CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-0349

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0328

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2008-0329

    Last Modified: 23 Apr 2026

    LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter.

    Published: 17 Jan 2008
    7.8
    High

    CVE-2008-0330

    Last Modified: 23 Apr 2026

    Open System Consultants (OSC) Radiator before 4.0 allows remote attackers to cause a denial of service (daemon crash) via malformed RADIUS requests, as demonstrated by packets sent by nmap.

    Published: 17 Jan 2008
    7.8
    High

    CVE-2008-0331

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Funkwerk System Software before 7.4.1 PATCH 9 for certain Funkwerk Router / VPN devices allows remote attackers to cause a denial of service (panic and reboot) via unspecified DNS requests.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2008-0332

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2008-0333

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the temp_filename parameter.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0337

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2008-0338

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0326

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to show.php.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0325

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0327

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in show.php in FaScript FaMp3 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 17 Jan 2008
    4.3
    Medium

    CVE-2008-0335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.

    Published: 17 Jan 2008
    4.3
    Medium

    CVE-2008-0336

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in BugTracker.NET before 2.7.2 allow remote attackers to delete arbitrary bugs and perform other administrative tasks via unspecified vectors, possibly related to delete_*.aspx pages, and massedit.aspx, subscribe.aspx, flag.aspx, and relationships.aspx.

    Published: 17 Jan 2008
    2.6
    Low

    CVE-2008-0334

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in pm/language/spanish/preferences.php in PMachine Pro 2.4.1 allows remote attackers to inject arbitrary web script or HTML via the L_PREF_NAME[855] parameter.

    Published: 17 Jan 2008
    9.3
    Critical

    CVE-2007-5760

    Last Modified: 23 Apr 2026

    Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2007-6428

    Last Modified: 23 Apr 2026

    The ProcGetReservedColormapEntries function in the TOG-CUP extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to read the contents of arbitrary memory locations via a request containing a 32-bit value that is improperly used as an array index.

    Published: 17 Jan 2008
    9.3
    Critical

    CVE-2007-6427

    Last Modified: 23 Apr 2026

    The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.

    Published: 17 Jan 2008
    9.3
    Critical

    CVE-2007-6429

    Last Modified: 23 Apr 2026

    Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request containing a 32-bit value that is improperly used to calculate an amount of memory for allocation by the EVI extension, or (2) a request containing values related to pixmap size that are improperly used in management of shared memory by the MIT-SHM extension.

    Published: 17 Jan 2008
    4.9
    Medium

    CVE-2008-0324

    Last Modified: 23 Apr 2026

    Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2008-0027

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6688

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the storage folder."

    Published: 17 Jan 2008
    7.5
    High

    CVE-2007-6689

    Last Modified: 23 Apr 2026

    Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core application or (2) MIME module.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6690

    Last Modified: 23 Apr 2026

    The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.

    Published: 17 Jan 2008
    6.4
    Medium

    CVE-2007-6692

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core and (2) print modules.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6693

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."

    Published: 17 Jan 2008
    4.3
    Medium

    CVE-2007-6687

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Menalto Gallery before 2.2.4 allow remote attackers to inject arbitrary web script or HTML via crafted filenames to the (1) Core or (2) add-item modules; or via (3) HTTP PROPPATCH in the WebDAV module.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6686

    Last Modified: 23 Apr 2026

    The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.

    Published: 17 Jan 2008
    7.2
    High

    CVE-2008-0302

    Last Modified: 23 Apr 2026

    Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in the current working directory.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6685

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.

    Published: 17 Jan 2008
    10
    Critical

    CVE-2007-6691

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the WebDAV module, (3) a comment view in the Comment module, (4) unspecified "item information disclosure attacks" in the Core module Gallery application, (5) the slideshow in the Slideshow module, and (6) multiple Print modules.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2007-6681

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, and (3) Vplayer file.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2007-6682

    Last Modified: 23 Apr 2026

    Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifiers in the Connection parameter.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2007-6683

    Last Modified: 23 Apr 2026

    The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT statement in an MP3 file, possibly an argument injection vulnerability.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2007-6684

    Last Modified: 23 Apr 2026

    The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dereference.

    Published: 17 Jan 2008
    9.3
    Critical

    CVE-2009-4243

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allow remote attackers to have an unspecified impact via a crafted media file that uses HTTP chunked transfer coding, related to an "overflow."

    Published: 17 Jan 2008
    9.3
    Critical

    CVE-2009-4248

    Last Modified: 11 Apr 2025

    Buffer overflow in the RTSPProtocol::HandleSetParameterRequest function in client/core/rtspprotocol.cpp in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted RTSP SET_PARAMETER request.

    Published: 17 Jan 2008
    5
    Medium

    CVE-2007-5958

    Last Modified: 23 Apr 2026

    X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in the -sp option to the X program, which produces different error messages depending on whether the filename exists.

    Published: 17 Jan 2008
    7.5
    High

    CVE-2008-0006

    Last Modified: 23 Apr 2026

    Buffer overflow in (1) X.Org Xserver before 1.4.1, and (2) the libfont and libXfont libraries on some platforms including Sun Solaris, allows context-dependent attackers to execute arbitrary code via a PCF font with a large difference between the last col and first col values in the PCF_BDF_ENCODINGS table.

    Published: 17 Jan 2008
    Unknown

    CVE-2008-0188

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requester. Further investigation showed that it was not a new security issue. Notes: none

    Published: 16 Jan 2008
    Unknown

    CVE-2008-0189

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its requester. Further investigation showed that it was not a new security issue. Notes: none

    Published: 16 Jan 2008
    4.3
    Medium

    CVE-2008-0298

    Last Modified: 23 Apr 2026

    KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV element.

    Published: 16 Jan 2008
    9.8
    Critical

    CVE-2008-0081

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.

    Published: 16 Jan 2008
    5
    Medium

    CVE-2008-0297

    Last Modified: 23 Apr 2026

    PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

    Published: 16 Jan 2008
    7.5
    High

    CVE-2008-0291

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 16 Jan 2008
    6.8
    Medium

    CVE-2008-0293

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function.

    Published: 16 Jan 2008
    5
    Medium

    CVE-2008-0294

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the seat-locking implementation in FreeSeat before 1.1.5d allows attackers to book a seat more than once via unspecified vectors.

    Published: 16 Jan 2008
    8.5
    High

    CVE-2008-0295

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attackers to cause a denial of service (crash) or execute arbitrary code via long Session Description Protocol (SDP) data.

    Published: 16 Jan 2008
    10
    Critical

    CVE-2008-0296

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the libaccess_realrtsp plugin in VideoLAN VLC Media Player 0.8.6d and earlier on Windows might allow remote RTSP servers to cause a denial of service (application crash) or execute arbitrary code via a long string.

    Published: 16 Jan 2008
    4.3
    Medium

    CVE-2008-0292

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Jan 2008