CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2007-6253

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Adobe Form Designer 5.0 and Form Client 5.0 allow remote attackers to execute arbitrary code via unknown vectors in the (1) Adobe File Dialog Button (FileDlg.dll) and the (2) Adobe Copy to Server Object (SvrCopy.dll) ActiveX controls.

    Published: 12 Mar 2008
    9.3
    Critical

    CVE-2008-0110

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0112

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3, and Office for Mac 2004 and 2008 allows user-assisted remote attackers to execute arbitrary code via a crafted .SLK file that is not properly handled when importing the file, aka "Excel File Import Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0118

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an "allocation error," aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0116

    Last Modified: 23 Apr 2026

    Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, Compatibility Pack, and Office 2004 and 2008 for Mac allows user-assisted remote attackers to execute arbitrary code via malformed tags in rich text, aka "Excel Rich Text Validation Vulnerability."

    Published: 11 Mar 2008
    6.8
    Medium

    CVE-2008-0300

    Last Modified: 23 Apr 2026

    mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in the factor parameter, which are not properly handled when accessing a filename that contains those sequences.

    Published: 11 Mar 2008
    7.5
    High

    CVE-2008-0301

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0307

    Last Modified: 23 Apr 2026

    Integer signedness error in vserver in SAP MaxDB 7.6.0.37, and possibly other versions, allows remote attackers to execute arbitrary code via unknown vectors that trigger heap corruption.

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2007-1201

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0114

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0111

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted data validation records, aka "Excel Data Validation Record Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0113

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microsoft Office Cell Parsing Memory Corruption Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0115

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2007, Viewer 2003, Compatibility Pack, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via malformed formulas, aka "Excel Formula Parsing Vulnerability."

    Published: 11 Mar 2008
    9.3
    Critical

    CVE-2008-0117

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."

    Published: 11 Mar 2008
    6.9
    Medium

    CVE-2008-0306

    Last Modified: 23 Apr 2026

    sdbstarter in SAP MaxDB 7.6.0.37, and possibly other versions, allows local users to execute arbitrary commands by using unspecified environment variables to modify configuration settings.

    Published: 11 Mar 2008
    7.8
    High

    CVE-2008-1286

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java Web Console 3.0.2, 3.0.3, and 3.0.4 allows remote attackers to bypass intended access restrictions and determine the existence of files or directories via unknown vectors.

    Published: 11 Mar 2008
    5
    Medium

    CVE-2008-1287

    Last Modified: 23 Apr 2026

    IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.

    Published: 11 Mar 2008
    5
    Medium

    CVE-2008-1288

    Last Modified: 23 Apr 2026

    IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 might allow local or remote attackers to obtain sensitive information about users by reading user cookies.

    Published: 11 Mar 2008
    6
    Medium

    CVE-2008-1284

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Horde 3.1.6, Groupware before 1.0.5, and Groupware Webmail Edition before 1.0.6, when running with certain configurations, allows remote authenticated users to read and execute arbitrary files via ".." sequences and a null byte in the theme name.

    Published: 11 Mar 2008
    4.3
    Medium

    CVE-2008-1283

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web script or HTML via the URI, which is not properly handled in the 404 error page.

    Published: 11 Mar 2008
    4.6
    Medium

    CVE-2008-0890

    Last Modified: 23 Apr 2026

    Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors.

    Published: 11 Mar 2008
    4.3
    Medium

    CVE-2008-1285

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 11 Mar 2008
    7.5
    High

    CVE-2008-4360

    Last Modified: 23 Apr 2026

    mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there is a configuration rule for .php files.

    Published: 11 Mar 2008
    7.5
    High

    CVE-2008-1272

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showad.php and the (2) ad parameter to pfriendly.php.

    Published: 10 Mar 2008
    6.9
    Medium

    CVE-2008-1274

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in man in IBM AIX 6.1.0 allows local users to execute arbitrary code via a malicious program in the man directory.

    Published: 10 Mar 2008
    7.8
    High

    CVE-2008-1275

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edition 3.x and earlier allow remote attackers to cause a denial of service (crash) via crafted (1) EXPN or (2) VRFY commands.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1279

    Last Modified: 23 Apr 2026

    Acronis True Image Group Server 1.5.19.191 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a packet with an invalid length field, which causes an out-of-bounds read.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1280

    Last Modified: 23 Apr 2026

    Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, which triggers a NULL pointer dereference.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1281

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in TFTPsrvs.exe 2.5.3.1 and earlier, as used in Argon Technology Client Management Services (CMS) 1.31 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1282

    Last Modified: 23 Apr 2026

    Buffer overflow in the BFup ActiveX control (BFup.dll) in B21Soft BFup before 1.0.802.29 allows remote attackers to execute arbitrary code via a long FilePath parameter.

    Published: 10 Mar 2008
    9
    Critical

    CVE-2008-1277

    Last Modified: 23 Apr 2026

    The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial of service (crash) via (1) SEARCH and (2) APPEND commands without required arguments, which triggers a NULL pointer dereference.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1273

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web script or HTML via the path parameter to (1) popup.php, (2) test/dir2.php, (3) admin/upload.php, and (4) dirxml.php in upload/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1278

    Last Modified: 23 Apr 2026

    The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attackers to cause a denial of service (crash) via an invalid Accept-Charset header, which triggers a NULL pointer dereference. NOTE: the service is automatically restarted.

    Published: 10 Mar 2008
    9
    Critical

    CVE-2008-1276

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote authenticated attackers to execute arbitrary code via long arguments to the (1) FETCH, (2) EXAMINE, and (3) UNSUBSCRIBE commands.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1161

    Last Modified: 23 Apr 2026

    Buffer overflow in the Matroska demuxer (demuxers/demux_matroska.c) in xine-lib before 1.1.10.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Matroska file with invalid frame sizes.

    Published: 10 Mar 2008
    Unknown

    CVE-2008-1271

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1218. Reason: This candidate is a duplicate of CVE-2008-1218. Notes: All CVE users should reference CVE-2008-1218 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1270

    Last Modified: 23 Apr 2026

    mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

    Published: 10 Mar 2008
    7.5
    High

    CVE-2008-1219

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the kid parameter in a hadisgoster action to modules.php.

    Published: 10 Mar 2008
    7.5
    High

    CVE-2008-1220

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Mar 2008
    5
    Medium

    CVE-2008-1221

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote attackers to read arbitrary files via an absolute pathname in the RETR (get) command.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1225

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebCT Campus Edition 4.1.5.8, when "Don't wrap text" is enabled, allow remote authenticated users to inject arbitrary web script or HTML via a (1) mail message or (2) discussion board message. NOTE: this might overlap CVE-2005-1076.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1226

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration Suite (ZCS) 4.0.3, 4.5.6, and possibly other versions before 4.5.10 allow remote attackers to inject arbitrary web script or HTML via an e-mail attachment, possibly involving a (1) .jpg or (2) .gif image attachment.

    Published: 10 Mar 2008
    7.5
    High

    CVE-2008-1227

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the silc_fingerprint function in lib/silcutil/silcutil.c in Secure Internet Live Conferencing (SILC) Toolkit 1.1.5, and unspecified earlier versions, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via long input data. NOTE: some of these details are obtained from third party information.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1228

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly Minigal) allows remote attackers to inject arbitrary web script or HTML via the list parameter in an import action.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1229

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject arbitrary web script or HTML via the editor parameter, a different vector than CVE-2007-5120.b.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1242

    Last Modified: 23 Apr 2026

    The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.

    Published: 10 Mar 2008
    4.3
    Medium

    CVE-2008-1243

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability on the Linksys WRT300N router with firmware 2.00.20, when Mozilla Firefox or Apple Safari is used, allows remote attackers to inject arbitrary web script or HTML via the dyndns_domain parameter to the default URI.

    Published: 10 Mar 2008
    10
    Critical

    CVE-2008-1244

    Last Modified: 23 Apr 2026

    cgi-bin/setup_dns.exe on the Belkin F5D7230-4 router with firmware 9.01.10 does not require authentication, which allows remote attackers to perform administrative actions, as demonstrated by changing a DNS server via the dns1_1, dns1_2, dns1_3, and dns1_4 parameters. NOTE: it was later reported that F5D7632-4V6 with firmware 6.01.08 is also affected.

    Published: 10 Mar 2008
    9.4
    Critical

    CVE-2008-1249

    Last Modified: 23 Apr 2026

    snomControl.swf in the central phone server for the Snom 320 SIP Phone allows remote attackers to cause a denial of service (application crash and corruption of call logs) via a "'); (double quote, quote, close parenthesis, semicolon) sequence in the "Call a number" field.

    Published: 10 Mar 2008
    9.3
    Critical

    CVE-2008-1250

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the central phone server for the Snom 320 SIP Phone allow remote attackers to perform actions as the phone user, as demonstrated by inserting an address-book entry containing an XSS sequence.

    Published: 10 Mar 2008