CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-0761

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a players action.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0750

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0751

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to plugin/tag/.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0752

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show action.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0753

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL commands via the month parameter.

    Published: 13 Feb 2008
    4.3
    Medium

    CVE-2008-0749

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a calimero_webpage action.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0748

    Last Modified: 23 Apr 2026

    Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0746

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0745

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 13 Feb 2008
    9.3
    Critical

    CVE-2008-0747

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute arbitrary code via a long URL in a .asx file, a different vulnerability than CVE-2007-5487.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0754

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! allow remote attackers to execute arbitrary SQL commands via (1) the user_id parameter in a showuser action or (2) the category_id parameter in a viewcategorysrecipes action.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0755

    Last Modified: 23 Apr 2026

    Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; might allow remote attackers to execute arbitrary code via format string specifiers in the queue name in a request.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0756

    Last Modified: 23 Apr 2026

    The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1030 and earlier; Workstation 4.10.836 and earlier; and Standard 4.10.940 and earlier; allows remote attackers to cause a denial of service (daemon crash) via a connection that begins with (1) a "Send queue state" LPD command 3 or (2) a "Send queue state" LPD command 4.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0743

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the hlp parameter.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0744

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in user_login.asp in PreProjects.com Pre Hotels & Resorts Management System allows remote attackers to execute arbitrary SQL commands via the login page.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0742

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include arbitrary files via a .. (dot dot) in the (1) subpage parameter in (a) categories.inc.php, (b) news.inc.php, (c) other.inc.php, (d) permissions.inc.php, (e) templates.inc.php, and (f) users.inc.php in pnadmin/; and (2) the page parameter to (g) pnadmin/index.php. NOTE: vector 2 is only exploitable by administrators.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0733

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in CS Team Counter Strike Portals allows remote attackers to execute arbitrary SQL commands via the id parameter, as demonstrated using the downloads page.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0734

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the cuid cookie parameter to admin.php.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0735

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.

    Published: 13 Feb 2008
    5
    Medium

    CVE-2008-0736

    Last Modified: 23 Apr 2026

    admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attackers to obtain the path via a certain value of the FedExAccount parameter.

    Published: 13 Feb 2008
    2.1
    Low

    CVE-2008-0740

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.

    Published: 13 Feb 2008
    10
    Critical

    CVE-2008-0741

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0738

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idcust parameter to (a) ajax_getTiers.asp and (b) ajax_getCust.asp in ajax/, and the (2) tableName parameter to (c) ajax/ajax_tableFields.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0739

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and earlier 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the FedExAccount parameter.

    Published: 13 Feb 2008
    7.5
    High

    CVE-2008-0737

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x versions, allows remote attackers to execute arbitrary SQL commands via the helpfield parameter.

    Published: 13 Feb 2008
    6.9
    Medium

    CVE-2007-5757

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gain root privileges via a modified DB2INSTANCE environment variable that points to a malicious library. NOTE: this might be the same issue as CVE-2008-0697.

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0103

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka "Microsoft Office Execution Jump Vulnerability."

    Published: 12 Feb 2008
    10
    Critical

    CVE-2007-3676

    Last Modified: 23 Apr 2026

    IBM DB2 Universal Database (UDB) Administration Server (DAS) 8 before Fix Pack 16 and 9 before Fix Pack 4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via modified pointer values in unspecified remote administration requests, which triggers memory corruption or other invalid memory access. NOTE: this might be the same issue as CVE-2008-0698.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2007-0065

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted script request.

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2007-0216

    Last Modified: 23 Apr 2026

    wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section length headers, aka "Microsoft Works File Converter Input Validation Vulnerability."

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0076

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via crafted HTML layout combinations, aka "HTML Rendering Memory Corruption Vulnerability."

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0078

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in an ActiveX control (dxtmsft.dll) in Microsoft Internet Explorer 5.01, 6 SP1 and SP2, and 7 allows remote attackers to execute arbitrary code via a crafted image, aka "Argument Handling Memory Corruption Vulnerability."

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0104

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, aka "Publisher Memory Corruption Vulnerability."

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0109

    Last Modified: 23 Apr 2026

    Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and memory corruption.

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0105

    Last Modified: 23 Apr 2026

    Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter Index Table Vulnerability."

    Published: 12 Feb 2008
    8.8
    High

    CVE-2008-0077

    Last Modified: 23 Apr 2026

    Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0108

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft Works File Converter Field Length Vulnerability."

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0080

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the WebDAV Mini-Redirector in Microsoft Windows XP SP2, Server 2003 SP1 and SP2, and Vista allows remote attackers to execute arbitrary code via a crafted WebDAV response.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0102

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."

    Published: 12 Feb 2008
    2.1
    Low

    CVE-2008-0010

    Last Modified: 23 Apr 2026

    The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which allow local users to read from arbitrary kernel memory locations.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0075

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 through 6.0 allows remote attackers to execute arbitrary code via crafted inputs to ASP pages.

    Published: 12 Feb 2008
    7.8
    High

    CVE-2008-0084

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.

    Published: 12 Feb 2008
    4.6
    Medium

    CVE-2008-0730

    Last Modified: 23 Apr 2026

    The (1) Simplified Chinese, (2) Traditional Chinese, (3) Korean, and (4) Thai language input methods in Sun Solaris 10 create files and directories with weak permissions under (a) .iiim/le and (b) .Xlocale in home directories, which might allow local users to write to, or read from, the home directories of other users.

    Published: 12 Feb 2008
    7.2
    High

    CVE-2008-0074

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors related to file change notifications in the TPRoot, NNTPFile\Root, or WWWRoot folders.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0088

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Active Directory on Microsoft Windows 2000 and Windows Server 2003, and Active Directory Application Mode (ADAM) on XP and Server 2003, allows remote attackers to cause a denial of service (hang and restart) via a crafted LDAP request.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0731

    Last Modified: 23 Apr 2026

    The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow attackers to trigger the unconfining of an apparmored task.

    Published: 12 Feb 2008
    2.1
    Low

    CVE-2008-0732

    Last Modified: 23 Apr 2026

    The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.

    Published: 12 Feb 2008
    4.4
    Medium

    CVE-2008-0163

    Last Modified: 23 Apr 2026

    Linux kernel 2.6, when using vservers, allows local users to access resources of other vservers via a symlink attack in /proc.

    Published: 12 Feb 2008
    7.1
    High

    CVE-2008-0729

    Last Modified: 23 Apr 2026

    Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion and device crash) via certain JavaScript code that constructs a long string and an array containing long string elements, possibly a related issue to CVE-2006-3677. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0039

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mail in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary commands via a crafted file:// URL.

    Published: 12 Feb 2008