CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1563

    Last Modified: 23 Apr 2026

    The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 28 Mar 2008
    6.8
    Medium

    CVE-2008-1026

    Last Modified: 23 Apr 2026

    Integer overflow in the PCRE regular expression compiler (JavaScriptCore/pcre/pcre_compile.cpp) in Apple WebKit, as used in Safari before 3.1.1, allows remote attackers to execute arbitrary code via a regular expression with large, nested repetition counts, which triggers a heap-based buffer overflow.

    Published: 28 Mar 2008
    6.8
    Medium

    CVE-2008-1533

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the XML-RPC Blogger API plugin in Joomla! 1.5 allows remote attackers to perform unauthorized article operations on articles via unknown vectors.

    Published: 28 Mar 2008
    9.3
    Critical

    CVE-2008-1530

    Last Modified: 23 Apr 2026

    GnuPG (gpg) 1.4.8 and 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted duplicate keys that are imported from key servers, which triggers "memory corruption around deduplication of user IDs."

    Published: 27 Mar 2008
    4.3
    Medium

    CVE-2008-1531

    Last Modified: 23 Apr 2026

    The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be lost.

    Published: 27 Mar 2008
    7.1
    High

    CVE-2008-1150

    Last Modified: 23 Apr 2026

    The virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (resource exhaustion) via a series of PPTP sessions, related to the persistence of interface descriptor block (IDB) data structures after process termination, aka bug ID CSCdv59309.

    Published: 27 Mar 2008
    7.8
    High

    CVE-2008-1152

    Last Modified: 23 Apr 2026

    The data-link switching (DLSw) component in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device restart or memory consumption) via crafted (1) UDP port 2067 or (2) IP protocol 91 packets.

    Published: 27 Mar 2008
    7.1
    High

    CVE-2008-1151

    Last Modified: 23 Apr 2026

    Memory leak in the virtual private dial-up network (VPDN) component in Cisco IOS before 12.3 allows remote attackers to cause a denial of service (memory consumption) via a series of PPTP sessions, related to "dead memory" that remains allocated after process termination, aka bug ID CSCsj58566.

    Published: 27 Mar 2008
    5
    Medium

    CVE-2008-1384

    Last Modified: 23 Apr 2026

    Integer overflow in PHP 5.2.5 and earlier allows context-dependent attackers to cause a denial of service and possibly have unspecified other impact via a printf format parameter with a large width specifier, related to the php_sprintf_appendstring function in formatted_print.c and probably other functions for formatted strings (aka *printf functions).

    Published: 27 Mar 2008
    7.1
    High

    CVE-2008-0537

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Supervisor Engine 32 (Sup32), Supervisor Engine 720 (Sup720), and Route Switch Processor 720 (RSP720) for multiple Cisco products, when using Multi Protocol Label Switching (MPLS) VPN and OSPF sham-link, allows remote attackers to cause a denial of service (blocked queue, device restart, or memory leak) via unknown vectors.

    Published: 27 Mar 2008
    5.1
    Medium

    CVE-2008-1156

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast states on the core routers" via a crafted Multicast Distribution Tree (MDT) Data Join message.

    Published: 27 Mar 2008
    7.1
    High

    CVE-2008-1153

    Last Modified: 23 Apr 2026

    Cisco IOS 12.1, 12.2, 12.3, and 12.4, with IPv4 UDP services and the IPv6 protocol enabled, allows remote attackers to cause a denial of service (device crash and possible blocked interface) via a crafted IPv6 packet to the device.

    Published: 27 Mar 2008
    10
    Critical

    CVE-2008-5184

    Last Modified: 23 Apr 2026

    The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

    Published: 27 Mar 2008
    6.9
    Medium

    CVE-2008-1692

    Last Modified: 23 Apr 2026

    Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users to hijack X11 connections. NOTE: realistic attack scenarios require that the victim enters a command on the wrong machine.

    Published: 27 Mar 2008
    5
    Medium

    CVE-2008-1523

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain ISP and Dynamic DNS credentials by sending a direct request for (1) WAN.html, (2) wzPPPOE.html, and (3) rpDyDNS.html, and then reading the HTML source.

    Published: 26 Mar 2008
    6.5
    Medium

    CVE-2008-1521

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to gain privileges by accessing administrative URIs, as demonstrated by rpSysAdmin.html.

    Published: 26 Mar 2008
    5
    Medium

    CVE-2008-1529

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers have a minimum password length for the admin account that is too small, which makes it easier for remote attackers to guess passwords via brute force methods.

    Published: 26 Mar 2008
    7.5
    High

    CVE-2008-1522

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), have (1) "user" as their default password for the "user" account and (2) "1234" as their default password for the "admin" account, which makes it easier for remote attackers to obtain access.

    Published: 26 Mar 2008
    7.5
    High

    CVE-2008-1524

    Last Modified: 23 Apr 2026

    The SNMP service on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has "public" as its default community for both (1) read and (2) write operations, which allows remote attackers to perform administrative actions via SNMP, as demonstrated by reading the Dynamic DNS service password or inserting an XSS sequence into the system.sysName.0 variable, which is displayed on the System Status page.

    Published: 26 Mar 2008
    7.5
    High

    CVE-2008-1526

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), do not use a salt when calculating an MD5 password hash, which makes it easier for attackers to crack passwords.

    Published: 26 Mar 2008
    7.5
    High

    CVE-2008-1527

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(PE9) and 3.40(AGD.2) through 3.40(AHQ.3), support authentication over HTTP via a hash string in the hiddenPassword field, which allows remote attackers to obtain access via a replay attack.

    Published: 26 Mar 2008
    4
    Medium

    CVE-2008-1528

    Last Modified: 23 Apr 2026

    ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain authentication data by making direct HTTP requests and then reading the HTML source, as demonstrated by a request for (1) RemMagSNMP.html, which discloses SNMP communities; or (2) WLAN.html, which discloses WEP keys.

    Published: 26 Mar 2008
    5
    Medium

    CVE-2008-1525

    Last Modified: 23 Apr 2026

    The default SNMP configuration on ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), has a Trusted Host value of 0.0.0.0, which allows remote attackers to send SNMP requests from any source IP address.

    Published: 26 Mar 2008
    7.1
    High

    CVE-2009-0778

    Last Modified: 23 Apr 2026

    The icmp_send function in net/ipv4/icmp.c in the Linux kernel before 2.6.25, when configured as a router with a REJECT route, does not properly manage the Protocol Independent Destination Cache (aka DST) in some situations involving transmission of an ICMP Host Unreachable message, which allows remote attackers to cause a denial of service (connectivity outage) by sending a large series of packets to many destination IP addresses within this REJECT route, related to an "rt_cache leak."

    Published: 26 Mar 2008
    4.3
    Medium

    CVE-2008-1510

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1512

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the phpEx parameter. NOTE: some of these details are obtained from third party information.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1508

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in EfesTech E-Kontör and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1509

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the query parameter.

    Published: 25 Mar 2008
    9.8
    Critical

    CVE-2008-1511

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PathToComment parameter for (1) classes/class_admin.php and (2) classes/class_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Mar 2008
    6.8
    Medium

    CVE-2008-1513

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.

    Published: 25 Mar 2008
    5
    Medium

    CVE-2008-1506

    Last Modified: 23 Apr 2026

    PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1507

    Last Modified: 23 Apr 2026

    PEEL, possibly 3.x and earlier, has (1) a default [email protected] account with password admin, and (2) a default [email protected] account with password cinema, which allows remote attackers to gain administrative access.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1492

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php and (2) install.php. NOTE: it was later reported that vector 1 is also present in 2.0.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1493

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1494

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/module/online.php in Easy-Clanpage 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a user details action, a different vector than CVE-2008-1425.

    Published: 25 Mar 2008
    6.5
    Medium

    CVE-2008-1495

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote authenticated administrators to upload and execute arbitrary PHP files via a modified content type in an ajout action, as demonstrated by (1) image/gif and (2) application/pdf.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1496

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

    Published: 25 Mar 2008
    5
    Medium

    CVE-2008-1501

    Last Modified: 23 Apr 2026

    The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and unspecified other ircu derivatives allows remote attackers to cause a denial of service (daemon crash) via a malformed MODE command.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1503

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a node object, or the (2) sysContact or (3) sysLocation SNMP configuration field, aka "Audit Log XSS." NOTE: these issues might be resultant from cross-site request forgery (CSRF) vulnerabilities.

    Published: 25 Mar 2008
    9.3
    Critical

    CVE-2008-1490

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659.

    Published: 25 Mar 2008
    9
    Critical

    CVE-2008-1498

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitrary code via a long first argument to the LIST command.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1500

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in TinyPortal 0.8.6 and 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the PHPSESSID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1504

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in setup.php3 in phpHeaven phpMyChat 0.14.5 allows remote attackers to inject arbitrary web script or HTML via the Lang parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Mar 2008
    10
    Critical

    CVE-2008-1491

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1499

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1502

    Last Modified: 23 Apr 2026

    The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks via a string containing crafted URL protocols.

    Published: 25 Mar 2008
    9
    Critical

    CVE-2008-1497

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1505

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php.

    Published: 25 Mar 2008
    9.3
    Critical

    CVE-2008-1092

    Last Modified: 23 Apr 2026

    Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. NOTE: as of 20080513, Microsoft has stated that this is the same issue as CVE-2007-6026.

    Published: 25 Mar 2008
    6.8
    Medium

    CVE-2008-1233

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via "XPCNativeWrapper pollution."

    Published: 25 Mar 2008