CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2008-0591

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".

    Published: 7 Feb 2008
    4.3
    Medium

    CVE-2008-0592

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8 allows user-assisted remote attackers to cause a denial of service via a plain .txt file with a "Content-Disposition: attachment" and an invalid "Content-Type: plain/text," which prevents Firefox from rendering future plain text files within the browser.

    Published: 7 Feb 2008
    5
    Medium

    CVE-2008-0594

    Last Modified: 23 Apr 2026

    Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.

    Published: 7 Feb 2008
    4
    Medium

    CVE-2008-0658

    Last Modified: 23 Apr 2026

    slapd/back-bdb/modrdn.c in the BDB backend for slapd in OpenLDAP 2.3.39 allows remote authenticated users to cause a denial of service (daemon crash) via a modrdn operation with a NOOP (LDAP_X_NO_OPERATION) control, a related issue to CVE-2007-6698.

    Published: 7 Feb 2008
    7.8
    High

    CVE-2008-0212

    Last Modified: 23 Apr 2026

    ovtopmd in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allows remote attackers to cause a denial of service (crash) via a crafted TCP request that triggers an out-of-bounds memory access.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0623

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0624

    Last Modified: 23 Apr 2026

    Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0625

    Last Modified: 23 Apr 2026

    Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.

    Published: 6 Feb 2008
    Unknown

    CVE-2008-0626

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6303. Reason: This candidate is a duplicate of CVE-2007-6303. Notes: All CVE users should reference CVE-2007-6303 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Feb 2008
    Unknown

    CVE-2008-0627

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6304. Reason: This candidate is a duplicate of CVE-2007-6304. Notes: All CVE users should reference CVE-2007-6304 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0631

    Last Modified: 23 Apr 2026

    Multiple ActiveX controls in MailBee.dll in MailBee Objects 5.5 allow remote attackers to (1) overwrite arbitrary files via the SaveToDisk method, or (2) modify files via the AddStringToFile method.

    Published: 6 Feb 2008
    9.3
    Critical

    CVE-2008-0632

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root directory.

    Published: 6 Feb 2008
    6
    Medium

    CVE-2008-0633

    Last Modified: 23 Apr 2026

    Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to cause a denial of service (exception) via a user name with a large number of quotes, which triggers the overflow during escaping.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0634

    Last Modified: 23 Apr 2026

    Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo ActiveSquare6, allows remote attackers to execute arbitrary code via a long argument to the Install method, a different vulnerability than CVE-2008-0551.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0635

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the delivery engine in Openads 2.4.0 through 2.4.2 allows remote attackers to execute arbitrary PHP code via unknown vectors.

    Published: 6 Feb 2008
    6.8
    Medium

    CVE-2008-0630

    Last Modified: 23 Apr 2026

    Buffer overflow in url.c in MPlayer 1.0rc2 and SVN before r25823 allows remote attackers to execute arbitrary code via a crafted URL that prevents the IPv6 parsing code from setting a pointer to NULL, which causes the buffer to be reused by the unescape code.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0629

    Last Modified: 23 Apr 2026

    Buffer overflow in stream_cddb.c in MPlayer 1.0rc2 and SVN before r25824 allows remote user-assisted attackers to execute arbitrary code via a CDDB database entry containing a long album title.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0603

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the listid parameter in a viewlist task.

    Published: 6 Feb 2008
    6.8
    Medium

    CVE-2008-0604

    Last Modified: 23 Apr 2026

    The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0605

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0609

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in DivideConcept VHD Web Pack 2.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

    Published: 6 Feb 2008
    9.3
    Critical

    CVE-2008-0610

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0611

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0612

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 6 Feb 2008
    5
    Medium

    CVE-2008-0613

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.

    Published: 6 Feb 2008
    4
    Medium

    CVE-2008-0615

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. (dot dot) in the (1) folder and (2) file parameters.

    Published: 6 Feb 2008
    6.5
    Medium

    CVE-2008-0616

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via unspecified vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0617

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter to wp-admin/admin.php, or the (2) messagefield parameter in the guestbook page, and the (3) title parameter in the messagearea.

    Published: 6 Feb 2008
    9.3
    Critical

    CVE-2008-0619

    Last Modified: 23 Apr 2026

    Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (persistent crash) via a long URI in a .M3U file.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0622

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0607

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) 2.5.3 component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the catid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Feb 2008
    4.3
    Medium

    CVE-2008-0618

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) gbname, (2) gbemail, (3) gburl, and (4) gbmsg parameters to unspecified programs. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0621

    Last Modified: 23 Apr 2026

    Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary code via long arguments to the (1) 0x01, (2) 0x02, (3) 0x03, (4) 0x04, and (5) 0x05 LPD commands.

    Published: 6 Feb 2008
    6.8
    Medium

    CVE-2008-0602

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the class_name parameter.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0601

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Published: 6 Feb 2008
    5
    Medium

    CVE-2008-0608

    Last Modified: 23 Apr 2026

    The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0606

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter.

    Published: 6 Feb 2008
    7.5
    High

    CVE-2008-0614

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL commands via the pic parameter in a showpic action.

    Published: 6 Feb 2008
    10
    Critical

    CVE-2008-0620

    Last Modified: 23 Apr 2026

    SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to cause a denial of service (crash) via a 0x53 LPD command, which causes the server to terminate.

    Published: 6 Feb 2008
    8.8
    High

    CVE-2008-0655

    Last Modified: 21 Apr 2026

    Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.

    Published: 6 Feb 2008
    9.3
    Critical

    CVE-2008-0485

    Last Modified: 23 Apr 2026

    Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom tag.

    Published: 5 Feb 2008
    9
    Critical

    CVE-2008-0590

    Last Modified: 23 Apr 2026

    Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long opendir command.

    Published: 5 Feb 2008
    2.1
    Low

    CVE-2007-6340

    Last Modified: 23 Apr 2026

    Geert Moernaut LSrunasE 1.0 and Supercrypt 1.0 use the RC4 stream cipher without constructing a unique initialization vector (IV), which makes it easier for local users to obtain cleartext passwords.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0582

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.1 through 3.6.0.244 on Windows allows remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Full Name field of a reviewer of a business item entry, accessible through (1) the SkypeFind dialog and (2) a skype:?skypefind URI for the skype: URI handler.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0584

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs.

    Published: 5 Feb 2008
    6.6
    Medium

    CVE-2008-0585

    Last Modified: 23 Apr 2026

    sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "alter the behavior of" this client by overwriting these files.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0586

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) lchangevg, (2) ldeletepv, (3) putlvodm, (4) lvaryoffvg, and (5) lvgenminor programs in bos.rte.lvm; and the (6) tellclvmd program in bos.clvm.enh.

    Published: 5 Feb 2008
    2.1
    Low

    CVE-2008-0580

    Last Modified: 23 Apr 2026

    Geert Moernaut LSrunasE and Supercrypt use an encryption key composed of an SHA1 hash of a fixed string embedded in the executable file, which makes it easier for local users to obtain this key without reverse engineering.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0581

    Last Modified: 23 Apr 2026

    Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batch file that specifies this password in the /password switch and specifies an arbitrary program in the /command switch.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0583

    Last Modified: 23 Apr 2026

    Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via the Description and unspecified other metadata fields of a Metacafe movie submitted by Metacafe Pro to the Skype video gallery, accessible through a search within the (1) "Add video to chat" or (2) "Add video to mood" dialog, a different vector than CVE-2008-0454.

    Published: 5 Feb 2008