CVE Feed

    Dashboard / CVE

    3.6
    Low

    CVE-2008-2148

    Last Modified: 23 Apr 2026

    The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.

    Published: 8 Apr 2008
    9.3
    Critical

    CVE-2007-0071

    Last Modified: 23 Apr 2026

    Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.

    Published: 8 Apr 2008
    9.3
    Critical

    CVE-2008-3872

    Last Modified: 23 Apr 2026

    Adobe Flash Player 8.0.39.0 and earlier, and 9.x up to 9.0.115.0, allows remote attackers to bypass the allowScriptAccess parameter setting via a crafted SWF file with unspecified "Filter evasion" manipulations.

    Published: 8 Apr 2008
    9.3
    Critical

    CVE-2007-6019

    Last Modified: 23 Apr 2026

    Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via an SWF file with a modified DeclareFunction2 Actionscript tag, which prevents an object from being instantiated properly.

    Published: 8 Apr 2008
    7.5
    High

    CVE-2008-1720

    Last Modified: 23 Apr 2026

    Buffer overflow in rsync 2.6.9 to 3.0.1, with extended attribute (xattr) support enabled, might allow remote attackers to execute arbitrary code via unknown vectors.

    Published: 8 Apr 2008
    9.3
    Critical

    CVE-2008-1887

    Last Modified: 23 Apr 2026

    Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.

    Published: 8 Apr 2008
    5
    Medium

    CVE-2008-1996

    Last Modified: 23 Apr 2026

    licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash) via a large number of connections.

    Published: 8 Apr 2008
    4.3
    Medium

    CVE-2008-1655

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.

    Published: 8 Apr 2008
    4.3
    Medium

    CVE-2008-1722

    Last Modified: 23 Apr 2026

    Multiple integer overflows in (1) filter/image-png.c and (2) filter/image-zoom.c in CUPS 1.3 allow attackers to cause a denial of service (crash) and trigger memory corruption, as demonstrated via a crafted PNG image.

    Published: 8 Apr 2008
    9.3
    Critical

    CVE-2008-1328

    Last Modified: 23 Apr 2026

    Buffer overflow in the LGServer service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary code via unspecified "command arguments."

    Published: 7 Apr 2008
    5
    Medium

    CVE-2008-1618

    Last Modified: 23 Apr 2026

    The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes depending on whether the username is valid or invalid, which allows remote attackers to enumerate valid usernames.

    Published: 7 Apr 2008
    9
    Critical

    CVE-2007-4620

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager for the Enterprise 8.1 and r8, allow remote authenticated users to execute arbitrary code via crafted RPC requests.

    Published: 7 Apr 2008
    10
    Critical

    CVE-2008-1329

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the NetBackup service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary commands, related to "insufficient verification of file uploads."

    Published: 7 Apr 2008
    6.9
    Medium

    CVE-2008-0310

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append to arbitrary files via ".." sequences in an unspecified environment variable, probably PKGINST.

    Published: 7 Apr 2008
    5
    Medium

    CVE-2008-1689

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (daemon crash) via a long request header in an HTTP request to TCP port 801. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2008
    10
    Critical

    CVE-2008-1690

    Last Modified: 23 Apr 2026

    WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a long URI in HTTP requests to TCP port 801. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2008
    5
    Medium

    CVE-2008-1691

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in SLMail.exe in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (UDP service outage) via a large packet to UDP port 54. NOTE: some of these details are obtained from third party information.

    Published: 7 Apr 2008
    5.5
    Medium

    CVE-2008-0709

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other user accounts via unknown vectors, a different issue than CVE-2008-0214.

    Published: 7 Apr 2008
    9.3
    Critical

    CVE-2008-0311

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.

    Published: 6 Apr 2008
    4.6
    Medium

    CVE-2008-0708

    Last Modified: 23 Apr 2026

    HP USB 2.0 Floppy Drive Key product options (1) 442084-B21 and (2) 442085-B21 for certain HP ProLiant servers contain the (a) W32.Fakerecy and (b) W32.SillyFDC worms, which might be launched if the server does not have up-to-date detection.

    Published: 6 Apr 2008
    10
    Critical

    CVE-2008-1602

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.

    Published: 6 Apr 2008
    4.7
    Medium

    CVE-2008-1684

    Last Modified: 23 Apr 2026

    inetd on Sun Solaris 10, when debug logging is enabled, allows local users to write to arbitrary files via a symlink attack on the /var/tmp/inetd.log temporary file.

    Published: 6 Apr 2008
    6.8
    Medium

    CVE-2008-1682

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter.

    Published: 4 Apr 2008
    10
    Critical

    CVE-2008-1681

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privilege.

    Published: 4 Apr 2008
    10
    Critical

    CVE-2008-1154

    Last Modified: 23 Apr 2026

    The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1013

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote attackers to execute arbitrary code via a crafted applet.

    Published: 4 Apr 2008
    4.3
    Medium

    CVE-2008-1014

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.4.5 does not properly handle external URLs in movies, which allows remote attackers to obtain sensitive information.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1015

    Last Modified: 23 Apr 2026

    Buffer overflow in the data reference atom handling in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1018

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via an MP4A movie with a malformed Channel Compositor (aka chan) atom.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1019

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted PICT image file, related to an improperly terminated memory copy loop.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1020

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in quickTime.qts in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file with Kodak encoding, related to error checking and error messages.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1021

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Animation codec content handling in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted movie with run length encoding.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1022

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted VR movie with an obji atom of zero size.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1023

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Clip opcode parsing in Apple QuickTime before 7.4.5 on Windows allows remote attackers to execute arbitrary code via a crafted PICT image file.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1017

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in clipping region (aka crgn) atom handling in quicktime.qts in Apple QuickTime before 7.4.5 allows remote attackers to execute arbitrary code via a crafted movie.

    Published: 4 Apr 2008
    6.8
    Medium

    CVE-2008-1016

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.4.5 does not properly handle movie media tracks, which allows remote attackers to execute arbitrary code via a crafted movie that triggers memory corruption.

    Published: 4 Apr 2008
    9.3
    Critical

    CVE-2007-5661

    Last Modified: 1 Aug 2025

    The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.

    Published: 4 Apr 2008
    5
    Medium

    CVE-2008-1680

    Last Modified: 23 Apr 2026

    PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.

    Published: 4 Apr 2008
    7.5
    High

    CVE-2008-0555

    Last Modified: 23 Apr 2026

    The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' characters in a Distinguished Name (DN) in a client certificate, which might allow remote attackers to bypass authentication via a crafted DN that triggers overwriting of environment variables.

    Published: 4 Apr 2008
    10
    Critical

    CVE-2008-1331

    Last Modified: 23 Apr 2026

    cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014.001, and other versions, allows remote attackers to execute arbitrary commands and "obtain OXO resources" via shell metacharacters in the id2 parameter.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1654

    Last Modified: 23 Apr 2026

    Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

    Published: 2 Apr 2008
    6.8
    Medium

    CVE-2008-0069

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long FontName parameter in a slideshow (.sld) file, a different vector than CVE-2008-1461.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1620

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r3497 and earlier allows remote attackers to read or overwrite arbitrary files via a ... (dot dot dot) in the filename.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1621

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    6.8
    Medium

    CVE-2008-1625

    Last Modified: 23 Apr 2026

    aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain privileges via certain IOCTL requests.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1626

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in eggBlog before 4.0.1 allows remote attackers to execute arbitrary SQL commands via an unspecified cookie. NOTE: this might overlap CVE-2008-0159.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1629

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PHPkrm before 1.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1634

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JV2 Folder Gallery 3.1 allows remote attackers to inject arbitrary web script or HTML via the image parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1635

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tmp_theme parameter. NOTE: 5.1.1 is also reportedly affected.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1636

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in JV2 Quick Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the f parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008