CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-1975

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1967

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in CFLogon/CFLogon.asp in Cezanne 6.5.1 and 7 allows remote attackers to inject arbitrary web script or HTML via the SleUserName parameter.

    Published: 27 Apr 2008
    6
    Medium

    CVE-2008-1968

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Cezanne 7 allow remote authenticated users to execute arbitrary SQL commands via the FUNID parameter to (1) CFLookup.asp and (2) CznCommon/CznCustomContainer.asp.

    Published: 27 Apr 2008
    3.5
    Low

    CVE-2008-1969

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cezanne 6.5.1 and 7 allow remote attackers to inject arbitrary web script or HTML via the (1) LookUPId and (2) CbFun parameters to (a) CFLookUP.asp; (3) TitleParms, (4) WidgetsHeights, (5) WidgetsLinks, and (6) WidgetsTitles parameters to (b) CznCommon/CznCustomContainer.asp, (7) CFTARGET parameter to (c) home.asp, (8) PersonOid parameter to (d) PeopleWeb/Cards/CVCard.asp, (9) DESTLINKOID and PersonOID parameters to (e) PeopleWeb/Cards/PayrollCard.asp, and the (10) FolderTemplateId and (11) FolderTemplateName parameters to (f) PeopleWeb/CznDocFolder/CznDFStartProcess.asp.

    Published: 27 Apr 2008
    2.1
    Low

    CVE-2008-1970

    Last Modified: 23 Apr 2026

    muCommander before 0.8.2 stores credentials.xml with insecure permissions, which allows local users to obtain credentials.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1971

    Last Modified: 23 Apr 2026

    phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or (2) in 1.4 and earlier, the ssbadmin cookie to shoutadmin.php.

    Published: 27 Apr 2008
    4
    Medium

    CVE-2008-1966

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the JAR file administration routines in the BSU JAVA subcomponent in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 allow remote authenticated users to cause a denial of service (instance crash) via a call to the (1) RECOVERJAR or (2) REMOVE_JAR procedure with a crafted parameter, related to (a) sqlj.install_jar and (b) sqlj.replace_jar.

    Published: 27 Apr 2008
    4.3
    Medium

    CVE-2008-1972

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the user account creation feature in Exponent CMS 0.96.6-GA20071003 and earlier, when the Allow Registration? configuration option is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) firstname, (3) lastname, and (4) e-mail address fields. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2008
    9.3
    Critical

    CVE-2008-1973

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

    Published: 27 Apr 2008
    4.9
    Medium

    CVE-2008-2004

    Last Modified: 23 Apr 2026

    The drive_init function in QEMU 0.9.1 determines the format of a raw disk image based on the header, which allows local guest users to read arbitrary files on the host by modifying the header to identify a different format, which is used when the guest is restarted.

    Published: 27 Apr 2008
    7.5
    High

    CVE-2008-1381

    Last Modified: 23 Apr 2026

    ZoneMinder before 1.23.3 allows remote authenticated users, and possibly unauthenticated attackers in some installations, to execute arbitrary commands via shell metacharacters in a crafted URL.

    Published: 27 Apr 2008
    9.3
    Critical

    CVE-2008-1670

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted image.

    Published: 26 Apr 2008
    4.6
    Medium

    CVE-2008-1671

    Last Modified: 23 Apr 2026

    start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable input" (probably command-line arguments) that cause start_kdeinit to send SIGUSR1 signals to other processes.

    Published: 26 Apr 2008
    6.8
    Medium

    CVE-2008-0712

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513.

    Published: 25 Apr 2008
    9.3
    Critical

    CVE-2008-1965

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -launcher option via a cai: URI, as demonstrated by a reference to a UNC share pathname.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1964

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the demux_nsf_send_headers function in src/demuxers/demux_nsf.c in xine-lib allows remote attackers to have an unknown impact via a long copyright field in an NSF header in an NES Sound file, a different issue than CVE-2008-1878. NOTE: a third party claims that the copyright field always has a safe length

    Published: 25 Apr 2008
    4.3
    Medium

    CVE-2008-1953

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Sitedesigner before 1.1.5 search template in Magnolia Enterprise Edition allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1954

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the user_id parameter.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1961

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary SQL commands via the AMG_id parameter in a comments action.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1963

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attackers to execute arbitrary PHP code via a URL in the location parameter.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1959

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the get_remote_video_port_media function in call.cpp in SIPp 3.0 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SIP message. NOTE: some of these details are obtained from third party information.

    Published: 25 Apr 2008
    7.5
    High

    CVE-2008-1957

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands via the nb parameter in voir mode.

    Published: 25 Apr 2008
    4.3
    Medium

    CVE-2008-1956

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbitrary web script or HTML via the wiki parameter.

    Published: 25 Apr 2008
    4.3
    Medium

    CVE-2008-1955

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject arbitrary web script or HTML via the id parameter. information.

    Published: 25 Apr 2008
    6.5
    Medium

    CVE-2008-1958

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authenticated users to execute arbitrary code by uploading a file with a .php extension.

    Published: 25 Apr 2008
    4.3
    Medium

    CVE-2008-1960

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/contray/search.cgi in ContRay 3.x allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Apr 2008
    6.8
    Medium

    CVE-2008-1962

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) class parameter to include/functions.inc.php and the (2) file parameter to include/common.inc.php.

    Published: 25 Apr 2008
    6.8
    Medium

    CVE-2008-3217

    Last Modified: 23 Apr 2026

    PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, which makes it easier for remote attack vectors to conduct DNS cache poisoning. NOTE: this is related to incomplete integration of security improvements associated with addressing CVE-2008-1637.

    Published: 25 Apr 2008
    4.3
    Medium

    CVE-2008-2068

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Apr 2008
    6.4
    Medium

    CVE-2008-1938

    Last Modified: 23 Apr 2026

    Sony Mylo COM-2 Japanese model firmware before 1.002 does not properly verify web server SSL certificates, which allows remote attackers to obtain sensitive information and conduct spoofing attacks.

    Published: 24 Apr 2008
    4.6
    Medium

    CVE-2008-1940

    Last Modified: 23 Apr 2026

    The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls.

    Published: 24 Apr 2008
    7.5
    High

    CVE-2008-1939

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) topic parameters to (a) philboard_reply.asp, and the (3) forumid parameter to (b) philboard_newtopic.asp, different vectors than CVE-2007-2641 and CVE-2007-0920.

    Published: 24 Apr 2008
    3.5
    Low

    CVE-2008-1941

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the profile update feature in Akiva WebBoard 8.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors in the form field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Apr 2008
    6.8
    Medium

    CVE-2008-1942

    Last Modified: 23 Apr 2026

    Foxit Reader 2.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a PDF file with (1) a malformed ExtGState resource containing a /Font resource, or (2) an XObject resource with a Rotate setting, which triggers memory corruption. NOTE: this is probably a different vulnerability than CVE-2007-2186.

    Published: 24 Apr 2008
    6.8
    Medium

    CVE-2008-1931

    Last Modified: 23 Apr 2026

    Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry keys via a crafted IOCTL request.

    Published: 24 Apr 2008
    6.8
    Medium

    CVE-2008-1932

    Last Modified: 23 Apr 2026

    Integer overflow in Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allows local users to execute arbitrary code via a crafted IOCTL request.

    Published: 24 Apr 2008
    4.3
    Medium

    CVE-2008-1933

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run.

    Published: 24 Apr 2008
    6.8
    Medium

    CVE-2008-1769

    Last Modified: 23 Apr 2026

    VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers an out-of-bounds array access and memory corruption.

    Published: 24 Apr 2008
    7.5
    High

    CVE-2008-1934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 24 Apr 2008
    7.5
    High

    CVE-2008-1935

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Filiale 1.0.4 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the idFiliale parameter.

    Published: 24 Apr 2008
    6.8
    Medium

    CVE-2008-1768

    Last Modified: 23 Apr 2026

    Multiple integer overflows in VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via the (1) MP4 demuxer, (2) Real demuxer, and (3) Cinepak codec, which triggers a buffer overflow.

    Published: 24 Apr 2008
    7.5
    High

    CVE-2008-1936

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in an add action. NOTE: this issue might be site-specific.

    Published: 24 Apr 2008
    4.3
    Medium

    CVE-2008-7271

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.

    Published: 24 Apr 2008
    5
    Medium

    CVE-2008-1925

    Last Modified: 23 Apr 2026

    Buffer overflow in InspIRCd before 1.1.18, when using the namesx and uhnames modules, allows remote attackers to cause a denial of service (daemon crash) via a large number of channel users with crafted nicknames, idents, and long hostnames.

    Published: 23 Apr 2008
    7.1
    High

    CVE-2008-1923

    Last Modified: 23 Apr 2026

    The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.

    Published: 23 Apr 2008
    3.5
    Low

    CVE-2008-1924

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in phpMyAdmin before 2.11.5.2, when running on shared hosts, allows remote authenticated users with CREATE table permissions to read arbitrary files via a crafted HTTP POST request, related to use of an undefined UploadDir variable.

    Published: 23 Apr 2008
    4.3
    Medium

    CVE-2008-1386

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the installer in Serendipity (S9Y) 1.3 allow remote attackers to inject arbitrary web script or HTML via (1) unspecified path fields or (2) the database host field. NOTE: the timing window for exploitation of this issue might be limited.

    Published: 23 Apr 2008
    4.3
    Medium

    CVE-2008-1385

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.

    Published: 23 Apr 2008
    9.3
    Critical

    CVE-2007-6255

    Last Modified: 23 Apr 2026

    Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.

    Published: 23 Apr 2008
    9.3
    Critical

    CVE-2008-1765

    Last Modified: 23 Apr 2026

    Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute arbitrary code via a BMP file with an invalid image header. NOTE: the related issue in Photoshop CS3 is already covered by CVE-2007-2244.

    Published: 23 Apr 2008