CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2008-1599

    Last Modified: 23 Apr 2026

    The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat.

    Published: 31 Mar 2008
    4.9
    Medium

    CVE-2008-0211

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BIOS F.04 through F.11 for the HP Compaq Business Notebook PC allows local users to cause a denial of service via unspecified vectors.

    Published: 31 Mar 2008
    4.7
    Medium

    CVE-2008-1598

    Last Modified: 23 Apr 2026

    The kernel in IBM AIX 6.1 allows local users with ProbeVue privileges to read arbitrary kernel memory and obtain sensitive information via unspecified vectors.

    Published: 31 Mar 2008
    7.2
    High

    CVE-2008-0706

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BIOS F.26 and earlier for the HP Compaq Notebook PC allows physically proximate attackers to obtain privileged access via unspecified vectors, possibly involving an authentication bypass of the power-on password.

    Published: 31 Mar 2008
    4.9
    Medium

    CVE-2008-1597

    Last Modified: 23 Apr 2026

    The WPAR system call implementation in the kernel in IBM AIX 6.1 allows local users to cause a denial of service via unknown calls that trigger "undefined behavior."

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1560

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.asp.

    Published: 31 Mar 2008
    5.5
    Medium

    CVE-2008-1567

    Last Modified: 23 Apr 2026

    phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.

    Published: 31 Mar 2008
    3.3
    Low

    CVE-2008-1569

    Last Modified: 23 Apr 2026

    policyd-weight 0.1.14 beta-16 and earlier allows local users to modify or delete arbitrary files via a symlink attack on temporary files that are used when creating a socket.

    Published: 31 Mar 2008
    6.9
    Medium

    CVE-2008-1570

    Last Modified: 23 Apr 2026

    Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating the LOCKPATH directory, then modifying it after the symbolic link check occurs. NOTE: this is due to an incomplete fix for CVE-2008-1569.

    Published: 31 Mar 2008
    7.5
    High

    CVE-2008-1565

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the phpEx parameter.

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1564

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Dan Costin File Transfer before 1.2f allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) in the filename.

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1566

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Search.do in ManageEngine Applications Manager 8.x allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Mar 2008
    4.6
    Medium

    CVE-2008-0070

    Last Modified: 23 Apr 2026

    Integer overflow in Orb Networks Orb 2.00.1014 and Winamp Remote BETA allows remote attackers to execute arbitrary code via an RPC request that specifies a large number of array dimensions, which triggers a heap-based buffer overflow.

    Published: 31 Mar 2008
    7.5
    High

    CVE-2008-1551

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1553

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in mod.php in TopperMod 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the to parameter.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1554

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a non-alphanumeric first character the localita parameter, which bypasses a protection mechanism.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1555

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _bFileToInclude parameter.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1559

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1549

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to execute arbitrary SQL commands via the (1) GrdBk parameter to GradebookOptions.asp and the (2) SchlCode variable to loginproc.asp, a different vector than CVE-2008-0942.

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1556

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1 allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter to (a) system/actionspages/_b/contentFiles/gBImageViewer.php, (2) ForEditor parameter to (b) system/actionspages/_b/contentFiles/gBselectorContents.php, (3) the PATH_INFO to (c) gBLoginPage.php and (d) gBPassword.php in system/actionspages/_b/contentFiles/, (4) formlogin parameter to system/actionspages/_b/contentFiles/gBLoginPage.php, and the (5) bolini_searchengine46Search parameter to (e) help/index.php.

    Published: 31 Mar 2008
    5
    Medium

    CVE-2008-1557

    Last Modified: 23 Apr 2026

    BolinOS 4.6.1 allows remote attackers to obtain sensitive information via a direct request to system/actionspages/_b/contentFiles/gBphpInfo.php, which calls the phpinfo function.

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1550

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in CubeCart 4.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the _a parameter in a searchStr action and the (2) Submit parameter.

    Published: 31 Mar 2008
    10
    Critical

    CVE-2008-1558

    Last Modified: 23 Apr 2026

    Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. NOTE: this issue has been referred to as an integer overflow.

    Published: 31 Mar 2008
    4.3
    Medium

    CVE-2008-1548

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Aeries Browser Interface (ABI) 3.8.3.14 in Eagle Software Aries Student Information System allow remote attackers to inject arbitrary web script or HTML via the (1) UserName parameter to loginproc.asp and the (2) usr parameter to Login.asp.

    Published: 31 Mar 2008
    4.1
    Medium

    CVE-2008-1628

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the audit_log_user_command function in lib/audit_logging.c in Linux Audit before 1.7 might allow remote attackers to execute arbitrary code via a long command argument. NOTE: some of these details are obtained from third party information.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1637

    Last Modified: 23 Apr 2026

    PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.

    Published: 31 Mar 2008
    6.5
    Medium

    CVE-2008-1657

    Last Modified: 23 Apr 2026

    OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

    Published: 31 Mar 2008
    6.8
    Medium

    CVE-2008-1685

    Last Modified: 23 Apr 2026

    gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of length testing code that was intended as a protection mechanism against integer overflow and buffer overflow attacks, and provide no diagnostic message about this removal. NOTE: the vendor has determined that this compiler behavior is correct according to section 6.5.6 of the C99 standard (aka ISO/IEC 9899:1999)

    Published: 30 Mar 2008
    6.8
    Medium

    CVE-2008-1679

    Last Modified: 23 Apr 2026

    Multiple integer overflows in imageop.c in Python before 2.5.3 allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted images that trigger heap-based buffer overflows. NOTE: this issue is due to an incomplete fix for CVE-2007-4965.

    Published: 29 Mar 2008
    4.3
    Medium

    CVE-2008-1545

    Last Modified: 23 Apr 2026

    The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

    Published: 28 Mar 2008
    7.8
    High

    CVE-2008-1546

    Last Modified: 23 Apr 2026

    servlet/MIMEReceiveServlet in the web controller for Mitsubishi Electric GB-50 and GB-50A air-conditioning control systems allows remote attackers to cause a denial of service (air-conditioning outage) via an XML document containing a setRequest command.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1543

    Last Modified: 23 Apr 2026

    The Advanced User Interface Pages in the ProST Web Management component on the Airspan WiMAX ProST have a certain default User ID and password, which makes it easier for remote attackers to obtain partial administrative access, a different vulnerability than CVE-2008-1262.

    Published: 28 Mar 2008
    7.1
    High

    CVE-2008-1544

    Last Modified: 23 Apr 2026

    The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to (1) conduct HTTP request splitting and HTTP request smuggling attacks via an incorrect Content-Length header, (2) access arbitrary virtual hosts via a modified Host header, (3) bypass referrer restrictions via an incorrect Referer header, and (4) bypass the same-origin policy and obtain sensitive information via a crafted request header.

    Published: 28 Mar 2008
    10
    Critical

    CVE-2008-0704

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SSH server in HP OpenVMS TCP/IP Services on OpenVMS on the Alpha platform with 5.4 before ECO 7, and on the Integrity and Alpha platforms with 5.5 before ECO 3 and 5.6 before ECO 2, allows remote attackers to obtain unspecified access via unknown vectors.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1542

    Last Modified: 23 Apr 2026

    Airspan Base Station Distribution Unit (BSDU) has "topsecret" as its password for the root account, which allows remote attackers to obtain administrative access via a telnet login, a different vulnerability than CVE-2008-1262.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-0926

    Last Modified: 23 Apr 2026

    The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of service (daemon shutdown) or read arbitrary files. NOTE: it was later reported that 8.7.3.10 (aka 8.7.3 SP10) is also affected.

    Published: 28 Mar 2008
    4.3
    Medium

    CVE-2008-1536

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pictures Pro (aka Tim Grissett) Photo Cart 4.1 allows remote attackers to inject arbitrary web script or HTML via the amessage parameter. NOTE: some of these details are obtained from third party information.

    Published: 28 Mar 2008
    6.8
    Medium

    CVE-2008-1537

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

    Published: 28 Mar 2008
    4.3
    Medium

    CVE-2008-1538

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in searchAction.do in ManageEngine EventLog Analyzer 5 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. Fixed in EventLog Analyzer 10.0 Build 10000.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1539

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1540

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Datsogallery (com_datsogallery) 1.3.1 module for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1534

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) settings[footer] parameter to footer.inc.php and the (2) settings[header] parameter to header.inc.php.

    Published: 28 Mar 2008
    4.3
    Medium

    CVE-2008-1541

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter.

    Published: 28 Mar 2008
    6.8
    Medium

    CVE-2008-0924

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.

    Published: 28 Mar 2008
    7.5
    High

    CVE-2008-1535

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the op_id parameter in a view action to index.php.

    Published: 28 Mar 2008
    5
    Medium

    CVE-2008-1240

    Last Modified: 23 Apr 2026

    LiveConnect in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 does not properly parse the content origin for jar: URIs before sending them to the Java plugin, which allows remote attackers to access arbitrary ports on the local machine. NOTE: this is closely related to CVE-2008-1195.

    Published: 28 Mar 2008
    4.9
    Medium

    CVE-2008-5713

    Last Modified: 23 Apr 2026

    The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.

    Published: 28 Mar 2008
    5
    Medium

    CVE-2008-1532

    Last Modified: 23 Apr 2026

    Perlbal before 1.70, when buffered upload is enabled, allows remote attackers to cause a denial of service (crash) via a zero-byte chunked upload.

    Published: 28 Mar 2008
    5
    Medium

    CVE-2008-1561

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to cause a denial of service (application crash) via a malformed packet to the (1) X.509sat or (2) Roofnet dissectors. NOTE: Vector 2 might also lead to a hang.

    Published: 28 Mar 2008
    5
    Medium

    CVE-2008-1562

    Last Modified: 23 Apr 2026

    The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740.

    Published: 28 Mar 2008