CVE Feed

    Dashboard / CVE

    1.9
    Low

    CVE-2008-1865

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the msx_readnode function in libmosix.c in openmosix-tools (aka userspace-tools) in openMosix might allow local users to cause a denial of service (application crash) via a third-party program that calls this function with a long item argument. NOTE: the vendor does not provide any program that is capable of causing this overflow.

    Published: 17 Apr 2008
    9
    Critical

    CVE-2008-1866

    Last Modified: 23 Apr 2026

    admin/modif_config.php in Blog Pixel Motion (aka PixelMotion) does not require admin authentication, which allows remote authenticated users to upload arbitrary PHP scripts in a ZIP archive, which is written to templateZip/ and then automatically extracted under templates/ for execution via a direct request.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1867

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL commands via the categorie parameter to index.php, possibly related to include/requetesIndex.php.

    Published: 17 Apr 2008
    6.5
    Medium

    CVE-2008-1871

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to execute arbitrary SQL commands via the cat_id parameter in a list action.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1872

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Apr 2008
    6.5
    Medium

    CVE-2008-1874

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to execute arbitrary SQL commands via the reed parameter.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1875

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2008-1876

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the _CONFIG[files][functions_page] parameter.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1870

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1869

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: this issue might be site-specific.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2008-1024

    Last Modified: 23 Apr 2026

    Apple Safari before 3.1.1, when running on Windows XP or Vista, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file download with a crafted file name, which triggers memory corruption.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1863

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1868

    Last Modified: 23 Apr 2026

    admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote attackers to trigger a database backup dump, and obtain the resulting blogPM.sql file that contains sensitive information.

    Published: 17 Apr 2008
    4.3
    Medium

    CVE-2008-1873

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the private message feature in Nuke ET 3.2 and 3.4, when using Internet Explorer, allows remote authenticated users to inject arbitrary web script or HTML via a CSS property in the STYLE attribute of a DIV element in the mensaje parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Apr 2008
    5.1
    Medium

    CVE-2008-1861

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the exbb[default_lang] parameter.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2008-1862

    Last Modified: 23 Apr 2026

    ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which allows remote attackers to bypass this check via (1) POST or (2) COOKIE variables, a different vector than CVE-2006-4488. NOTE: this can be leveraged to conduct PHP remote file inclusion attacks via a URL in the (a) new_exbb[home_path] or (b) exbb[home_path] parameter to modules/threadstop/threadstop.php.

    Published: 17 Apr 2008
    9.3
    Critical

    CVE-2008-1860

    Last Modified: 23 Apr 2026

    Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2007-5746

    Last Modified: 23 Apr 2026

    Integer overflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an EMF file with a crafted EMR_STRETCHBLT record, which triggers a heap-based buffer overflow.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2007-5747

    Last Modified: 23 Apr 2026

    Integer underflow in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted values that trigger an excessive loop and a stack-based buffer overflow.

    Published: 17 Apr 2008
    9.3
    Critical

    CVE-2008-0320

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an OLE file with a crafted DocumentSummaryInformation stream.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2008-1693

    Last Modified: 23 Apr 2026

    The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2007-5745

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in OpenOffice.org before 2.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Quattro Pro (QPRO) file with crafted (1) Attribute and (2) Font Description records.

    Published: 17 Apr 2008
    6.8
    Medium

    CVE-2008-1102

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the imb_loadhdr function in Blender 2.45 allows user-assisted remote attackers to execute arbitrary code via a .blend file that contains a crafted Radiance RGBE image.

    Published: 17 Apr 2008
    7.5
    High

    CVE-2008-1878

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long NSF title.

    Published: 17 Apr 2008
    9.3
    Critical

    CVE-2007-6713

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Flip4Mac WMV before 2.2.0.49 has unknown impact and attack vectors related to malformed WMV files.

    Published: 16 Apr 2008
    6.8
    Medium

    CVE-2008-1857

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in viewsource.php in Make our Life Easy (Mole) 2.1.0 allow remote attackers to read arbitrary files via directory traversal sequences in the (1) dirn and (2) fname parameters.

    Published: 16 Apr 2008
    7.5
    High

    CVE-2008-1858

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 16 Apr 2008
    7.5
    High

    CVE-2008-1859

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action.

    Published: 16 Apr 2008
    5
    Medium

    CVE-2008-1854

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SmarterMail Web Server (SMWebSvr.exe) in SmarterMail 5.0.2999 allows remote attackers to cause a denial of service (service termination) via a long HTTP (1) GET, (2) HEAD, (3) PUT, (4) POST, or (5) TRACE request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Apr 2008
    5
    Medium

    CVE-2008-1855

    Last Modified: 23 Apr 2026

    FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service crash) via a long invalid method in requests for the /spin//AVClient//AVClient.csp URI, a different vulnerability than CVE-2006-5274.

    Published: 16 Apr 2008
    5.1
    Medium

    CVE-2008-1856

    Last Modified: 23 Apr 2026

    plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration.

    Published: 16 Apr 2008
    6.9
    Medium

    CVE-2007-5664

    Last Modified: 23 Apr 2026

    db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to overwrite arbitrary files via a symlink attack on files used for initialization.

    Published: 16 Apr 2008
    5
    Medium

    CVE-2008-0068

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in OpenView5.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to read arbitrary files via directory traversal sequences in the Action parameter.

    Published: 16 Apr 2008
    5
    Medium

    CVE-2008-1851

    Last Modified: 23 Apr 2026

    ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (hang) via certain requests that do not provide all required arguments.

    Published: 16 Apr 2008
    4.3
    Medium

    CVE-2008-1853

    Last Modified: 23 Apr 2026

    The ovtopmd service in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (exit) by sending a 0x36 packet (exit request).

    Published: 16 Apr 2008
    6.9
    Medium

    CVE-2007-5758

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in db2dasrrm in the DB2 Administration Server (DAS) in IBM DB2 Universal Database 9.5 before Fix Pack 1, 9.1 before Fix Pack 4a, and 8 before FixPak 16 allows local users to execute arbitrary code via a long DASPROF environment variable.

    Published: 16 Apr 2008
    7.8
    High

    CVE-2008-1852

    Last Modified: 23 Apr 2026

    ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, 7.53, and possibly other versions allows remote attackers to cause a denial of service (crash) via certain requests that specify a large number of sub-arguments, which triggers a NULL pointer dereference due to memory allocation failure.

    Published: 16 Apr 2008
    10
    Critical

    CVE-2008-1155

    Last Modified: 23 Apr 2026

    Cisco Network Admission Control (NAC) Appliance 3.5.x, 3.6.x before 3.6.4.4, 4.0.x before 4.0.6, and 4.1.x before 4.1.2 allows remote attackers to obtain the shared secret for the Clean Access Server (CAS) and Clean Access Manager (CAM) by sniffing error logs.

    Published: 16 Apr 2008
    7.5
    High

    CVE-2008-1838

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.

    Published: 16 Apr 2008
    6.5
    Medium

    CVE-2008-1840

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.

    Published: 16 Apr 2008
    10
    Critical

    CVE-2008-1842

    Last Modified: 23 Apr 2026

    Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.

    Published: 16 Apr 2008
    7.5
    High

    CVE-2008-1843

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.php in W2B DatingClub (aka Dating Club) allows remote attackers to execute arbitrary SQL commands via the age_to parameter in a browsebyCat action.

    Published: 16 Apr 2008
    7.5
    High

    CVE-2008-1847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Apr 2008
    4.3
    Medium

    CVE-2008-1848

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter in a show_error action to index.php.

    Published: 16 Apr 2008
    5
    Medium

    CVE-2008-1849

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 and earlier allows remote attackers to list arbitrary directories via a .. (dot dot) in the dir parameter in a show_error action.

    Published: 16 Apr 2008
    9.3
    Critical

    CVE-2008-1786

    Last Modified: 23 Apr 2026

    The DSM gui_cm_ctrls ActiveX control (gui_cm_ctrls.ocx), as used in multiple CA products including BrightStor ARCServe Backup for Laptops and Desktops r11.5, Desktop Management Suite r11.1 through r11.2 C2; Unicenter r11.1 through r11.2 C2; and Desktop and Server Management r11.1 through r11.2 C2 allows remote attackers to execute arbitrary code via crafted function arguments.

    Published: 16 Apr 2008
    4.3
    Medium

    CVE-2008-1839

    Last Modified: 23 Apr 2026

    Multgiple cross-site scripting (XSS) vulnerabilities in module/main.php in WORK system e-commerce 4.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, and (3) year parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Apr 2008
    6.8
    Medium

    CVE-2008-1841

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.

    Published: 16 Apr 2008
    4.3
    Medium

    CVE-2008-1846

    Last Modified: 23 Apr 2026

    The default configuration of SAP NetWeaver before 7.0 SP15 does not enable the "Always Use Secure HTML Editor" (aka Editor Security or Secure Editing) parameter, which allows remote attackers to conduct cross-site scripting (XSS) attacks by entering feedback for a file.

    Published: 16 Apr 2008
    4.3
    Medium

    CVE-2008-1850

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in login.php in Omnistar Interactive OSI Affiliate allow remote attackers to inject arbitrary web script or HTML via the (1) login, (2) profile, (3) profile2, and (4) ref parameters.

    Published: 16 Apr 2008