CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-1638

    Last Modified: 23 Apr 2026

    Nik Sharpener Pro, possibly 2.0, uses world-writable permissions for plug-in files, which allows local users to gain privileges by replacing a plug-in with a Trojan horse.

    Published: 2 Apr 2008
    5
    Medium

    CVE-2008-1643

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.7 SP5 and earlier and 8.8 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1645

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitrary local files via a .. (dot dot) in the filename parameter.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1646

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1640

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Board (wBB) allows remote attackers to execute arbitrary SQL commands via the view_id parameter in an ansicht action.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1641

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1650

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL commands via the read parameter in an edp_Help_Internal_News action.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1651

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 2 Apr 2008
    3.5
    Low

    CVE-2008-1627

    Last Modified: 23 Apr 2026

    CDS Invenio 0.92.1 and earlier allows remote authenticated users to delete email notification alerts of arbitrary users via a modified internal UID.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1642

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    5
    Medium

    CVE-2008-1648

    Last Modified: 23 Apr 2026

    Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.

    Published: 2 Apr 2008
    6.8
    Medium

    CVE-2008-1622

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via a URL in the id parameter to (1) show.php, (2) search.php, and (3) view.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1623

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1624

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the xPage parameter.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1630

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CuteFlow 1.5.0 and 2.10.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) page/showcirculation.php; and (2) edittemplate_step2.php, (3) showfields.php, (4) showuser.php, (5) editmailinglist_step1.php, and (6) showtemplates.php in pages/.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1632

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) listid parameter to pages/editmailinglist_step1.php, the (2) userid parameter to pages/edituser.php, the (3) fieldid parameter to pages/editfield.php, and the (4) templateid to pages/edittemplate_step1.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    10
    Critical

    CVE-2008-1633

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) /tmp and (2) MINDI_CACHE.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1644

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1649

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in staticpages/easypublish/index.php in EasyNews 4.0 allows remote attackers to inject arbitrary web script or HTML via the read parameter in an edp_pupublish action.

    Published: 2 Apr 2008
    6.8
    Medium

    CVE-2008-1653

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Sava's Link Manager 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the q parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1631

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in CuteFlow 1.5.0 and 2.10.0 allows remote attackers to execute arbitrary SQL commands via the UserId parameter, related to the login form field in index.php.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1639

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a show action, probably related to the showArticle function in lib/lib_article.include.php.

    Published: 2 Apr 2008
    9.3
    Critical

    CVE-2008-1647

    Last Modified: 23 Apr 2026

    The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0, and earlier in ChilkatHttp ActiveX expose the unsafe SaveLastError method, which allows remote attackers to overwrite arbitrary files. NOTE: some of these details are obtained from third party information.

    Published: 2 Apr 2008
    4.3
    Medium

    CVE-2008-1614

    Last Modified: 23 Apr 2026

    suPHP before 0.6.3 allows local users to gain privileges via (1) a race condition that involves multiple symlink changes to point a file owned by a different user, or (2) a symlink to the directory of a different user, which is used to determine privileges.

    Published: 2 Apr 2008
    4.7
    Medium

    CVE-2008-0887

    Last Modified: 23 Apr 2026

    gnome-screensaver before 2.22.1, when a remote authentication server is enabled, crashes upon an unlock attempt during a network outage, which allows physically proximate attackers to gain access to the locked session, a related issue to CVE-2007-1859.

    Published: 2 Apr 2008
    Unknown

    CVE-2008-1683

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-0887. Reason: This candidate is a duplicate of CVE-2008-0887. Notes: All CVE users should reference CVE-2008-0887 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1687

    Last Modified: 23 Apr 2026

    The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

    Published: 2 Apr 2008
    7.5
    High

    CVE-2008-1688

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.

    Published: 2 Apr 2008
    4.7
    Medium

    CVE-2008-2365

    Last Modified: 23 Apr 2026

    Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.

    Published: 2 Apr 2008
    6.4
    Medium

    CVE-2008-1515

    Last Modified: 23 Apr 2026

    The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related to "Missing security checks."

    Published: 1 Apr 2008
    4.3
    Medium

    CVE-2008-1603

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in GNB DesignForm before 3.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the email form.

    Published: 1 Apr 2008
    4.3
    Medium

    CVE-2008-1604

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PerlMailer before 3.02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Apr 2008
    6.8
    Medium

    CVE-2008-1605

    Last Modified: 23 Apr 2026

    The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.

    Published: 1 Apr 2008
    10
    Critical

    CVE-2008-1611

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request.

    Published: 1 Apr 2008
    6
    Medium

    CVE-2008-1606

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Elastic Path (EP) 4.1 and 4.1.1 allow remote attackers to (1) download arbitrary files via a .. (dot dot) in the file parameter to manager/getImportFileRedirect.jsp, (2) upload arbitrary files via a "..\" (dot dot backslash) in the file parameter to importData.jsp, and (3) list directory contents via a .. (dot dot) in the dir parameter to manager/fileManager.jsp.

    Published: 1 Apr 2008
    6.8
    Medium

    CVE-2008-1607

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbitrary SQL commands via the haber parameter.

    Published: 1 Apr 2008
    7.5
    High

    CVE-2008-1608

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in postview.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter, a different vector than CVE-2008-0363 and CVE-2006-0583.

    Published: 1 Apr 2008
    6.8
    Medium

    CVE-2008-1609

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php, (b) headlines.php, and (c) main.php in forum/, and (2) main_dir parameter to forum/forum.php. NOTE: other main_dir vectors are already covered by CVE-2006-7127.

    Published: 1 Apr 2008
    7.5
    High

    CVE-2008-1610

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request.

    Published: 1 Apr 2008
    6.8
    Medium

    CVE-2008-1374

    Last Modified: 23 Apr 2026

    Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888.

    Published: 1 Apr 2008
    6.9
    Medium

    CVE-2008-0884

    Last Modified: 23 Apr 2026

    The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp packages before 0.65-2 in Red Hat Enterprise Linux (RHEL) 5 uses lstat instead of stat to determine the /etc/pam.d/system-auth file permissions, leading to a change to world-writable permissions for the /etc/pam.d/system-auth-ac file, which allows local users to gain privileges by modifying this file.

    Published: 1 Apr 2008
    5.8
    Medium

    CVE-2008-1373

    Last Modified: 23 Apr 2026

    Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF file with a large code_size value, a similar issue to CVE-2006-4484.

    Published: 1 Apr 2008
    4.6
    Medium

    CVE-2008-1592

    Last Modified: 23 Apr 2026

    MQSeries 5.1 in IBM WebSphere MQ 5.1 through 5.3.1 on the HP NonStop and Tandem NSK platforms does not require mqm group membership for execution of administrative tasks, which allows local users to bypass intended access restrictions via the runmqsc program, related to "Pathway panels."

    Published: 31 Mar 2008
    7.2
    High

    CVE-2008-1593

    Last Modified: 23 Apr 2026

    The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.

    Published: 31 Mar 2008
    4.9
    Medium

    CVE-2008-1594

    Last Modified: 23 Apr 2026

    The kernel in IBM AIX 5.2 and 5.3 does not properly handle resizing JFS2 filesystems on concurrent volume groups spread across multiple nodes, which allows local users of one node to cause a denial of service (remote node crash) by using chfs or lreducelv to reduce a filesystem's size.

    Published: 31 Mar 2008
    4.9
    Medium

    CVE-2008-1595

    Last Modified: 23 Apr 2026

    The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information.

    Published: 31 Mar 2008
    7.2
    High

    CVE-2008-1596

    Last Modified: 23 Apr 2026

    Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.

    Published: 31 Mar 2008
    7.5
    High

    CVE-2008-1591

    Last Modified: 23 Apr 2026

    The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as demonstrated by the CLIENT_IP HTTP header (HTTP_CLIENT_IP variable).

    Published: 31 Mar 2008
    7.2
    High

    CVE-2008-1600

    Last Modified: 23 Apr 2026

    The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329.

    Published: 31 Mar 2008
    7.2
    High

    CVE-2008-1601

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the reboot program on IBM AIX 5.2 and 5.3 allows local users in the shutdown group to gain privileges.

    Published: 31 Mar 2008