CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2008-0531

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SIP firmware might allow remote SIP servers to execute arbitrary code via a crafted challenge/response message.

    Published: 15 Feb 2008
    7.5
    High

    CVE-2008-0789

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in countdown.php in LI-Scripts LI-Countdown allows remote attackers to execute arbitrary SQL commands via the years parameter.

    Published: 15 Feb 2008
    5
    Medium

    CVE-2008-0790

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 15 Feb 2008
    7.8
    High

    CVE-2008-0526

    Last Modified: 23 Apr 2026

    Cisco Unified IP Phone 7940, 7940G, 7960, and 7960G running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a long ICMP echo request (ping) packet.

    Published: 15 Feb 2008
    7.8
    High

    CVE-2008-0527

    Last Modified: 23 Apr 2026

    The HTTP server in Cisco Unified IP Phone 7935 and 7936 running SCCP firmware allows remote attackers to cause a denial of service (reboot) via a crafted HTTP request.

    Published: 15 Feb 2008
    10
    Critical

    CVE-2008-0529

    Last Modified: 23 Apr 2026

    Buffer overflow in the telnet server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G running SCCP firmware might allow remote authenticated users to execute arbitrary code via a crafted command.

    Published: 15 Feb 2008
    4.9
    Medium

    CVE-2008-0777

    Last Modified: 23 Apr 2026

    The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.

    Published: 15 Feb 2008
    4.3
    Medium

    CVE-2008-0793

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in search.asp in Tendenci CMS allow remote attackers to inject arbitrary web script or HTML via the (1) category, (2) searchtext, (3) jobcategoryid, (4) contactcompany, and unspecified other parameters. NOTE: some of these details are obtained from third party information. NOTE: it is not clear whether this affects Tendenci Enterprise Edition in addition to the product's deployment on Tendenci's own server farm. If only the latter was affected, then this issue should not be included in CVE.

    Published: 15 Feb 2008
    6.4
    Medium

    CVE-2008-0794

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.

    Published: 15 Feb 2008
    5
    Medium

    CVE-2008-0791

    Last Modified: 23 Apr 2026

    ipdsserver.exe in Intermate WinIPDS 3.3 G52-33-021 allows remote attackers to cause a denial of service (CPU consumption) via short packets on TCP port 5001 with the 3, 5, 7, 13, 14, or 15 packet types.

    Published: 15 Feb 2008
    5.8
    Medium

    CVE-2008-0792

    Last Modified: 23 Apr 2026

    Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and others, allow remote attackers to bypass malware detection via a crafted CAB archive.

    Published: 15 Feb 2008
    6.5
    Medium

    CVE-2008-0787

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execute arbitrary SQL commands via the options[disablesmilies] parameter to private.php.

    Published: 15 Feb 2008
    6.1
    Medium

    CVE-2008-0642

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) WebHelp5 (WebHelp5Ext) or (2) WildFire (WildFireExt) extension, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-1280.

    Published: 15 Feb 2008
    6.8
    Medium

    CVE-2008-0788

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in MyBB 1.2.11 and earlier allow remote attackers to (1) hijack the authentication of moderators or administrators for requests that delete threads via a do_multideletethreads action to moderation.php and (2) hijack the authentication of arbitrary users for requests that delete private messages (PM) via a delete action to private.php.

    Published: 15 Feb 2008
    5
    Medium

    CVE-2008-0784

    Last Modified: 23 Apr 2026

    graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allows remote attackers to obtain the full path via an invalid local_graph_id parameter and other unspecified vectors.

    Published: 14 Feb 2008
    4.3
    Medium

    CVE-2008-0786

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k, when running on older PHP interpreters, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 14 Feb 2008
    4.3
    Medium

    CVE-2008-0783

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to inject arbitrary web script or HTML via (1) the view_type parameter to graph.php; (2) the filter parameter to graph_view.php; (3) the action parameter to the draw_navigation_text function in lib/functions.php, reachable through index.php (aka the login page) or data_input.php; or (4) the login_username parameter to index.php.

    Published: 14 Feb 2008
    7.5
    High

    CVE-2008-0785

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated users to execute arbitrary SQL commands via the (1) graph_list parameter to graph_view.php, (2) leaf_id and id parameters to tree.php, (3) local_graph_id parameter to graph_xport.php, and (4) login_username parameter to index.php/login.

    Published: 14 Feb 2008
    4.3
    Medium

    CVE-2008-0780

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in MoinMoin 1.5.x through 1.5.8 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the login action.

    Published: 14 Feb 2008
    4.3
    Medium

    CVE-2008-0781

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.5.8 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) message, (2) pagename, and (3) target filenames.

    Published: 14 Feb 2008
    7.2
    High

    CVE-2008-0779

    Last Modified: 23 Apr 2026

    The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, which allows local users to access kernel memory and execute arbitrary code via a crafted request.

    Published: 14 Feb 2008
    6.5
    Medium

    CVE-2008-0026

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.

    Published: 14 Feb 2008
    7.5
    High

    CVE-2008-0778

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long arguments to the (1) SetBgColor, (2) SetHREF, (3) SetMovieName, (4) SetTarget, and (5) SetMatrix methods.

    Published: 14 Feb 2008
    7.5
    High

    CVE-2008-3143

    Last Modified: 23 Apr 2026

    Multiple integer overflows in Python before 2.5.2 might allow context-dependent attackers to have an unknown impact via vectors related to (1) Include/pymem.h; (2) _csv.c, (3) _struct.c, (4) arraymodule.c, (5) audioop.c, (6) binascii.c, (7) cPickle.c, (8) cStringIO.c, (9) cjkcodecs/multibytecodec.c, (10) datetimemodule.c, (11) md5.c, (12) rgbimgmodule.c, and (13) stropmodule.c in Modules/; (14) bufferobject.c, (15) listobject.c, and (16) obmalloc.c in Objects/; (17) Parser/node.c; and (18) asdl.c, (19) ast.c, (20) bltinmodule.c, and (21) compile.c in Python/, as addressed by "checks for integer overflows, contributed by Google."

    Published: 14 Feb 2008
    7.2
    High

    CVE-2008-1078

    Last Modified: 23 Apr 2026

    expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.

    Published: 14 Feb 2008
    Unknown

    CVE-2007-5763

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-0401. Reason: This candidate is a reservation duplicate of CVE-2008-0401. Notes: All CVE users should reference CVE-2008-0401 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0774

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0769

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Livelink ECM 9.0.0 through 9.7.0 and possibly earlier does not set the charset, which allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0773

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0776

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0770

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the g_display_order cookie parameter.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0772

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the sid parameter in a view task.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0771

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0775

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in sboxDB.php in Simple Machines Forum (SMF) Shoutbox 1.14 through 1.16b allows remote attackers to inject arbitrary web script or HTML via strings to the shoutbox form that start with "&#", contain the desired script, and end with ";".

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0768

    Last Modified: 23 Apr 2026

    Multiple stack-based and heap-based buffer overflows in the Windows RPC components for IBM Informix Storage Manager (ISM), as used in Informix Dynamic Server (IDS) 10.00.xC8 and earlier and 11.10.xC2 and earlier, allow attackers to execute arbitrary code via crafted XDR requests.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0757

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in MercuryBoard 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the message parameter (aka the message text area), which leads to an injection in the messenger during private message (PM) preview. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0758

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a "..\" (dot dot backslash) sequence in the filename.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0759

    Last Modified: 23 Apr 2026

    ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allows remote attackers to cause a denial of service (daemon crash) via an invalid UAM field in a request to the Apple Filing Protocol (AFP) service on TCP port 548.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0760

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.0.4.0 and earlier, allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the URI. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-6483.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0764

    Last Modified: 23 Apr 2026

    Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0767

    Last Modified: 23 Apr 2026

    ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs" field is consistent with the packet length, which allows remote attackers to cause a denial of service (daemon crash) via a large integer in this field in a packet to the Service Location Protocol (SLP) service on UDP port 427, triggering an out-of-bounds read.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2007-6148

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to execute arbitrary code via an unspecified sequence of Real Time Message Protocol (RTMP) requests.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2007-6431

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allows remote attackers to "take control of the affected system" via unspecified vectors, a different issue than CVE-2007-6148 and CVE-2007-6149.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2007-6701

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP4 for Windows allow remote attackers to execute arbitrary code via long arguments to multiple unspecified RPC functions, aka Novell bug 287919, a different vulnerability than CVE-2007-2954.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0639

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the EnumPrinters function in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2, SP3, and SP4 for Windows allows remote attackers to execute arbitrary code via a crafted RPC request, aka Novell bug 353138, a different vulnerability than CVE-2006-5854. NOTE: this issue exists because of an incomplete fix for CVE-2007-6701.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0762

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the com_iomezun component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit action.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0763

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows remote attackers to execute arbitrary code via a long argument in a LICENSE command on TCP port 3114.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0765

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in artmedic webdesign weblog allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to artmedic_print.php and the (2) jahrneu parameter to index.php.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0766

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2007-6149

    Last Modified: 23 Apr 2026

    Multiple integer overflows in the Edge server in Adobe Flash Media Server 2 before 2.0.5, and Connect Enterprise Server 6 before SP3, allow remote attackers to execute arbitrary code via a Real Time Message Protocol (RTMP) message with a crafted integer field that is used for allocation.

    Published: 13 Feb 2008