CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-1067

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP code via a URL in the _SESSION[path] parameter to (1) ezmlm.php and (2) tools/update_translations.php.

    Published: 28 Feb 2008
    6.8
    Medium

    CVE-2008-1068

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) Vert/index.php, (2) Noir/index.php, and (3) Bleu/index.php in template/, different vectors than CVE-2008-0645.

    Published: 28 Feb 2008
    4.3
    Medium

    CVE-2008-0124

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Serendipity (S9Y) before 1.3-beta1 allows remote authenticated users to inject arbitrary web script or HTML via (1) the "Real name" field in Personal Settings, which is presented to readers of articles; or (2) a file upload, as demonstrated by a .htm, .html, or .js file.

    Published: 28 Feb 2008
    4.3
    Medium

    CVE-2008-1063

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability index.php in the XM-Memberstats (xmmemberstats) module for XOOPS allows remote attackers to inject arbitrary web script or HTML via the sortby parameter.

    Published: 28 Feb 2008
    4.3
    Medium

    CVE-2008-1064

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in images.php in the Red Mexico RMSOFT Gallery System (GS) 2.0 module (aka rmgs) for XOOPS allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 28 Feb 2008
    7.5
    High

    CVE-2008-1065

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in the XM-Memberstats (xmmemberstats) 2.0e module for XOOPS allow remote attackers to execute arbitrary SQL commands via the (1) letter or (2) sortby parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Feb 2008
    7.5
    High

    CVE-2008-1066

    Last Modified: 23 Apr 2026

    The modifier.regex_replace.php plugin in Smarty before 2.6.19, as used by Serendipity (S9Y) and other products, allows attackers to call arbitrary PHP functions via templates, related to a '\0' character in a search string.

    Published: 28 Feb 2008
    7.5
    High

    CVE-2007-5397

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the activePDF Server service (aka APServer.exe) in activePDF Server 3.8.4 and 3.8.5.14, and possibly other versions before 3.8.6.16, allows remote attackers to execute arbitrary code via a packet with a size field that is less than the actual size of the data.

    Published: 28 Feb 2008
    7.1
    High

    CVE-2008-0308

    Last Modified: 23 Apr 2026

    Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to cause a denial of service (memory consumption) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).

    Published: 28 Feb 2008
    6.8
    Medium

    CVE-2008-0309

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Symantec Decomposer, as used in certain Symantec antivirus products including Symantec Scan Engine 5.1.2 and other versions before 5.1.6.31, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed RAR file to the Internet Content Adaptation Protocol (ICAP) port (1344/tcp).

    Published: 28 Feb 2008
    7.5
    High

    CVE-2008-1059

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter.

    Published: 28 Feb 2008
    7.5
    High

    CVE-2008-1060

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote attackers to execute arbitrary PHP code via the text parameter.

    Published: 28 Feb 2008
    5
    Medium

    CVE-2008-1062

    Last Modified: 23 Apr 2026

    InterVideo IMC Server (aka IMCSvr.exe) and InterVideo Home Theater (aka IHT.exe) in InterVideo WinDVD Media Center 2.11.15.0 allow remote attackers to cause a denial of service (NULL dereference and application crash) via a crafted packet with two CRLF sequences. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 Feb 2008
    6.9
    Medium

    CVE-2008-1056

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Symark PowerBroker 2.8 through 5.0.1 allow local users to gain privileges via a long argv[0] string when executing (1) pbrun, (2) pbsh, or (3) pbksh. NOTE: the product is often installed in environments with trust relationships that facilitate subsequent remote compromises.

    Published: 28 Feb 2008
    7.8
    High

    CVE-2008-1058

    Last Modified: 23 Apr 2026

    The tcp_respond function in netinet/tcp_subr.c in OpenBSD 4.1 and 4.2 allows attackers to cause a denial of service (panic) via crafted TCP packets. NOTE: some of these details are obtained from third party information.

    Published: 28 Feb 2008
    7.8
    High

    CVE-2008-1057

    Last Modified: 23 Apr 2026

    The ip6_check_rh0hdr function in netinet6/ip6_input.c in OpenBSD 4.2 allows attackers to cause a denial of service (panic) via malformed IPv6 routing headers.

    Published: 28 Feb 2008
    4.3
    Medium

    CVE-2008-1061

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) text parameter to (a) warning.php, (b) notice.php, and (c) inset.php in view/sniplets/, and possibly (d) modules/execute.php; the (2) url parameter to (e) view/admin/submenu.php; and the (3) page parameter to (f) view/admin/pager.php.

    Published: 28 Feb 2008
    7.1
    High

    CVE-2008-1198

    Last Modified: 23 Apr 2026

    The default IPSec ifup script in Red Hat Enterprise Linux 3 through 5 configures racoon to use aggressive IKE mode instead of main IKE mode, which makes it easier for remote attackers to conduct brute force attacks by sniffing an unencrypted preshared key (PSK) hash.

    Published: 28 Feb 2008
    4.3
    Medium

    CVE-2008-1037

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the file listing function in the web management interface in Packeteer PacketShaper and PolicyCenter 8.2.2 allows remote attackers to inject arbitrary web script or HTML via the FILELIST parameter to an arbitrary component, which triggers injection into an Error Report page.

    Published: 27 Feb 2008
    6.8
    Medium

    CVE-2008-1038

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the extmanager_install parameter.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1039

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands via the QID parameter.

    Published: 27 Feb 2008
    10
    Critical

    CVE-2008-1040

    Last Modified: 23 Apr 2026

    Buffer overflow in the Single Sign-On function in Fujitsu Interstage Application Server 8.0.0 through 8.0.3 and 9.0.0, Interstage Studio 8.0.1 and 9.0.0, and Interstage Apworks 8.0.0 allows remote attackers to execute arbitrary code via a long URI.

    Published: 27 Feb 2008
    4.3
    Medium

    CVE-2008-1045

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.

    Published: 27 Feb 2008
    6.8
    Medium

    CVE-2008-1046

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in footer.php in Quinsonnas Mail Checker 1.55 allows remote attackers to execute arbitrary PHP code via a URL in the op[footer_body] parameter.

    Published: 27 Feb 2008
    4.3
    Medium

    CVE-2008-1047

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in tiki-edit_article.php in TikiWiki before 1.9.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Feb 2008
    4.3
    Medium

    CVE-2008-1048

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in manager/xmedia.php in Plume CMS 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1053

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticle or (2) printpage action to modules.php.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1055

    Last Modified: 23 Apr 2026

    Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in the page parameter.

    Published: 27 Feb 2008
    6.8
    Medium

    CVE-2008-1042

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1050

    Last Modified: 6 Apr 2026

    SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitrary SQL commands via the sbcat_id parameter.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1043

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BETA allows remote attackers to execute arbitrary PHP code via a URL in the menu parameter.

    Published: 27 Feb 2008
    7.5
    High

    CVE-2008-1044

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different vector than CVE-2007-4722. NOTE: some of these details are obtained from third party information.

    Published: 27 Feb 2008
    6.8
    Medium

    CVE-2008-1051

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/body_comm.inc.php in phpProfiles 4.5.2 BETA allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Published: 27 Feb 2008
    6.4
    Medium

    CVE-2008-1052

    Last Modified: 23 Apr 2026

    The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL pointer dereference when memory allocation fails.

    Published: 27 Feb 2008
    6.4
    Medium

    CVE-2008-1054

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlier, and beta 39a, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via an HTTP request with multiple long headers to webmail.exe and unspecified other CGI executables, which triggers an overflow when assigning values to environment variables. NOTE: some of these details are obtained from third party information.

    Published: 27 Feb 2008
    4.3
    Medium

    CVE-2008-1041

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mwhois.php in Matt Wilson Matt's Whois (MWhois) allows remote attackers to inject arbitrary web script or HTML via the domain parameter.

    Published: 27 Feb 2008
    10
    Critical

    CVE-2008-1049

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.

    Published: 27 Feb 2008
    4.6
    Medium

    CVE-2008-0595

    Last Modified: 23 Apr 2026

    dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.

    Published: 27 Feb 2008
    6.8
    Medium

    CVE-2008-0411

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.

    Published: 27 Feb 2008
    9.3
    Critical

    CVE-2008-0984

    Last Modified: 23 Apr 2026

    The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote attackers to overwrite arbitrary memory and execute arbitrary code via a malformed MP4 file.

    Published: 26 Feb 2008
    5
    Medium

    CVE-2008-0983

    Last Modified: 23 Apr 2026

    lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.

    Published: 26 Feb 2008
    7.5
    High

    CVE-2008-0304

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.12 and SeaMonkey before 1.1.8 might allow remote attackers to execute arbitrary code via a crafted external-body MIME type in an e-mail message, related to an incorrect memory allocation during message preview.

    Published: 26 Feb 2008
    6.9
    Medium

    CVE-2008-0923

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.

    Published: 26 Feb 2008
    7.5
    High

    CVE-2008-0973

    Last Modified: 23 Apr 2026

    Buffer overflow in Double-Take (aka HP StorageWorks Storage Mirroring) 4.5.0.1629, and other 4.5.0.x versions, allows remote attackers to have an unknown impact via a packet with a long string in the username field.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0974

    Last Modified: 23 Apr 2026

    Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon termination) via (1) a large vector<T> value, which raises a "vector<T> too long" exception; or (2) a certain packet that raises an ospace/time/src\date.cpp exception.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0979

    Last Modified: 23 Apr 2026

    Stack consumption vulnerability in Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain packet that triggers the recursive calling of a function.

    Published: 25 Feb 2008
    6.4
    Medium

    CVE-2008-0981

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in spyce/examples/redirect.spy in Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0976

    Last Modified: 23 Apr 2026

    Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a malformed packet, as demonstrated by a packet of type (1) 0x2722 or (2) 0x272a.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0977

    Last Modified: 23 Apr 2026

    Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (daemon crash) via a certain long packet that triggers an attempt to allocate a large amount of memory.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0978

    Last Modified: 23 Apr 2026

    Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to obtain sensitive information via a packet of type (1) 0x2728, which provides operating system and path information; (2) 0x274e, which lists Ethernet adapters; (3) 0x2726, which provides filesystem information; (4) 0x274f, which specifies the printer driver; or (5) 0x2757, which provides recent log entries.

    Published: 25 Feb 2008