CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1612

    Last Modified: 23 Apr 2026

    The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.

    Published: 22 Mar 2008
    4.6
    Medium

    CVE-2008-1658

    Last Modified: 23 Apr 2026

    Format string vulnerability in the grant helper (polkit-grant-helper.c) in PolicyKit 0.7 and earlier allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in a password.

    Published: 22 Mar 2008
    6.8
    Medium

    CVE-2008-2276

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.

    Published: 22 Mar 2008
    4.3
    Medium

    CVE-2008-1428

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Ubercart 5.x before 5.x-1.0-beta7 module for Drupal allow remote attackers to inject arbitrary web script or HTML via a text attribute value for a product.

    Published: 20 Mar 2008
    7.8
    High

    CVE-2008-1429

    Last Modified: 23 Apr 2026

    Secure Internet Live Conferencing (SILC) Server before 1.1.1 allows remote attackers to cause a denial of service (daemon crash) via a NEW_CLIENT packet without a nickname.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1430

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1427

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joobi Acajoom (com_acajoom) 1.1.5 and 1.2.5 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the mailingid parameter in a mailing view action to index.php.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1432

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine SupportCenter Plus 7.0.0 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, a related issue to CVE-2008-1299. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1425

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a kate action.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1426

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

    Published: 20 Mar 2008
    2.1
    Low

    CVE-2008-1431

    Last Modified: 23 Apr 2026

    RaidSonic NAS-4220-B with 2.6.0-n(2007-10-11) firmware stores a partition encryption key in an unencrypted /system/.crypt file with base64 encoding, which allows local users to obtain the key.

    Published: 20 Mar 2008
    6.9
    Medium

    CVE-2008-1417

    Last Modified: 23 Apr 2026

    The prerm script in axyl 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the axyl.conf temporary file.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1012

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple AirPort Extreme Base Station Firmware 7.3.1 allows remote attackers to cause a denial of service (file sharing hang) via a crafted AFP request, related to "input validation."

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1398

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1399

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Clansphere 2008 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1403

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the TFTP server in BootManage TFTPD 1.99 and earlier in BootManage Administrator 7.1 and earlier allows remote attackers to execute arbitrary code via a request with a long filename.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1404

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1405

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1406

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn action.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1407

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1408

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/functions/banners-external.php in phpBP 2 RC3 (2.204) FIX 4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a banner_out action.

    Published: 20 Mar 2008
    5
    Medium

    CVE-2008-1411

    Last Modified: 23 Apr 2026

    The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of service (crash) via an incomplete TFTP request, which triggers a NULL pointer dereference.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1414

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4) smartlinks.php, and (5) todo.php, as demonstrated using a META tag.

    Published: 20 Mar 2008
    5
    Medium

    CVE-2008-1415

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to read arbitrary files via "../..//" (modified dot dot) sequences in the tab parameter.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1416

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/.

    Published: 20 Mar 2008
    7.1
    High

    CVE-2008-1402

    Last Modified: 23 Apr 2026

    MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine).

    Published: 20 Mar 2008
    5
    Medium

    CVE-2008-1400

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot slash) in the URI.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1401

    Last Modified: 23 Apr 2026

    Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to execute arbitrary code via format string specifiers in the URI, which is recorded in a log file.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1409

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1410

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to read arbitrary files via directory traversal sequences to the TFTP service.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1412

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1413

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in SNewsCMS Rus 2.1 through 2.4 allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Published: 20 Mar 2008
    5.8
    Medium

    CVE-2008-1333

    Last Modified: 23 Apr 2026

    Format string vulnerability in Asterisk Open Source 1.6.x before 1.6.0-beta6 might allow remote attackers to execute arbitrary code via logging messages that are not properly handled by (1) the ast_verbose logging API call, or (2) the astman_append function.

    Published: 20 Mar 2008
    7.8
    High

    CVE-2008-1364

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service.

    Published: 20 Mar 2008
    10
    Critical

    CVE-2008-1392

    Last Modified: 23 Apr 2026

    The default configuration of VMware Workstation 6.0.2, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 makes the console of the guest OS accessible through anonymous VIX API calls, which has unknown impact and attack vectors.

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1395

    Last Modified: 23 Apr 2026

    Plone CMS does not record users' authentication states, and implements the logout feature solely on the client side, which makes it easier for context-dependent attackers to reuse a logged-out session.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-1396

    Last Modified: 23 Apr 2026

    Plone CMS 3.x uses invariant data (a client username and a server secret) when calculating an HMAC-SHA1 value for an authentication cookie, which makes it easier for remote attackers to gain permanent access to an account by sniffing the network.

    Published: 20 Mar 2008
    9.3
    Critical

    CVE-2007-6254

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before CHF74 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2008-0164

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in Plone CMS 3.0.5 and 3.0.6 allow remote attackers to (1) add arbitrary accounts via the join_form page and (2) change the privileges of arbitrary groups via the prefs_groups_overview page.

    Published: 20 Mar 2008
    4.3
    Medium

    CVE-2007-4592

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface for IBM Rational ClearQuest before 2003.06.16 Patch 2008A, 7.0.0.2_iFix01, and 7.0.1.1_iFix01 allow remote attackers to inject arbitrary web script or HTML via the (1) contextid, (2) username, (3) userNameVal, and (4) schema parameters to the login component.

    Published: 20 Mar 2008
    7.2
    High

    CVE-2008-0707

    Last Modified: 23 Apr 2026

    HP StorageWorks Library and Tape Tools (LTT) before 4.5 SR1 on HP-UX B.11.11 and B.11.23 allows local users to gain privileges via unspecified vectors.

    Published: 20 Mar 2008
    8.8
    High

    CVE-2008-1332

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2.5.1, and C.x.x before C.1.6.2; AsteriskNOW 1.0.x before 1.0.2; Appliance Developer Kit before 1.4 revision 109393; and s800i 1.0.x before 1.1.0.2; allows remote attackers to access the SIP channel driver via a crafted From header.

    Published: 20 Mar 2008
    7.1
    High

    CVE-2008-1340

    Last Modified: 23 Apr 2026

    Virtual Machine Communication Interface (VMCI) in VMware Workstation 6.0.x before 6.0.3, VMware Player 2.0.x before 2.0.3, and VMware ACE 2.0.x before 2.0.1 allows attackers to cause a denial of service (host OS crash) via crafted VMCI calls that trigger "memory exhaustion and memory corruption."

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1361

    Last Modified: 23 Apr 2026

    VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation that causes the authd process to connect to an arbitrary named pipe, a different vulnerability than CVE-2008-1362.

    Published: 20 Mar 2008
    7.2
    High

    CVE-2008-1363

    Last Modified: 23 Apr 2026

    VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges via an unspecified manipulation of a config.ini file located in an Application Data folder, which can be used for "hijacking the VMX process."

    Published: 20 Mar 2008
    7.5
    High

    CVE-2008-1394

    Last Modified: 23 Apr 2026

    Plone CMS before 3 places a base64 encoded form of the username and password in the __ac cookie for all user accounts, which makes it easier for remote attackers to obtain access by sniffing the network.

    Published: 20 Mar 2008
    6.8
    Medium

    CVE-2008-1552

    Last Modified: 23 Apr 2026

    The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.

    Published: 20 Mar 2008
    7.2
    High

    CVE-2008-1362

    Last Modified: 23 Apr 2026

    VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 and 1.0.x before 1.0.5, and VMware Server 1.0.x before 1.0.5 on Windows allow local users to gain privileges or cause a denial of service by impersonating the authd process through an unspecified use of an "insecurely created named pipe," a different vulnerability than CVE-2008-1361.

    Published: 20 Mar 2008
    10
    Critical

    CVE-2008-1393

    Last Modified: 23 Apr 2026

    Plone CMS 3.0.5, and probably other 3.x versions, places a base64 encoded form of the username and password in the __ac cookie for the admin account, which makes it easier for remote attackers to obtain administrative privileges by sniffing the network.

    Published: 20 Mar 2008
    6.5
    Medium

    CVE-2008-1397

    Last Modified: 23 Apr 2026

    Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.

    Published: 20 Mar 2008