CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1234

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."

    Published: 25 Mar 2008
    9.3
    Critical

    CVE-2008-1235

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to execute arbitrary code via unknown vectors that cause JavaScript to execute with the wrong principal, aka "Privilege escalation via incorrect principals."

    Published: 25 Mar 2008
    6.8
    Medium

    CVE-2008-1236

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the layout engine.

    Published: 25 Mar 2008
    5
    Medium

    CVE-2009-4881

    Last Modified: 11 Apr 2025

    Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n string, a related issue to CVE-2008-1391.

    Published: 25 Mar 2008
    9.8
    Critical

    CVE-2008-1160

    Last Modified: 23 Apr 2026

    ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.

    Published: 25 Mar 2008
    6.8
    Medium

    CVE-2008-1237

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the JavaScript engine.

    Published: 25 Mar 2008
    5
    Medium

    CVE-2008-1238

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9, when generating the HTTP Referer header, does not list the entire URL when it contains Basic Authentication credentials without a username, which makes it easier for remote attackers to bypass application protection mechanisms that rely on Referer headers, such as with some Cross-Site Request Forgery (CSRF) mechanisms.

    Published: 25 Mar 2008
    4.3
    Medium

    CVE-2008-1241

    Last Modified: 23 Apr 2026

    GUI overlay vulnerability in Mozilla Firefox before 2.0.0.13 and SeaMonkey before 1.1.9 allows remote attackers to spoof form elements and redirect user inputs via a borderless XUL pop-up window from a background tab.

    Published: 25 Mar 2008
    7.5
    High

    CVE-2008-1391

    Last Modified: 23 Apr 2026

    Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.

    Published: 25 Mar 2008
    6.8
    Medium

    CVE-2008-1489

    Last Modified: 23 Apr 2026

    Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a different vulnerability than CVE-2008-0984.

    Published: 25 Mar 2008
    3.5
    Low

    CVE-2008-1484

    Last Modified: 23 Apr 2026

    The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1485

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in PunBB 1.2.16 and earlier allows remote attackers to inject arbitrary web script or HTML via the get_host parameter to moderate.php.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1486

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Phorum before 5.2.6, when mysql_use_ft is disabled, allows remote attackers to execute arbitrary SQL commands via the non-fulltext search.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1487

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) functions/other.php, (4) include/left_menu.class.php, and (5) plugins/stats/stats_view.php.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1488

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename.

    Published: 24 Mar 2008
    10
    Critical

    CVE-2007-6711

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges via unknown vectors.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-0125

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir parameter.

    Published: 24 Mar 2008
    9.3
    Critical

    CVE-2008-0951

    Last Modified: 23 Apr 2026

    Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1470

    Last Modified: 23 Apr 2026

    Incomplete blacklist vulnerability in IISWebAgentIF.dll in the WebID RSA Authentication Agent 5.3, and possibly earlier, allows remote attackers to conduct cross-site scripting (XSS) attacks via the postdata parameter, due to an incomplete fix for CVE-2005-1118.

    Published: 24 Mar 2008
    9.3
    Critical

    CVE-2008-1472

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

    Published: 24 Mar 2008
    7.2
    High

    CVE-2008-1473

    Last Modified: 23 Apr 2026

    The Altiris Client Service (AClient.exe) in Symantec Altiris Deployment Solution 6.8.x before 6.9.164 allows local users to gain privileges via a "Shatter" style attack.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1480

    Last Modified: 23 Apr 2026

    rpc.metad in Sun Solaris 10 allows remote attackers to cause a denial of service (daemon crash) via a malformed RPC request.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-0073

    Last Modified: 23 Apr 2026

    Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parameter.

    Published: 24 Mar 2008
    5
    Medium

    CVE-2008-1478

    Last Modified: 23 Apr 2026

    Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode connection, then closing the original FTP connection. NOTE: some of these details are obtained from third party information.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1479

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in cyberfrogs.net cfnetgs 0.24 allows remote attackers to inject arbitrary web script or HTML via the directory parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2008
    7.2
    High

    CVE-2008-1471

    Last Modified: 23 Apr 2026

    The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-bounds write of kernel memory.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1476

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to received trackbacks.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1477

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in busca.php in eForum 0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) busca and (2) link parameters.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1481

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.1.2 allows remote attackers to inject arbitrary web script or HTML via the board parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1482

    Last Modified: 23 Apr 2026

    Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1474

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Roundup before 1.4.4 have unknown impact and attack vectors, some of which may be related to cross-site scripting (XSS).

    Published: 24 Mar 2008
    6.4
    Medium

    CVE-2008-1475

    Last Modified: 23 Apr 2026

    The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1462

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle action.

    Published: 24 Mar 2008
    7.5
    High

    CVE-2008-1464

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Gallarific Free Edition 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) query parameter to (a) search.php; (2) gusername and (3) gpassword parameters to (b) login.php; and the (4) username and (5) password parameters to (c) gadmin/index.php in a signin action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2008
    7.5
    High

    CVE-2008-1466

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in W-Agora 4.0 allow remote attackers to execute arbitrary PHP code via a URL in the bn_dir_default parameter to (1) add_user.php, (2) create_forum.php, (3) create_user.php, (4) delete_notes.php, (5) delete_user.php, (6) edit_forum.php, (7) mail_users.php, (8) moderate_notes.php, and (9) reorder_forums.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1468

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input, related to failure to set the charset, a different vector than CVE-2004-1318 and CVE-2001-1350. NOTE: some of these details are obtained from third party information.

    Published: 24 Mar 2008
    6.4
    Medium

    CVE-2008-1469

    Last Modified: 23 Apr 2026

    Gallarific Free Edition 1.1 does not require authentication for (1) photos.php, (2) comments.php, and (3) gallery.php in gadmin/, which allows remote attackers to edit objects via a direct request, different vectors than CVE-2008-1327. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1463

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of an alert page.

    Published: 24 Mar 2008
    9.3
    Critical

    CVE-2008-1465

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Detodas Restaurante (com_restaurante) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php, a different product than CVE-2008-0562.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1467

    Last Modified: 23 Apr 2026

    CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "received URLs in the message window." NOTE: this issue has been disputed due to the user-assisted nature, since the URL must be selected and launched by the victim

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1458

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in CS-Cart 1.3.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter in a products search action. NOTE: it was also reported that 1.3.5-SP2 trial edition is also affected.

    Published: 24 Mar 2008
    7.5
    High

    CVE-2008-1459

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 24 Mar 2008
    7.5
    High

    CVE-2008-1460

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 24 Mar 2008
    7.6
    High

    CVE-2008-1461

    Last Modified: 23 Apr 2026

    Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. NOTE: it is unclear whether there are common handler configurations in which this argument is controlled by an attacker.

    Published: 24 Mar 2008
    6.8
    Medium

    CVE-2008-1201

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in FLA file parsing in Adobe Flash CS3 Professional, Flash Professional 8, and Flash Basic 8 on Windows allow user-assisted remote attackers to execute arbitrary code via a crafted .FLA file.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1290

    Last Modified: 23 Apr 2026

    ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

    Published: 24 Mar 2008
    7.5
    High

    CVE-2008-1289

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and s800i 1.1.x before 1.1.0.2 allow remote attackers to (1) write a zero to an arbitrary memory location via a large RTP payload number, related to the ast_rtp_unset_m_type function in main/rtp.c; or (2) write certain integers to an arbitrary memory location via a large number of RTP payloads, related to the process_sdp function in channels/chan_sip.c.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1292

    Last Modified: 23 Apr 2026

    ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

    Published: 24 Mar 2008
    4.3
    Medium

    CVE-2008-1291

    Last Modified: 23 Apr 2026

    ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.

    Published: 24 Mar 2008
    9.3
    Critical

    CVE-2008-1390

    Last Modified: 23 Apr 2026

    The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

    Published: 24 Mar 2008