CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-0579

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in a list action.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0587

    Last Modified: 23 Apr 2026

    Buffer overflow in the uspchrp program in devices.chrp.base.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0588

    Last Modified: 23 Apr 2026

    Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

    Published: 5 Feb 2008
    4.9
    Medium

    CVE-2008-0589

    Last Modified: 23 Apr 2026

    The ps program in bos.rte.control in IBM AIX 5.2, 5.3, and 6.1 allows local users to obtain sensitive information via unspecified vectors.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2007-6700

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in cgi-bin/bgplg in the web interface for the BGPD daemon in OpenBSD 4.1 allows remote attackers to inject arbitrary web script or HTML via the cmd parameter.

    Published: 5 Feb 2008
    6.8
    Medium

    CVE-2008-0566

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/smarty.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path_to_public_program parameter.

    Published: 5 Feb 2008
    7.5
    High

    CVE-2008-0567

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) PPS/File.php, (2) Writer.php, and (3) PPS.php in excelwriter/; and (4) BIFFwriter.php, (5) Workbook.php, (6) Worksheet.php, and (7) Format.php in excelwriter/Writer/.

    Published: 5 Feb 2008
    10
    Critical

    CVE-2008-0568

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the IP-authentication feature in the Secure Site 5.x-1.0 and 4.7.x-1.0 module for Drupal allows remote attackers to gain the privileges of a user who has authenticated from behind the same proxy server as the attacker.

    Published: 5 Feb 2008
    6.4
    Medium

    CVE-2008-0569

    Last Modified: 23 Apr 2026

    The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors.

    Published: 5 Feb 2008
    5
    Medium

    CVE-2008-0570

    Last Modified: 23 Apr 2026

    The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0574

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in webSPELL 4.01.02 allows remote attackers to inject arbitrary web script or HTML via the sort parameter in a whoisonline action.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0575

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin/admincenter.php in webSPELL 4.01.02 allows remote attackers to assign the superadmin privilege level to arbitrary accounts as administrators via an "update member" action.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0578

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Feb 2008
    6.8
    Medium

    CVE-2008-0572

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP code via a URL in the MM_GLOBALS[home] parameter to (1) acweb/admin_index.php; and (2) ask.inc.php, (3) learn.inc.php, (4) manage.inc.php, (5) mind.inc.php, and (6) sensory.inc.php in include/.

    Published: 5 Feb 2008
    6.8
    Medium

    CVE-2008-0565

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Feb 2008
    7.2
    High

    CVE-2008-0573

    Last Modified: 23 Apr 2026

    IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0576

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors that write to summary table pages.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0571

    Last Modified: 23 Apr 2026

    The point moderation form in the Userpoints 4.7.x before 4.7.x-2.3, 5.x-2 before 5.x-2.16, and 5.x-3 before 5.x-3.3 module for Drupal does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and manipulate points.

    Published: 5 Feb 2008
    6.4
    Medium

    CVE-2008-0577

    Last Modified: 23 Apr 2026

    The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier in the 4.7.x-2.x series, and 4.7.x-1.6 and earlier in the 4.7.x-1.x series for Drupal (1) does not restrict the extensions of attached files when the Upload module is enabled for issue nodes, which allows remote attackers to upload and possibly execute arbitrary files; and (2) accepts the .html extension within the bundled file-upload functionality, which allows remote attackers to upload files containing arbitrary web script or HTML.

    Published: 5 Feb 2008
    10
    Critical

    CVE-2008-0657

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.

    Published: 5 Feb 2008
    10
    Critical

    CVE-2007-5602

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in SwiftView Viewer before 8.3.5, as used by SwiftView and SwiftSend, allow remote attackers to execute arbitrary code via unspecified vectors to the (1) svocx.ocx ActiveX control or the (2) npsview.dll plugin for Mozilla and Firefox.

    Published: 5 Feb 2008
    6.4
    Medium

    CVE-2008-0664

    Last Modified: 23 Apr 2026

    The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog users via unknown vectors.

    Published: 5 Feb 2008
    4.3
    Medium

    CVE-2008-0178

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Published: 4 Feb 2008
    2.6
    Low

    CVE-2008-0179

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2008-0182

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated users via the Shutdown message.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2008-0180

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field in a User Profile.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2008-0181

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2008-0563

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to perform unspecified actions as unspecified authenticated users via the User-Agent HTTP header, which is used when composing Forgot Password e-mail messages in HTML format.

    Published: 4 Feb 2008
    6.8
    Medium

    CVE-2008-0386

    Last Modified: 23 Apr 2026

    Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2008-0558

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Uniwin eCart Professional before 2.0.16 allows remote attackers to inject arbitrary web script or HTML via the rp parameter to cartView.asp and unspecified other components. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 4 Feb 2008
    5
    Medium

    CVE-2008-0559

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Nilson's Blogger 0.11 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the permalink parameter in core.php, accessed through index.php; and (2) the thispost parameter in comments.php.

    Published: 4 Feb 2008
    6.8
    Medium

    CVE-2008-0560

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in cforms-css.php in Oliver Seidel cforms (contactforms), a Wordpress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the tm parameter. NOTE: CVE disputes this issue for 7.3, since there is no tm parameter, and the code exits with a fatal error due to a call to an undefined function

    Published: 4 Feb 2008
    7.5
    High

    CVE-2008-0561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Arthur Konze AkoGallery (com_akogallery) 2.5 beta component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 4 Feb 2008
    7.5
    High

    CVE-2008-0562

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Restaurant (com_restaurant) 1.0 component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 4 Feb 2008
    4.3
    Medium

    CVE-2007-6699

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the AIM PicEditor 9.5.1.8 ActiveX control in YGPPicEdit.dll in AOL You've Got Pictures (YGP) Picture Editor allow remote attackers to cause a denial of service (browser crash) via a long string in the (1) DisplayName, (2) FinalSavePath, (3) ForceSaveTo, (4) HiddenControls, (5) InitialEditorScreen, (6) Locale, (7) Proxy, and (8) UserAgent property values.

    Published: 4 Feb 2008
    7.5
    High

    CVE-2008-0557

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.

    Published: 4 Feb 2008
    7.5
    High

    CVE-2008-0486

    Last Modified: 23 Apr 2026

    Array index vulnerability in libmpdemux/demux_audio.c in MPlayer 1.0rc2 and SVN before r25917, and possibly earlier versions, as used in Xine-lib 1.1.10, might allow remote attackers to execute arbitrary code via a crafted FLAC tag, which triggers a buffer overflow.

    Published: 4 Feb 2008
    4.9
    Medium

    CVE-2008-0807

    Last Modified: 23 Apr 2026

    lib/Driver/sql.php in Turba 2 (turba2) Contact Manager H3 2.1.x before 2.1.7 and 2.2.x before 2.2-RC3, as used in products such as Horde Groupware before 1.0.4 and Horde Groupware Webmail Edition before 1.0.5, does not properly check access rights, which allows remote authenticated users to modify address data via a modified object_id parameter to edit.php, as demonstrated by modifying a personal address book entry when there is write access to a shared address book.

    Published: 4 Feb 2008
    5.5
    Medium

    CVE-2008-7316

    Last Modified: 12 Apr 2025

    mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault for an iovec of nonzero length.

    Published: 2 Feb 2008
    4.9
    Medium

    CVE-2008-1615

    Last Modified: 23 Apr 2026

    Linux kernel 2.6.18, and possibly other versions, when running on AMD64 architectures, allows local users to cause a denial of service (crash) via certain ptrace calls.

    Published: 2 Feb 2008
    4.3
    Medium

    CVE-2008-0547

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably earlier 4.x and 3.x versions, allows remote attackers to inject arbitrary web script or HTML via the helpfield parameter.

    Published: 1 Feb 2008
    4.3
    Medium

    CVE-2008-0539

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in dms/policy/rep_request.php in F5 BIG-IP Application Security Manager (ASM) 9.4.3 allows remote attackers to inject arbitrary web script or HTML via the report_type parameter.

    Published: 1 Feb 2008
    5
    Medium

    CVE-2008-0549

    Last Modified: 23 Apr 2026

    Integer overflow in the OggHeaderParse function in Steamcast 0.9.75 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via a long Ogg tag.

    Published: 1 Feb 2008
    5
    Medium

    CVE-2008-0548

    Last Modified: 23 Apr 2026

    Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) via a large integer in the Content-Length HTTP header, which triggers a NULL dereference when malloc fails.

    Published: 1 Feb 2008
    4.3
    Medium

    CVE-2008-0541

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers to inject arbitrary web script or HTML via the (1) open and (2) date_show parameters.

    Published: 1 Feb 2008
    4.3
    Medium

    CVE-2008-0540

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in trixbox 2.4.2.0 allow remote attackers to inject arbitrary web script or HTML via the query string to index.php in (1) user/ or (2) maint/.

    Published: 1 Feb 2008
    7.5
    High

    CVE-2008-0545

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) uri parameter to (a) yui-menu.tpl.php, (b) simple.tpl.php, and (c) advanced.tpl.php in dispatcher/framework/; and the (2) page parameter to (d) yui-menu.php, (e) simple.php, and (f) advanced.php in dispatcher/framework/, different vectors than CVE-2008-0521.

    Published: 1 Feb 2008
    2.1
    Low

    CVE-2007-6696

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.1.6 allow remote attackers to inject arbitrary web script or HTML via (1) an event description, (2) the query string to pref.php, and (3) the adv parameter to search.php. NOTE: vector 1 requires user authentication.

    Published: 1 Feb 2008
    5
    Medium

    CVE-2008-0542

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 1 Feb 2008
    7.5
    High

    CVE-2008-0543

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Pre Dynamic Institution allow remote attackers to execute arbitrary SQL commands via the (1) sloginid and (2) spass parameters to (a) login.asp and (b) siteadmin/login.asp. NOTE: some of these details are obtained from third party information.

    Published: 1 Feb 2008