinite loop.

    Published: 30 Apr 2008
    7.5
    High

    CVE-2008-2012

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event action.

    Published: 30 Apr 2008
    5
    Medium

    CVE-2008-1678

    Last Modified: 23 Apr 2026

    Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client handshakes to the Apache HTTP Server mod_ssl that specify a compression algorithm.

    Published: 30 Apr 2008
    7.8
    High

    CVE-2008-2812

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.25.10 does not properly perform tty operations, which allows local users to cause a denial of service (system crash) or possibly gain privileges via vectors involving NULL pointer dereference of function pointers in (1) hamradio/6pack.c, (2) hamradio/mkiss.c, (3) irda/irtty-sir.c, (4) ppp_async.c, (5) ppp_synctty.c, (6) slip.c, (7) wan/x25_asy.c, and (8) wireless/strip.c in drivers/net/.

    Published: 30 Apr 2008
    6.8
    Medium

    CVE-2008-2013

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in a display action.

    Published: 30 Apr 2008
    4.9
    Medium

    CVE-2008-1735

    Last Modified: 23 Apr 2026

    BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an invalid pointer to the CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.

    Published: 29 Apr 2008
    2.1
    Low

    CVE-2008-1738

    Last Modified: 23 Apr 2026

    Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid pointer to the _CLIENT_ID structure in a call to the NtOpenProcess hooked System Service Descriptor Table (SSDT) function.

    Published: 29 Apr 2008
    7.2
    High

    CVE-2008-1736

    Last Modified: 23 Apr 2026

    Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (SSDT) functions, which allows local users to cause a denial of service (system crash) via (1) a crafted OBJECT_ATTRIBUTES structure in a call to the NtDeleteFile function, which leads to improper validation of a ZwQueryObject result; and unspecified calls to the (2) NtCreateFile and (3) NtSetThreadContext functions, different vectors than CVE-2007-0709.

    Published: 29 Apr 2008
    6.9
    Medium

    CVE-2008-1737

    Last Modified: 23 Apr 2026

    Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cause a denial of service (reboot with the product disabled) and possibly gain privileges via a zero value in a certain length field in the ObjectAttributes argument to the NtCreateKey hooked System Service Descriptor Table (SSDT) function.

    Published: 29 Apr 2008
    9.3
    Critical

    CVE-2008-2010

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute arbitrary code via a crafted QuickTime media file. NOTE: as of 20080429, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

    Published: 29 Apr 2008
    4.3
    Medium

    CVE-2008-2011

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows remote National Rail Enquiries servers or man-in-the-middle attackers to inject arbitrary web script or HTML, and execute arbitrary code, via a response body, as demonstrated by a SCRIPT element that references a vbscript: URI.

    Published: 29 Apr 2008
    9.3
    Critical

    CVE-2008-2008

    Last Modified: 23 Apr 2026

    Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.

    Published: 29 Apr 2008
    4.8
    Medium

    CVE-2008-1293

    Last Modified: 23 Apr 2026

    ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which allows remote attackers to connect to this server via TCP port 6006 (aka display :6).

    Published: 29 Apr 2008
    7.5
    High

    CVE-2008-2003

    Last Modified: 23 Apr 2026

    BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1) cause a denial of service via multiple invocations of uninst.exe, and have an unknown impact via (2) badblue.exe and (3) dyndns.exe. NOTE: this can be leveraged for arbitrary remote code execution in conjunction with CVE-2007-6378.

    Published: 28 Apr 2008
    8.5
    High

    CVE-2008-1998

    Last Modified: 23 Apr 2026

    The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter.

    Published: 28 Apr 2008
    6.9
    Medium

    CVE-2008-1103

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issues."

    Published: 28 Apr 2008
    4.3
    Medium

    CVE-2008-2001

    Last Modified: 23 Apr 2026

    Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that triggers an out-of-bounds access, possibly due to a NULL pointer dereference.

    Published: 28 Apr 2008
    7.8
    High

    CVE-2008-2002

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH allow remote attackers to (1) cause a denial of service (device reboot) via the "Restart Cable Modem" value in the BUTTON_INPUT parameter to configdata.html, and (2) cause a denial of service (hard reset) via the "Reset All Defaults" value in the BUTTON_INPUT parameter to configdata.html.

    Published: 28 Apr 2008
    7.5
    High

    CVE-2008-1930

    Last Modified: 23 Apr 2026

    The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPIRY_TIME, which allows remote attackers to forge cookies by registering a username that results in the same concatenated string, as demonstrated by registering usernames beginning with "admin" to obtain administrator privileges, aka a "cryptographic splicing" issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-6013.

    Published: 28 Apr 2008
    9
    Critical

    CVE-2008-1997

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unknown vectors. NOTE: the ADMIN_SP_C issue is already covered by CVE-2008-0699.

    Published: 28 Apr 2008
    7.5
    High

    CVE-2008-1995

    Last Modified: 23 Apr 2026

    Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect application of policy and allows remote attackers to bypass intended access restrictions for the server.

    Published: 28 Apr 2008
    4.3
    Medium

    CVE-2008-1985

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1986

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1987

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in EncapsGallery 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1992

    Last Modified: 23 Apr 2026

    Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, which allows remote attackers to bypass restrictions and relay email messages with modified From, FromName, and To fields.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1993

    Last Modified: 23 Apr 2026

    Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.

    Published: 27 Apr 2008
    7.2
    High

    CVE-2008-1994

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in (a) acon.c, (b) menu.c, and (c) child.c in Acon 1.0.5-5 through 1.0.5-7 allow local users to execute arbitrary code via (1) a long HOME environment variable or (2) a large number of terminal columns.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1990

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) cID parameter to default.asp and the (2) username parameter to main_login2.asp.

    Published: 27 Apr 2008
    9
    Critical

    CVE-2008-1988

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows remote authenticated administrators to upload and execute arbitrary PHP files by uploading a file with an executable extension, then accessing it via a direct request to the file in the rwx_gallery directory. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 27 Apr 2008
    10
    Critical

    CVE-2008-1989

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the e107path parameter.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1991

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the field parameter.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1977

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Internationalization (i18n) Drupal module 5.x before 5.x-2.3 and 5.x-1.1, and 6.x before 6.x-1.0 beta 1, allows remote attackers to change node translation relationships via unspecified vectors.

    Published: 27 Apr 2008
    3.5
    Low

    CVE-2008-1978

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Ubercart 5.x before 5.x-1.0 rc3 module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via node titles related to unspecified product features, a different vector than CVE-2008-1428.

    Published: 27 Apr 2008
    5
    Medium

    CVE-2008-1979

    Last Modified: 23 Apr 2026

    The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial of service (crash) via a packet with a large integer value used in an increment to TCP port 41523, which triggers a buffer over-read.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1976

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Drupal modules (1) Internationalization (i18n) 5.x before 5.x-2.3 and 5.x-1.1 and 6.x before 6.x-1.0 beta 1; and (2) Localizer 5.x before 5.x-3.4, 5.x-2.1, and 5.x-1.11; allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1983

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitrary web script or HTML via the beg parameter in a members action to index.php.

    Published: 27 Apr 2008
    7.8
    High

    CVE-2008-1984

    Last Modified: 23 Apr 2026

    The eTrust Common Services (Transport) Daemon (eCSqdmn) in CA Secure Content Manager 8.0.28000.511 and earlier allows remote attackers to cause a denial of service (crash or CPU consumption) via a malformed packet to TCP port 1882.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1982

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.

    Published: 27 Apr 2008
    6.8
    Medium

    CVE-2008-1981

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to perform unauthorized actions as other users via unspecified vectors.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1980

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in E-Publish 5.x before 5.x-1.1 and 6.x before 6.x-1.0 beta1, a Drupal module, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Apr 2008