CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-0040

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NFS in Apple Mac OS X 10.5 through 10.5.1 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via unknown vectors related to mbuf chains that trigger memory corruption.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0318

    Last Modified: 23 Apr 2026

    Integer overflow in the cli_scanpe function in libclamav in ClamAV before 0.92.1, as used in clamd, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Petite packed PE file, which triggers a heap-based buffer overflow.

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0636

    Last Modified: 23 Apr 2026

    Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0728

    Last Modified: 23 Apr 2026

    The unmew11 function in libclamav/mew.c in libclamav in ClamAV before 0.92.1 has unknown impact and attack vectors that trigger "heap corruption."

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0042

    Last Modified: 23 Apr 2026

    Argument injection vulnerability in Terminal.app in Terminal in Apple Mac OS X 10.4.11 and 10.5 through 10.5.1 allows remote attackers to execute arbitrary code via unspecified URL schemes.

    Published: 12 Feb 2008
    1.9
    Low

    CVE-2008-0038

    Last Modified: 23 Apr 2026

    Launch Services in Apple Mac OS X 10.5 through 10.5.1 allows an uninstalled application to be launched if it is in a Time Machine backup, which might allow local users to bypass intended security restrictions or exploit vulnerabilities in the application.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0037

    Last Modified: 23 Apr 2026

    X11 in Apple Mac OS X 10.5 through 10.5.1 does not properly handle when the "Allow connections from network client" preference is disabled, which allows remote attackers to bypass intended access restrictions and connect to the X server.

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0041

    Last Modified: 23 Apr 2026

    Parental Controls in Apple Mac OS X 10.5 through 10.5.1 contacts www.apple.com "when a website is unblocked," which allows remote attackers to determine when a system is running Parental Controls.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0716

    Last Modified: 23 Apr 2026

    The agent in Symantec Altiris Notification Server before 6.0 SP3 R7 allows local users to gain privileges via a "Shatter" style attack.

    Published: 12 Feb 2008
    4.7
    Medium

    CVE-2008-0718

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the USB Mouse STREAMS module (usbms) in Sun Solaris 9 and 10, when 64-bit mode is enabled, allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0719

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Online Merchant 2.2 allows remote attackers to execute arbitrary SQL commands via the testimonial_id parameter.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0714

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL commands via the username parameter in a lost_password_go action.

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0715

    Last Modified: 23 Apr 2026

    Buffer overflow in ACDSee Photo Manager 8.1, 9.0, and 10.0 allows user-assisted remote attackers to execute arbitrary code via a malformed XBM file. NOTE: this might be the same as CVE-2007-6009.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0215

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0720

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Webmin 1.370 and 1.390 and Usermin 1.300 and 1.320 allows remote attackers to inject arbitrary web script or HTML via the search parameter to webmin_search.cgi (aka the search section), and possibly other components accessed through a "search box" or "open file box." NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0721

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to execute arbitrary SQL commands via the gid parameter.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0722

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter in a pagetool_search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0723

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the hash parameter in an admin action to index.php, a different vulnerability than CVE-2006-2208.1.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0725

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in the (1) FTP service and (2) administration service in Titan FTP Server 6.0.5.549 allow remote attackers to cause a denial of service (daemon hang) and possibly execute arbitrary code via a long command. NOTE: the USER and PASS commands for the FTP service are covered by CVE-2008-0702.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0717

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Caching Proxy (CP) 5.1 through 6.1 in IBM WebSphere Edge Server, when CGI mapping rules are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors that trigger injection into an error response.

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0724

    Last Modified: 23 Apr 2026

    The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0673

    Last Modified: 23 Apr 2026

    TinTin++ 1.97.9 and WinTin++ 1.97.9 open files on the basis of an inbound file-transfer request, before the user has an opportunity to decline the request, which allows remote attackers to truncate arbitrary files in the top level of a home directory.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0675

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0676

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in A-Blog 2 allows remote attackers to inject arbitrary web script or HTML via the words parameter.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0677

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in blog.php in A-Blog 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in a news action.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0683

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0684

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to inject arbitrary web script or HTML via the CatID parameter.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0685

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in ViewCat.php in iTechClassifieds 3.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0686

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0681

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via the product_id parameter, as demonstrated by a shop/flypage action.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0682

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0690

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a viewcat action.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0692

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.

    Published: 12 Feb 2008
    7.8
    High

    CVE-2008-0693

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in PQCore.exe in Print Manager Plus 2008 Client Billing and Authentication 7.0.127.16 allows remote attackers to cause a denial of service (service outage) via a series of long packets to TCP port 48101.

    Published: 12 Feb 2008
    7.2
    High

    CVE-2008-0697

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

    Published: 12 Feb 2008
    7.8
    High

    CVE-2008-0698

    Last Modified: 23 Apr 2026

    Buffer overflow in the DAS server in IBM DB2 UDB before 8.2 Fixpak 16 has unknown attack vectors, and an impact probably involving "invalid memory access."

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0701

    Last Modified: 23 Apr 2026

    ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0696

    Last Modified: 23 Apr 2026

    IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0669

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.cgi in Sift Unity allows remote attackers to inject arbitrary web script or HTML via the qt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0679

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in BlogPHP 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0687

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in siteadmin/editor_files/includes/load_message.php in the Youtube Clone Script allows remote attackers to inject arbitrary web script or HTML via the lang[please_wait] parameter.

    Published: 12 Feb 2008
    9.3
    Critical

    CVE-2008-0702

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of service (daemon crash or hang) and possibly execute arbitrary code via a long argument to the (1) USER or (2) PASS command, different vectors than CVE-2004-1641.

    Published: 12 Feb 2008
    10
    Critical

    CVE-2008-0671

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to execute arbitrary code via a long chat message, related to conversion from LF to CRLF.

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0672

    Last Modified: 23 Apr 2026

    The process_chat_input function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attackers to cause a denial of service (application crash) via a YES message without a newline character, which triggers a NULL dereference.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0688

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in catalog.php in Smartscript Domain Trader 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a viewcategory action.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0689

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a show_category action.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0691

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in admin_panel.php in the Simon Elvery WP-Footnotes 2.2 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wp_footnotes_current_settings[priority], (2) wp_footnotes_current_settings[style_rules], (3) wp_footnotes_current_settings[pre_footnotes], and (4) wp_footnotes_current_settings[post_footnotes] parameters.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0694

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.

    Published: 12 Feb 2008
    9
    Critical

    CVE-2008-0699

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the ADMIN_SP_C procedure (SYSPROC.ADMIN_SP_C) in IBM DB2 UDB before 8.2 Fixpak 16, 9.1 before FP4a, and 9.5 before FP1 allows remote authenticated users to execute arbitrary code via unspecified attack vectors.

    Published: 12 Feb 2008
    6.8
    Medium

    CVE-2008-0678

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a page action.

    Published: 12 Feb 2008