CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-0980

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Spyce - Python Server Pages (PSP) 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the url or type parameter to docs/examples/redirect.spy; (2) the x parameter to docs/examples/handlervalidate.spy; (3) the name parameter to spyce/examples/request.spy; (4) the Name parameter to spyce/examples/getpost.spy; (5) the mytextarea parameter, the mypass parameter, or an empty parameter to spyce/examples/formtag.spy; (6) the newline parameter to the default URI under demos/chat/; (7) the text1 parameter to docs/examples/formintro.spy; or (8) the mytext or mydate parameter to docs/examples/formtag.spy.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0975

    Last Modified: 23 Apr 2026

    Double-Take 5.0.0.2865 and earlier, distributed under the HP StorageWorks Storage Mirroring name and other names, allows remote attackers to cause a denial of service (CPU consumption) via a -1 value in the field that specifies the size of the vector<T> value.

    Published: 25 Feb 2008
    5.8
    Medium

    CVE-2008-0982

    Last Modified: 23 Apr 2026

    Spyce - Python Server Pages (PSP) 2.1.3 allows remote attackers to obtain sensitive information via a direct request for spyce/examples/automaton.spy, which reveals the path in an error message.

    Published: 25 Feb 2008
    Unknown

    CVE-2008-0929

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 25 Feb 2008
    4.3
    Medium

    CVE-2008-0941

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote authenticated users to inject arbitrary web script or HTML via an event.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0942

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in GradebookStuScores.asp in Eagle Software Aeries Browser Interface (ABI) 3.8.2.8 allows remote attackers to execute arbitrary SQL commands via the GrdBk parameter.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0943

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Eagle Software Aeries Browser Interface (ABI) 3.7.2.2 allow remote attackers to execute arbitrary SQL commands via the (1) FC parameter to Comments.asp, or the Term parameter to (2) Labels.asp or (3) ClassList.asp.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0944

    Last Modified: 23 Apr 2026

    Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereference and application crash) via a version field containing zero.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0932

    Last Modified: 23 Apr 2026

    diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter.

    Published: 25 Feb 2008
    3.5
    Low

    CVE-2008-0945

    Last Modified: 23 Apr 2026

    Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field.

    Published: 25 Feb 2008
    4.9
    Medium

    CVE-2008-0946

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to create arbitrary empty files via a .. (dot dot) in the recipient field.

    Published: 25 Feb 2008
    4.3
    Medium

    CVE-2008-0940

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Plain Black WebGUI before 7.4.24 allows remote attackers to inject arbitrary web script or HTML when creating a username, a different vulnerability than CVE-2007-0407.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0939

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in wppa.php in the WP Photo Album (WPPA) before 1.1 plugin for WordPress allow remote attackers to execute arbitrary SQL commands via (1) the photo parameter to index.php, used by the wppa_photo_name function; or (2) the album parameter to index.php, used by the wppa_album_name function. NOTE: some of these details are obtained from third party information.

    Published: 25 Feb 2008
    4.7
    Medium

    CVE-2008-0933

    Last Modified: 23 Apr 2026

    Multiple race conditions in the CPU Performance Counters (cpc) subsystem in the kernel in Sun Solaris 10 allow local users to cause a denial of service (panic) via unspecified vectors related to kcpc_unbind and kcpc_restore.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0936

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Prayer List (prayerlist) 1.04 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Published: 25 Feb 2008
    10
    Critical

    CVE-2008-0935

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.34 allows remote attackers to execute arbitrary code via a long argument to the ExecuteRequest method.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2008-0934

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the NukeC 2.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id_catg parameter in a ViewCatg action.

    Published: 25 Feb 2008
    6.8
    Medium

    CVE-2008-0937

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter in a print action, a different vector than CVE-2007-1811.

    Published: 25 Feb 2008
    4.7
    Medium

    CVE-2008-0938

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the dynamic tracing framework (DTrace) in Sun Solaris 10 allows local users with PRIV_DTRACE_USER or PRIV_DTRACE_PROC privileges to obtain sensitive kernel information via unspecified vectors, a different vulnerability than CVE-2007-4126.

    Published: 25 Feb 2008
    7.5
    High

    CVE-2009-1438

    Last Modified: 23 Apr 2026

    Integer overflow in the CSoundFile::ReadMed function (src/load_med.cpp) in libmodplug before 0.8.6, as used in gstreamer-plugins, TTPlayer, and other products, allows context-dependent attackers to execute arbitrary code via a MED file with a crafted (1) song comment or (2) song name, which triggers a heap-based buffer overflow, as exploited in the wild in August 2008.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0597

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (crash) via crafted IPP packets.

    Published: 25 Feb 2008
    5
    Medium

    CVE-2008-0596

    Last Modified: 23 Apr 2026

    Memory leak in CUPS before 1.1.22, and possibly other versions, allows remote attackers to cause a denial of service (memory consumption and daemon crash) via a large number of requests to add and remove shared printers.

    Published: 25 Feb 2008
    6.4
    Medium

    CVE-2008-0915

    Last Modified: 23 Apr 2026

    The Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 stores the number of remaining allowed login attempts in a cookie, which makes it easier for remote attackers to conduct brute force attacks by manipulating this cookie's value.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0914

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Mediation server in IPdiva SSL VPN Server 2.2 before 2.2.8.84 and 2.3 before 2.3.2.14 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0922

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modules.php.

    Published: 22 Feb 2008
    6.5
    Medium

    CVE-2008-0911

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0913

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB or IP.Board) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via crafted BBCodes in an unspecified context.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0919

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 and earlier allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

    Published: 22 Feb 2008
    6.5
    Medium

    CVE-2008-0920

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5 allows remote authenticated users to execute arbitrary SQL commands via the portname parameter, which is not properly handled by a validation regular expression.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0921

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0916

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a viewcategory action to index.php.

    Published: 22 Feb 2008
    10
    Critical

    CVE-2008-0912

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products, allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long (1) username, (2) version, or (3) remote ID. NOTE: some of these details are obtained from third party information.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0917

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Tor World Tor Search 1.1 and earlier, I-Navigator 4.0, Mobile Frontier 2.1 and earlier, Diary.cgi (aka Quotes of the Day) 1.5 and earlier, Tor News 1.21 and earlier, Simple BBS 1.3 and earlier, Interactive BBS 1.3 and earlier, Tor Board 1.1 and earlier, Simple Vote 1.1 and earlier, and Com Vote 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0918

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/count_dl_or_link.inc.php in the astatsPRO (com_astatspro) 1.0.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to getfile.php, a different vector than CVE-2008-0839. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0910

    Last Modified: 23 Apr 2026

    Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted RAR archive. NOTE: this might be related to CVE-2008-0792.

    Published: 22 Feb 2008
    7.2
    High

    CVE-2008-0162

    Last Modified: 23 Apr 2026

    misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

    Published: 22 Feb 2008
    6.4
    Medium

    CVE-2008-0895

    Last Modified: 23 Apr 2026

    BEA WebLogic Server and WebLogic Express 6.1 through 10.0 allows remote attackers to bypass authentication for application servlets via crafted request headers.

    Published: 22 Feb 2008
    4.9
    Medium

    CVE-2008-0896

    Last Modified: 23 Apr 2026

    BEA WebLogic Portal 10.0 and 9.2 through MP1, when an administrator deletes a single instance of a content portlet, removes entitlement policies for other content portlets, which allows attackers to bypass intended access restrictions.

    Published: 22 Feb 2008
    7.9
    High

    CVE-2008-0897

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended access restrictions and receive messages from a standalone JMS Topic or secured Distributed Topic member destination, related to durable subscriptions.

    Published: 22 Feb 2008
    7.1
    High

    CVE-2008-0901

    Last Modified: 23 Apr 2026

    BEA WebLogic Server and Express 7.0 through 10.0 allows remote attackers to conduct brute force password guessing attacks, even when account lockout has been activated, via crafted URLs that indicate whether a guessed password is successful or not.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0902

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Server and Express 6.1 through 10.0 MP1 allow remote attackers to inject arbitrary web script or HTML via unspecified samples. NOTE: this might be the same issue as CVE-2007-2694.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0903

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BEA WebLogic Server and Express proxy plugin, as distributed before November 2007 and before 9.2 MP3 and 10.0 MP2, allows remote attackers to cause a denial of service (web server crash) via a crafted URL.

    Published: 22 Feb 2008
    7.8
    High

    CVE-2008-0904

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the download servlet in BEA Plumtree Collaboration 4.1 through SP2 and AquaLogic Interaction 4.2 through MP1 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0899

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Administration Console in BEA WebLogic Server and Express 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via URLs that are not properly handled by the Unexpected Exception Page.

    Published: 22 Feb 2008
    4.3
    Medium

    CVE-2008-0909

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to inject arbitrary web script or HTML via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Feb 2008
    5.8
    Medium

    CVE-2008-0898

    Last Modified: 23 Apr 2026

    The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client cannot send a message to a member of a distributed queue, which allows remote authenticated users to bypass intended access restrictions for protected distributed queues.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0907

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 22 Feb 2008
    7.5
    High

    CVE-2008-0908

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in browse.asp in Schoolwires Academic Portal allows remote attackers to execute arbitrary SQL commands via the c parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Feb 2008
    6
    Medium

    CVE-2008-0900

    Last Modified: 23 Apr 2026

    Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to hijack web sessions via unknown vectors.

    Published: 22 Feb 2008
    5
    Medium

    CVE-2008-0905

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 22 Feb 2008