CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-0985

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows remote attackers to execute arbitrary code via a crafted GIF file whose logical screen height and width are different than the actual height and width.

    Published: 6 Mar 2008
    7.5
    High

    CVE-2008-0986

    Last Modified: 23 Apr 2026

    Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1172

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerabilities in account-inbox.php in TorrentTrader Classic 1.08 allow remote attackers to perform certain actions as other users, as demonstrated by sending messages.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1173

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in account-inbox.php in TorrentTrader Classic 1.08 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1174

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in editUser.asp in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 6 Mar 2008
    7.5
    High

    CVE-2008-1177

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1178

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/doc/index.php in Centreon 1.4.2.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter, a different vector than CVE-2008-1119.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1180

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dana-na/auth/rdremediate.cgi in Juniper Networks Secure Access 2000 5.5 R1 build 11711 allows remote attackers to inject arbitrary web script or HTML via the delivery_mode parameter.

    Published: 6 Mar 2008
    5
    Medium

    CVE-2008-1181

    Last Modified: 23 Apr 2026

    Juniper Networks Secure Access 2000 5.5 R1 (build 11711) allows remote attackers to obtain sensitive information via a direct request for remediate.cgi without certain parameters, which reveals the path in an "Execute failed" error message.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1182

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1186

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1188

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the useEncodingDecl function in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allow remote attackers to execute arbitrary code via a JNLP file with (1) a long key name in the xml header or (2) a long charset value, different issues than CVE-2008-1189, aka "The first two issues."

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1193

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1194

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1195

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.

    Published: 6 Mar 2008
    6.8
    Medium

    CVE-2008-1196

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Java Web Start (javaws.exe) in Sun JDK and JRE 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to execute arbitrary code via a crafted JNLP file.

    Published: 6 Mar 2008
    5
    Medium

    CVE-2008-1184

    Last Modified: 23 Apr 2026

    The DNSSEC validation library (libval) library in dnssec-tools before 1.3.1 does not properly check that the signing key is the APEX trust anchor, which might allow attackers to conduct unspecified attacks.

    Published: 6 Mar 2008
    9.3
    Critical

    CVE-2008-1185

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."

    Published: 6 Mar 2008
    6.8
    Medium

    CVE-2008-1191

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka "The fifth issue."

    Published: 6 Mar 2008
    2.6
    Low

    CVE-2008-1176

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1179

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in include/common/javascript/color_picker.php in Centreon 1.4.2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) title parameters. NOTE: some of these details are obtained from third party information.

    Published: 6 Mar 2008
    6.8
    Medium

    CVE-2008-1187

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.

    Published: 6 Mar 2008
    6.8
    Medium

    CVE-2008-1189

    Last Modified: 23 Apr 2026

    Buffer overflow in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different issue than CVE-2008-1188, aka the "third" issue.

    Published: 6 Mar 2008
    6.8
    Medium

    CVE-2008-1192

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and "execute local applications" via unknown vectors.

    Published: 6 Mar 2008
    2.1
    Low

    CVE-2008-4870

    Last Modified: 23 Apr 2026

    dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.conf, which allows local users to obtain the ssl_key_password parameter value.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1175

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in AuthentiX 6.3b1 Trial allows remote attackers to inject arbitrary web script or HTML via the username parameter to aspAdmin/deleteUser.asp, a different vector than CVE-2008-1174. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Mar 2008
    4.3
    Medium

    CVE-2008-1183

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Crafty Syntax Live Help (CSLH) before 2.14.6 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) livehelp.php, (2) user_questions.php, and (3) leavemessage.php. NOTE: the lostsheep.php vector is covered by CVE-2008-0848.

    Published: 6 Mar 2008
    7.5
    High

    CVE-2008-1162

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.

    Published: 5 Mar 2008
    7.5
    High

    CVE-2008-1163

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbitrary SQL commands via the userid parameter in a profile action.

    Published: 5 Mar 2008
    7.5
    High

    CVE-2008-1164

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via the mod_project_id parameter in a project_detail action.

    Published: 5 Mar 2008
    5
    Medium

    CVE-2008-1166

    Last Modified: 23 Apr 2026

    Flyspray 0.9.9.4 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate usernames.

    Published: 5 Mar 2008
    6.8
    Medium

    CVE-2008-1170

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in KCWiki 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the page parameter to (1) minimal/wiki.php and (2) simplest/wiki.php.

    Published: 5 Mar 2008
    6.8
    Medium

    CVE-2008-1171

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the 123 Flash Chat Module for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter to (1) 123flashchat.php and (2) phpbb_login_chat.php. NOTE: CVE disputes this issue because $phpbb_root_path is explicitly set to "./" in both programs

    Published: 5 Mar 2008
    2.6
    Low

    CVE-2007-6704

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in F5 FirePass 4100 SSL VPN 5.4.1 through 5.5.2 and 6.0 through 6.0.1, when pre-logon sequences are enabled, allow remote attackers to inject arbitrary web script or HTML via the query string to (1) my.activation.php3 and (2) my.logon.php3.

    Published: 5 Mar 2008
    4.3
    Medium

    CVE-2008-1165

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Flyspray 0.9.9 through 0.9.9.4 allow remote attackers to inject arbitrary web script or HTML via (1) a forced SQL error message or (2) old_value and new_value database fields in task summaries, related to the item_summary parameter in a details action in index.php. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2008
    4.3
    Medium

    CVE-2008-1168

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Mar 2008
    7.8
    High

    CVE-2008-1169

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the embedded HTTP server in SCI Photo Chat Server 3.4.9 and earlier allows remote attackers to read arbitrary files via a "..\" (dot dot backslash) or "../" (dot dot forward slash) in the GET command.

    Published: 5 Mar 2008
    10
    Critical

    CVE-2008-1167

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2008
    5
    Medium

    CVE-2008-1099

    Last Modified: 23 Apr 2026

    _macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.

    Published: 5 Mar 2008
    4.3
    Medium

    CVE-2008-1098

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) certain input processed by formatter/text_gedit.py (aka the gui editor formatter); (2) a page name, which triggers an injection in PageEditor.py when the page is successfully deleted by a victim in a DeletePage action; or (3) the destination page name for a RenamePage action, which triggers an injection in PageEditor.py when a victim's rename attempt fails because of a duplicate name. NOTE: the AttachFile XSS issue is already covered by CVE-2008-0781, and the login XSS issue is already covered by CVE-2008-0780.

    Published: 5 Mar 2008
    6.8
    Medium

    CVE-2008-0072

    Last Modified: 23 Apr 2026

    Format string vulnerability in the emf_multipart_encrypted function in mail/em-format.c in Evolution 2.12.3 and earlier allows remote attackers to execute arbitrary code via a crafted encrypted message, as demonstrated using the Version field.

    Published: 5 Mar 2008
    7.5
    High

    CVE-2008-1367

    Last Modified: 23 Apr 2026

    gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU consumption in SBCL.

    Published: 5 Mar 2008
    6.8
    Medium

    CVE-2008-1148

    Last Modified: 23 Apr 2026

    A certain pseudo-random number generator (PRNG) algorithm that uses ADD with 0 random hops (aka "Algorithm A0"), as used in OpenBSD 3.5 through 4.2 and NetBSD 1.6.2 through 4.0, allows remote attackers to guess sensitive values such as (1) DNS transaction IDs or (2) IP fragmentation IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as DNS cache poisoning, injection into TCP packets, and OS fingerprinting.

    Published: 4 Mar 2008
    6.8
    Medium

    CVE-2008-1147

    Last Modified: 23 Apr 2026

    A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 2-bit random hops (aka "Algorithm X2"), as used in OpenBSD 2.6 through 3.4, Mac OS X 10 through 10.5.1, FreeBSD 4.4 through 7.0, and DragonFlyBSD 1.0 through 1.10.1, allows remote attackers to guess sensitive values such as IP fragmentation IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as injection into TCP packets and OS fingerprinting.

    Published: 4 Mar 2008
    6.8
    Medium

    CVE-2008-1146

    Last Modified: 23 Apr 2026

    A certain pseudo-random number generator (PRNG) algorithm that uses XOR and 3-bit random hops (aka "Algorithm X3"), as used in OpenBSD 2.8 through 4.2, allows remote attackers to guess sensitive values such as DNS transaction IDs by observing a sequence of previously generated values. NOTE: this issue can be leveraged for attacks such as DNS cache poisoning against OpenBSD's modification of BIND.

    Published: 4 Mar 2008
    5
    Medium

    CVE-2008-1111

    Last Modified: 23 Apr 2026

    mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.

    Published: 4 Mar 2008
    7.2
    High

    CVE-2008-1139

    Last Modified: 23 Apr 2026

    DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, aka the "ring0 link list zero SYSTEM" vulnerability.

    Published: 4 Mar 2008
    7.2
    High

    CVE-2008-1140

    Last Modified: 23 Apr 2026

    DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data structure associated with a mounted pseudo-filesystem, aka the "ring0 SYSTEM" vulnerability.

    Published: 4 Mar 2008
    4.9
    Medium

    CVE-2008-1141

    Last Modified: 23 Apr 2026

    Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures."

    Published: 4 Mar 2008
    4.9
    Medium

    CVE-2008-1138

    Last Modified: 23 Apr 2026

    DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a certain ZERO_MEM DLMFENC_IOCTL request to \\.\DLKPFSD_Device, aka the "ring0 link list zero" vulnerability.

    Published: 4 Mar 2008