CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-0376

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfile parameter.

    Published: 22 Jan 2008
    4.9
    Medium

    CVE-2008-0384

    Last Modified: 23 Apr 2026

    OpenBSD 4.2 allows local users to cause a denial of service (kernel panic) by calling the SIOCGIFRTLABEL IOCTL on an interface that does not have a route label, which triggers a NULL pointer dereference when the return value from the rtlabel_id2name function is not checked.

    Published: 22 Jan 2008
    10
    Critical

    CVE-2008-0065

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.

    Published: 22 Jan 2008
    9.3
    Critical

    CVE-2008-0379

    Last Modified: 23 Apr 2026

    Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the SelectedSession method, which triggers a buffer overflow.

    Published: 22 Jan 2008
    7.5
    High

    CVE-2008-0373

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.

    Published: 22 Jan 2008
    10
    Critical

    CVE-2008-0375

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the password and obtain administrative access via unspecified vectors.

    Published: 22 Jan 2008
    6.8
    Medium

    CVE-2008-0378

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in SocksCap 2.40-051231 and earlier, when "Resolve all names remotely" is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hostname.

    Published: 22 Jan 2008
    7.5
    High

    CVE-2008-0382

    Last Modified: 23 Apr 2026

    Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via the sortby parameter to (1) forumdisplay.php or (2) a results action in search.php.

    Published: 22 Jan 2008
    7.5
    High

    CVE-2008-0383

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyBB 1.2.10 and earlier allow remote moderators and administrators to execute arbitrary SQL commands via (1) the mergepost parameter in a do_mergeposts action, (2) rid parameter in an allreports action, or (3) threads parameter in a do_multimovethreads action to (a) moderation.php; or (4) gid parameter to (b) admin/usergroups.php.

    Published: 22 Jan 2008
    7.5
    High

    CVE-2008-0374

    Last Modified: 23 Apr 2026

    OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remote attackers to obtain the administrative password by connecting to TCP port 5548 or 7777.

    Published: 22 Jan 2008
    4.3
    Medium

    CVE-2008-0381

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Mahara before 0.9.1 has unknown impact and remote attack vectors, probably related to cross-site scripting (XSS) in uploaded files.

    Published: 22 Jan 2008
    2.6
    Low

    CVE-2008-0456

    Last Modified: 23 Apr 2026

    CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by uploading a file with a multi-line name containing HTTP header sequences and a file extension, which leads to injection within a (1) "406 Not Acceptable" or (2) "300 Multiple Choices" HTTP response when the extension is omitted in a request for the file.

    Published: 22 Jan 2008
    6.8
    Medium

    CVE-2007-4770

    Last Modified: 23 Apr 2026

    libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.

    Published: 22 Jan 2008
    9.3
    Critical

    CVE-2007-4771

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

    Published: 22 Jan 2008
    5
    Medium

    CVE-2007-4850

    Last Modified: 23 Apr 2026

    curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary files via a file:// request containing a \x00 sequence, a different vulnerability than CVE-2006-2563.

    Published: 22 Jan 2008
    6.9
    Medium

    CVE-2007-4998

    Last Modified: 23 Apr 2026

    cp, when running with an option to preserve symlinks on multiple OSes, allows local, user-assisted attackers to overwrite arbitrary files via a symlink attack using crafted directories containing multiple source files that are copied to the same destination.

    Published: 22 Jan 2008
    8.5
    High

    CVE-2007-6415

    Last Modified: 23 Apr 2026

    scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.

    Published: 21 Jan 2008
    5
    Medium

    CVE-2008-0782

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the MOIN_ID user ID in a cookie for a userform action. NOTE: this issue can be leveraged for PHP code execution via the quicklinks parameter.

    Published: 20 Jan 2008
    4.3
    Medium

    CVE-2007-6720

    Last Modified: 23 Apr 2026

    libmikmod 3.1.9 through 3.2.0, as used by MikMod, SDL-mixer, and possibly other products, relies on the channel count of the last loaded song, rather than the currently playing song, for certain playback calculations, which allows user-assisted attackers to cause a denial of service (application crash) by loading multiple songs (aka MOD files) with different numbers of channels.

    Published: 19 Jan 2008
    7.2
    High

    CVE-2008-0368

    Last Modified: 23 Apr 2026

    onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.

    Published: 18 Jan 2008
    6.9
    Medium

    CVE-2008-0369

    Last Modified: 23 Apr 2026

    Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.

    Published: 18 Jan 2008
    5
    Medium

    CVE-2008-0367

    Last Modified: 23 Apr 2026

    Mozilla Firefox 2.0.0.11, 3.0b2, and possibly earlier versions, when prompting for HTTP Basic Authentication, displays the site requesting the authentication after the Realm text, which might make it easier for remote HTTP servers to conduct phishing and spoofing attacks.

    Published: 18 Jan 2008
    7.2
    High

    CVE-2008-0366

    Last Modified: 23 Apr 2026

    CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments.

    Published: 18 Jan 2008
    5
    Medium

    CVE-2008-0364

    Last Modified: 23 Apr 2026

    Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cause a denial of service (application crash) via a long Unicode string representing a client version identifier.

    Published: 18 Jan 2008
    7.2
    High

    CVE-2008-0365

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via crafted arguments to (1) IOCTL functions in the Firewall module or (2) SSDT hook handler functions in the Registry module.

    Published: 18 Jan 2008
    7.5
    High

    CVE-2008-0353

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2008
    4.3
    Medium

    CVE-2008-0354

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim.

    Published: 18 Jan 2008
    7.5
    High

    CVE-2008-0355

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.

    Published: 18 Jan 2008
    10
    Critical

    CVE-2008-0356

    Last Modified: 23 Apr 2026

    Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code via an invalid size value in a packet to TCP port 2512 or 2513.

    Published: 18 Jan 2008
    4.3
    Medium

    CVE-2008-0359

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) index.php in photo/.

    Published: 18 Jan 2008
    7.5
    High

    CVE-2008-0360

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user parameter to action.php, or (3) the field parameter to admin/plugins/table/index.php.

    Published: 18 Jan 2008
    4.3
    Medium

    CVE-2008-0361

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabla parameter.

    Published: 18 Jan 2008
    4.3
    Medium

    CVE-2008-0362

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.

    Published: 18 Jan 2008
    7.5
    High

    CVE-2008-0363

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the (2) album parameter to gallery.php.

    Published: 18 Jan 2008
    4.3
    Medium

    CVE-2008-0357

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

    Published: 18 Jan 2008
    6.8
    Medium

    CVE-2008-0358

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.

    Published: 18 Jan 2008
    5.5
    Medium

    CVE-2010-4247

    Last Modified: 11 Apr 2025

    The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2008
    7.8
    High

    CVE-2008-0352

    Last Modified: 23 Apr 2026

    The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0350

    Last Modified: 23 Apr 2026

    admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2008-0351

    Last Modified: 23 Apr 2026

    admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0339

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0340

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0341

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0348

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0344

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0346

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0347

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0342

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0343

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0345

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.

    Published: 17 Jan 2008