CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-0906

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation.

    Published: 22 Feb 2008
    7.1
    High

    CVE-2007-6282

    Last Modified: 23 Apr 2026

    The IPsec implementation in Linux kernel before 2.6.25 allows remote routers to cause a denial of service (crash) via a fragmented ESP packet in which the first fragment does not contain the entire ESP header and IV.

    Published: 22 Feb 2008
    6.8
    Medium

    CVE-2008-0894

    Last Modified: 23 Apr 2026

    Apple Safari might allow remote attackers to obtain potentially sensitive memory contents or cause a denial of service (crash) via a crafted (1) bitmap (BMP) or (2) GIF file, a related issue to CVE-2008-0420.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2007-4516

    Last Modified: 23 Apr 2026

    The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation 5.0 for Windows allows remote attackers to cause a denial of service (daemon crash or hang) via malformed packets.

    Published: 21 Feb 2008
    9.3
    Critical

    CVE-2008-0638

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Veritas Enterprise Administrator (VEA) service (aka vxsvc.exe) in Symantec Veritas Storage Foundation 5.0 allows remote attackers to execute arbitrary code via a packet with a crafted value of a certain size field, which is not checked for consistency with the actual buffer size.

    Published: 21 Feb 2008
    6.8
    Medium

    CVE-2008-0871

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute arbitrary code via a (1) long password in an Authorization header to the HTTP service or a (2) large packet to the SMPP service.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0872

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in SmarterTools SmarterMail Enterprise 4.3 allows remote attackers to inject arbitrary web script or HTML via a STYLE attribute of an element in the Subject field of an e-mail message.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0873

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the jlmZone Classifieds module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in an Adsview action.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0879

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the Web_Links module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewlink action.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0880

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the page_id parameter.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0881

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0876

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SEWB3 messaging service in Hitachi SEWB3/PLATFORM and SEWB3/MI-PLATFORM 01-00 through 02-14-/A allows remote attackers to cause a denial of service (service outage) via "invalid data."

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0874

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0877

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme, and (6) language parameters to (b) ajax_request.php; the jz_path parameter to (c) slim.php; the frontend, theme, and jz_path parameters to (d) popup.php; the (13) PATH_INFO to index.php and (e) slim.php; and the (14) query parameter in a playlistedit action and (15) siteNewsData parameter in a sitenews action to (f) popup.php.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0878

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter in a view action.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0875

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Hitachi EUR Print Manager, and related Client and Local Server products, 05-06 through 05-06-/B and 05-08 allows remote attackers to cause a denial of service (service hang or termination) via unspecified vectors related to "unexpected data."

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0861

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in leg/Main.nsf in IBM Lotus Quickplace 7.0 allows remote attackers to inject arbitrary web script or HTML via an h_SearchString sub-parameter in the PreSetFields parameter of an EditDocument action.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0862

    Last Modified: 23 Apr 2026

    IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0863

    Last Modified: 23 Apr 2026

    BEA WebLogic Server and WebLogic Express 9.0 and 9.1 exposes the web service's WSDL and security policies, which allows remote attackers to obtain sensitive information and potentially launch further attacks.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0865

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0866

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0870

    Last Modified: 23 Apr 2026

    BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 2, under certain circumstances, can redirect a user from the https:// URI for the Portal Administration Console to an http URI, which allows remote attackers to sniff the session.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0868

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Groupspace in BEA WebLogic Portal 10.0 and 9.2 through Maintenance Pack 1 allows remote authenticated users to inject arbitrary web script or HTML via unknown vectors.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0869

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0864

    Last Modified: 23 Apr 2026

    Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definition label, which might allow remote attackers to bypass intended access restrictions.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0867

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in portal/server.pt in BEA AquaLogic Interaction 6.1 through MP1 and Plumtree Foundation 6.0 through SP1 allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 21 Feb 2008
    7.8
    High

    CVE-2007-6426

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in EMC RepliStor 6.2 SP2, and possibly earlier versions, allow remote attackers to execute arbitrary code via crafted compressed data.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0849

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0850

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0847

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0856

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0857

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WoltLab Burning Board 3.0.3 PL 1 allows remote attackers to execute arbitrary SQL commands via the sortOrder parameter to the PMList page.

    Published: 21 Feb 2008
    Unknown

    CVE-2008-6426

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6426. Reason: This candidate is a duplicate of CVE-2007-6426. Notes: All CVE users should reference CVE-2007-6426 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0848

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in lostsheep.php in Crafty Syntax Live Help (CSLH) before 2.14.16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the versions claimed by the original researcher are probably incorrect.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0852

    Last Modified: 23 Apr 2026

    freeSSHd 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a SSH2_MSG_NEWKEYS packet to TCP port 22, which triggers a NULL pointer dereference.

    Published: 21 Feb 2008
    5
    Medium

    CVE-2008-0859

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Kerio MailServer before 6.5.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors related to decoding of uuencoded input, which triggers memory corruption.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0851

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0854

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_salesrep component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the rid parameter in a showrep action to index.php.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0858

    Last Modified: 23 Apr 2026

    Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 21 Feb 2008
    10
    Critical

    CVE-2008-0860

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0853

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.

    Published: 21 Feb 2008
    7.5
    High

    CVE-2008-0855

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Facile Forms (com_facileforms) component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Published: 21 Feb 2008
    3.7
    Low

    CVE-2008-0883

    Last Modified: 23 Apr 2026

    acroread in Adobe Acrobat Reader 8.1.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files related to SSL certificate handling.

    Published: 21 Feb 2008
    4.3
    Medium

    CVE-2008-0834

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Lotus Quickr for i5/OS before 8.0.0.2 Hotfix 11, when anonymous access is disabled on HTTP ports, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Feb 2008
    4.3
    Medium

    CVE-2008-0838

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface in Sophos ES1000 and ES4000 Email Security Appliance 2.1.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) error and (2) go parameters to the login page.

    Published: 20 Feb 2008
    4.4
    Medium

    CVE-2008-0840

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in view_member.php in Public Warehouse LightBlog 9.6 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the username parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0841

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Giorgio Nordo Ricette (com_ricette) 1.0 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0842

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Published: 20 Feb 2008
    7.5
    High

    CVE-2008-0846

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_profile component for Joomla! allows remote attackers to execute arbitrary SQL commands via the oid parameter.

    Published: 20 Feb 2008
    4.9
    Medium

    CVE-2008-0836

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 9 and 10 on x86 architectures allows local users to cause a denial of service (panic) via unspecified vectors that trigger a NULL pointer dereference in the vuid3ps2 module, a different issue than CVE-2007-5319.

    Published: 20 Feb 2008