CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-1368

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted into an authenticated FTP connection established earlier in the same browser session, as demonstrated using a DELE command, a variant or possibly a regression of CVE-2004-1166. NOTE: a trailing "//" can force Internet Explorer to try to reuse an existing authenticated connection.

    Published: 18 Mar 2008
    10
    Critical

    CVE-2008-0947

    Last Modified: 23 Apr 2026

    Buffer overflow in the RPC library used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.4 through 1.6.3 allows remote attackers to execute arbitrary code by triggering a large number of open file descriptors.

    Published: 18 Mar 2008
    9.8
    Critical

    CVE-2008-0062

    Last Modified: 23 Apr 2026

    KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.

    Published: 18 Mar 2008
    7.5
    High

    CVE-2008-0063

    Last Modified: 23 Apr 2026

    The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

    Published: 18 Mar 2008
    5.8
    Medium

    CVE-2008-0992

    Last Modified: 23 Apr 2026

    Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value.

    Published: 18 Mar 2008
    4.3
    Medium

    CVE-2008-1372

    Last Modified: 23 Apr 2026

    bzlib.c in bzip2 before 1.0.5 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted file that triggers a buffer over-read, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

    Published: 18 Mar 2008
    5
    Medium

    CVE-2008-1366

    Last Modified: 23 Apr 2026

    Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to cause a denial of service (process consumption) via (1) an HTTP request without a Content-Length header or (2) invalid characters in unspecified CGI arguments, which triggers a NULL pointer dereference.

    Published: 17 Mar 2008
    6.4
    Medium

    CVE-2008-1365

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long encrypted password, which triggers the overflow in (1) cgiChkMasterPwd.exe, (2) policyserver.exe as reachable through cgiABLogon.exe, and other vectors.

    Published: 17 Mar 2008
    6.5
    Medium

    CVE-2008-1358

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.

    Published: 17 Mar 2008
    5.4
    Medium

    CVE-2008-1357

    Last Modified: 23 Apr 2026

    Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1355

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Jeebles Technology Jeebles Directory 2.9.60 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1359

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 before 2008-03-13 allows remote attackers to inject arbitrary web script or HTML via nested BBCodes, a different vector than CVE-2008-0913.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1360

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Nagios before 2.11 allows remote attackers to inject arbitrary web script or HTML via unknown vectors to unspecified CGI scripts, a different issue than CVE-2007-5624.

    Published: 17 Mar 2008
    6.3
    Medium

    CVE-2008-1356

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in xscreensaver in Sun Solaris 10 Java Desktop System (JDS), when using the GNOME On-Screen Keyboard (GOK), allows local users to bypass authentication via unknown vectors that cause the screen saver to crash.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1354

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MyIssuesView.asp in Advanced Data Solutions Virtual Support Office-XP (VSO-XP) allows remote attackers to execute arbitrary SQL commands via the Issue_ID parameter.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1353

    Last Modified: 23 Apr 2026

    zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1349

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1346

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter in a category action.

    Published: 17 Mar 2008
    4.9
    Medium

    CVE-2008-1343

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in (1) pkgadd and (2) pkgrm in SCO UnixWare 7.1.4 allows local users to gain privileges via unknown vectors.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1342

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) lucene_index_field_value parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1348

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in the eWebsite eWeather (Weather) module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the chart parameter to modules.php.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1347

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO or (2) the q parameter in an about action to the help system.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1350

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary SQL commands via the k parameter in an article action.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1351

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL commands via the tid parameter to printpage.php, which is accessible directly or through a printpage action to index.php.

    Published: 17 Mar 2008
    5
    Medium

    CVE-2008-1352

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in search.php in EdiorCMS (ecms) 3.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the _SearchTemplate parameter during a Title search.

    Published: 17 Mar 2008
    4.3
    Medium

    CVE-2008-1345

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and earlier allows remote attackers to inject arbitrary web script or HTML via the day parameter in a dayview action.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1344

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyioSoft EasyCalendar 4.0tr and earlier allow remote attackers to execute arbitrary SQL commands via the (1) year parameter in a dayview action to plugins/calendar/calendar_backend.php and the (2) page parameter to ajaxp_backend.php.

    Published: 17 Mar 2008
    7.5
    High

    CVE-2008-1341

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in SearchResults.aspx in LaGarde StoreFront 6 before SP8 allows remote attackers to execute arbitrary SQL commands via the CategoryId parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Mar 2008
    9.3
    Critical

    CVE-2008-0888

    Last Modified: 26 Aug 2025

    The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a free of uninitialized or previously-freed data.

    Published: 17 Mar 2008
    10
    Critical

    CVE-2008-0532

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument located immediately after the Logout argument, and possibly unspecified other vectors.

    Published: 14 Mar 2008
    7.5
    High

    CVE-2008-1118

    Last Modified: 23 Apr 2026

    Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.

    Published: 14 Mar 2008
    10
    Critical

    CVE-2008-1157

    Last Modified: 23 Apr 2026

    Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands.

    Published: 14 Mar 2008
    4.3
    Medium

    CVE-2008-0533

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary web script or HTML via an argument located immediately after the Help argument, and possibly unspecified other vectors.

    Published: 14 Mar 2008
    10
    Critical

    CVE-2008-1117

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.

    Published: 14 Mar 2008
    5
    Medium

    CVE-2008-1337

    Last Modified: 23 Apr 2026

    The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message.

    Published: 14 Mar 2008
    7.8
    High

    CVE-2008-1338

    Last Modified: 23 Apr 2026

    The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of service (daemon crash) via a server-DiffFile command with an integer value within a certain range, which causes a loop until all memory is exhausted.

    Published: 14 Mar 2008
    9.3
    Critical

    CVE-2008-1335

    Last Modified: 23 Apr 2026

    The ipsec4_get_ulp function in the kernel in NetBSD 2.0 through 3.1 and NetBSD-current before 20071028, when the fast_ipsec subsystem is enabled, allows remote attackers to bypass the IPsec policy by sending packets from a source machine with a different endianness than the destination machine, a different vulnerability than CVE-2006-0905.

    Published: 13 Mar 2008
    4.3
    Medium

    CVE-2007-6708

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to perform actions as administrators via an arbitrary valid request to an administrative URI, as demonstrated by (1) a Restore Factory Defaults action using the mtenRestore parameter to setup.cgi and (2) creation of a user account using the sysname parameter to setup.cgi.

    Published: 13 Mar 2008
    4.3
    Medium

    CVE-2007-6707

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2007-3574.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2007-6709

    Last Modified: 23 Apr 2026

    The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, which makes it easier for remote attackers to obtain access.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2008-1334

    Last Modified: 23 Apr 2026

    cgi/b on the BT Home Hub router allows remote attackers to bypass authentication, and read or modify administrative settings or make arbitrary VoIP telephone calls, by placing a character at the end of the PATH_INFO, as demonstrated by (1) %5C (encoded backslash), (2) '%' (percent), and (3) '~' (tilde). NOTE: the '/' (slash) vector is already covered by CVE-2007-5383.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2008-1336

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Koobi CMS 4.2.3 through 4.3.0 allows remote attackers to execute arbitrary SQL commands via the categ parameter in a links action to index.php, a different vector than CVE-2008-1122.

    Published: 13 Mar 2008
    5
    Medium

    CVE-2008-1321

    Last Modified: 23 Apr 2026

    The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote attackers to cause a denial of service (service termination) via the exit command to TCP port 6162, or have other impacts via other commands.

    Published: 13 Mar 2008
    9.3
    Critical

    CVE-2008-1319

    Last Modified: 23 Apr 2026

    Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 and earlier, as used in Borland CaliberRM and probably other products, allows remote attackers to execute arbitrary commands via a request to TCP port 5019 with a modified VERSANT_ROOT field.

    Published: 13 Mar 2008
    7.8
    High

    CVE-2008-1322

    Last Modified: 23 Apr 2026

    The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a denial of service (CPU consumption) or overwrite arbitrary files via a query string that specifies the -b option, probably due to an argument injection vulnerability.

    Published: 13 Mar 2008
    5
    Medium

    CVE-2008-1318

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in MediaWiki 1.11 before 1.11.2 allows remote attackers to obtain sensitive "cross-site" information via the callback parameter in an API call for JavaScript Object Notation (JSON) formatted results.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2008-1324

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Travelsized CMS 0.4.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1325.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2008-1325

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Uberghey CMS 0.3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) page_id and (2) language parameters. NOTE: this might be the same issue as CVE-2008-1324.

    Published: 13 Mar 2008
    4.3
    Medium

    CVE-2008-1326

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web script or HTML via the query parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Mar 2008
    7.5
    High

    CVE-2008-1327

    Last Modified: 23 Apr 2026

    Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and edit tasks via a direct request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Mar 2008