CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2008-0680

    Last Modified: 23 Apr 2026

    SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP SET request.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0670

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detalhe action.

    Published: 12 Feb 2008
    7.5
    High

    CVE-2008-0695

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL commands via the topicid parameter in a showtopic action.

    Published: 12 Feb 2008
    4.3
    Medium

    CVE-2008-0700

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in Crux Software CruxCMS 3.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 12 Feb 2008
    5
    Medium

    CVE-2008-0703

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) permalink or (2) section parameter to index.php, possibly involving includes/entries.inc.php and other files included by index.php.

    Published: 12 Feb 2008
    3.6
    Low

    CVE-2008-0665

    Last Modified: 23 Apr 2026

    wml_backend/p1_ipp/ipp.src in Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on the ipp.$$.tmp temporary file.

    Published: 11 Feb 2008
    3.6
    Low

    CVE-2008-0666

    Last Modified: 23 Apr 2026

    Website META Language (WML) 2.0.11 allows local users to overwrite arbitrary files via a symlink attack on (1) the /tmp/pe.tmp.$$ temporary file used by wml_contrib/wmg.cgi and (2) temporary files used by wml_backend/p3_eperl/eperl_sys.c.

    Published: 11 Feb 2008
    5
    Medium

    CVE-2007-5333

    Last Modified: 23 Apr 2026

    Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.

    Published: 11 Feb 2008
    9.3
    Critical

    CVE-2008-0726

    Last Modified: 23 Apr 2026

    Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.

    Published: 11 Feb 2008
    7.2
    High

    CVE-2008-0600

    Last Modified: 23 Apr 2026

    The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer before dereference, which allows local users to gain root privileges via crafted arguments in a vmsplice system call, a different vulnerability than CVE-2008-0009 and CVE-2008-0010.

    Published: 9 Feb 2008
    9.3
    Critical

    CVE-2008-0043

    Last Modified: 23 Apr 2026

    Format string vulnerability in Apple iPhoto before 7.1.2 allows remote attackers to execute arbitrary code via photocast subscriptions.

    Published: 8 Feb 2008
    10
    Critical

    CVE-2008-0659

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.

    Published: 8 Feb 2008
    6.8
    Medium

    CVE-2008-0661

    Last Modified: 23 Apr 2026

    Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file with a long URI. NOTE: this might be the same issue as CVE-2004-1569.

    Published: 8 Feb 2008
    2.1
    Low

    CVE-2008-0663

    Last Modified: 23 Apr 2026

    Novell Challenge Response Client (LCM) 2.7.5 and earlier, as used with Novell Client for Windows 4.91 SP4, allows users with physical access to a locked system to obtain contents of the clipboard by pasting the contents into the Challenge Question field.

    Published: 8 Feb 2008
    10
    Critical

    CVE-2008-0640

    Last Modified: 23 Apr 2026

    Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.

    Published: 8 Feb 2008
    9.3
    Critical

    CVE-2008-0660

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties.

    Published: 8 Feb 2008
    7.5
    High

    CVE-2008-0214

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via unknown vectors.

    Published: 8 Feb 2008
    7.8
    High

    CVE-2008-0662

    Last Modified: 23 Apr 2026

    The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.

    Published: 8 Feb 2008
    6.2
    Medium

    CVE-2007-5666

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.

    Published: 8 Feb 2008
    7.2
    High

    CVE-2008-0007

    Last Modified: 23 Apr 2026

    Linux kernel before 2.6.22.17, when using certain drivers that register a fault handler that does not perform range checks, allows local users to access kernel memory via an out-of-range offset.

    Published: 8 Feb 2008
    4.3
    Medium

    CVE-2008-0667

    Last Modified: 23 Apr 2026

    The DOC.print function in the Adobe JavaScript API, as used by Adobe Acrobat and Reader before 8.1.2, allows remote attackers to configure silent non-interactive printing, and trigger the printing of an arbitrary number of copies of a document. NOTE: this issue might be subsumed by CVE-2008-0655.

    Published: 8 Feb 2008
    7.8
    High

    CVE-2007-5659

    Last Modified: 21 Apr 2026

    Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.

    Published: 8 Feb 2008
    9.3
    Critical

    CVE-2007-5663

    Last Modified: 23 Apr 2026

    Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file that calls an insecure JavaScript method in the EScript.api plug-in. NOTE: this issue might be subsumed by CVE-2008-0655.

    Published: 8 Feb 2008
    4.3
    Medium

    CVE-2007-6286

    Last Modified: 23 Apr 2026

    Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.

    Published: 8 Feb 2008
    5.8
    Medium

    CVE-2008-0002

    Last Modified: 23 Apr 2026

    Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.

    Published: 8 Feb 2008
    7.8
    High

    CVE-2008-0177

    Last Modified: 23 Apr 2026

    The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check the return value of the m_pulldown function, which allows remote attackers to cause a denial of service (system crash) via an IPv6 packet with an IPComp header.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0213

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in a certain ActiveX control for HP Virtual Rooms (HPVR) 6 and earlier allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 7 Feb 2008
    10
    Critical

    CVE-2008-0457

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0645

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) config/conf-activation.php, (2) menu/item.php, and (3) modules/conf_modules.php in admin/system/; and (4) system/login.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Feb 2008
    7.8
    High

    CVE-2008-0646

    Last Modified: 23 Apr 2026

    The bdecode_recursive function in include/libtorrent/bencode.hpp in Rasterbar Software libtorrent before 0.12.1, as used in Deluge before 0.5.8.3 and other products, allows context-dependent attackers to cause a denial of service (stack exhaustion and crash) via a crafted bencoded message.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0651

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Pedro Santana Codice CMS allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0652

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the filecatid parameter in a selectfolder action.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0653

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showYNews action.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0654

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Azucar CMS 1.3 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the _VIEW (view) parameter to (1) index.php, (2) html/sitio/index.php, or (3) src/sistema/vistas/template/tpl_inicio.php.

    Published: 7 Feb 2008
    6.8
    Medium

    CVE-2008-0648

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenSiteAdmin 0.9.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) indexFooter.php; and (2) DatabaseManager.php, (3) FieldManager.php, (4) Filter.php, (5) Form.php, (6) FormManager.php, (7) LoginManager.php, and (8) Filters/SingleFilter.php in scripts/classes/.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0649

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to execute arbitrary SQL commands via the link_id parameter.

    Published: 7 Feb 2008
    7.5
    High

    CVE-2008-0650

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login.php in Simple OS CMS 0.1c beta allows remote attackers to execute arbitrary SQL commands via the username field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Feb 2008
    10
    Critical

    CVE-2008-0656

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in dmclTrace.jsp in EMC Documentum Administrator 5.3.0.313 and Webtop 5.3.0.317 allows remote attackers to overwrite arbitrary files via the filename attribute.

    Published: 7 Feb 2008
    10
    Critical

    CVE-2008-0647

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the (1) hgs_startGame and (2) hgs_startNotify methods, as exploited in the wild as of February 2008. NOTE: some of these details are obtained from third party information.

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0415

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to execute script outside of the sandbox and conduct cross-site scripting (XSS) attacks via multiple vectors including the XMLDocument.load function, aka "JavaScript privilege escalation bugs."

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0416

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0417

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0418

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8, when using "flat" addons, allows remote attackers to read arbitrary Javascript, image, and stylesheet files via the chrome: URI scheme, as demonstrated by stealing session information from sessionstore.js.

    Published: 7 Feb 2008
    9.3
    Critical

    CVE-2008-0419

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows remote attackers to steal navigation history and cause a denial of service (crash) via images in a page that uses designMode frames, which triggers memory corruption related to resize handles.

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0593

    Last Modified: 23 Apr 2026

    Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0414

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to trick the user into uploading arbitrary files via label tags that shift focus to a file input field, aka "focus spoofing."

    Published: 7 Feb 2008
    2.1
    Low

    CVE-2008-0009

    Last Modified: 23 Apr 2026

    The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain userspace pointer before dereference, which might allow local users to access arbitrary kernel memory locations.

    Published: 7 Feb 2008
    9.3
    Critical

    CVE-2008-0412

    Last Modified: 23 Apr 2026

    The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.

    Published: 7 Feb 2008
    9.3
    Critical

    CVE-2008-0413

    Last Modified: 23 Apr 2026

    The JavaScript engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via (1) a large switch statement, (2) certain uses of watch and eval, (3) certain uses of the mousedown event listener, and other vectors.

    Published: 7 Feb 2008
    9.3
    Critical

    CVE-2008-0420

    Last Modified: 23 Apr 2026

    modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.

    Published: 7 Feb 2008