CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2007-5657

    Last Modified: 23 Apr 2026

    TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets.

    Published: 16 Jan 2008
    10
    Critical

    CVE-2007-5658

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing size and copy-length values that trigger the overflow.

    Published: 16 Jan 2008
    10
    Critical

    CVE-2007-5655

    Last Modified: 23 Apr 2026

    TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers.

    Published: 16 Jan 2008
    10
    Critical

    CVE-2007-5656

    Last Modified: 23 Apr 2026

    TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that control loop operations related to memory.

    Published: 16 Jan 2008
    5.8
    Medium

    CVE-2008-0032

    Last Modified: 23 Apr 2026

    Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource header, which triggers heap corruption.

    Published: 16 Jan 2008
    6.8
    Medium

    CVE-2008-0036

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.

    Published: 16 Jan 2008
    9.3
    Critical

    CVE-2008-0033

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file with Image Descriptor (IDSC) atoms containing an invalid atom size, which triggers memory corruption.

    Published: 16 Jan 2008
    5.8
    Medium

    CVE-2008-0031

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sorenson 3 video file, which triggers memory corruption.

    Published: 16 Jan 2008
    2.1
    Low

    CVE-2008-0216

    Last Modified: 23 Apr 2026

    The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user.

    Published: 16 Jan 2008
    6.9
    Medium

    CVE-2008-0217

    Last Modified: 23 Apr 2026

    The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.

    Published: 16 Jan 2008
    6.8
    Medium

    CVE-2008-0287

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (2) checkout.php.

    Published: 16 Jan 2008
    7.5
    High

    CVE-2008-0290

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecified program, or (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in the gestion_membre.php page to base.php.

    Published: 16 Jan 2008
    4.6
    Medium

    CVE-2008-0034

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors related to emergency calls.

    Published: 16 Jan 2008
    6.8
    Medium

    CVE-2008-0035

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Foundation, as used in Apple iPhone 1.0 through 1.1.2, iPod touch 1.1 through 1.1.2, and Mac OS X 10.5 through 10.5.1, allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted URL that triggers memory corruption in Safari.

    Published: 16 Jan 2008
    6.8
    Medium

    CVE-2008-0289

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the i parameter. NOTE: a second vector might exist via the l parameter. NOTE: as of 20080118, the vendor has disputed the set of affected versions, stating that the issue "is already fixed, for almost a year."

    Published: 16 Jan 2008
    7.5
    High

    CVE-2008-0288

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.

    Published: 16 Jan 2008
    7.5
    High

    CVE-2008-0286

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.

    Published: 16 Jan 2008
    5
    Medium

    CVE-2008-0285

    Last Modified: 23 Apr 2026

    ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0282

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.

    Published: 15 Jan 2008
    6.8
    Medium

    CVE-2008-0283

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0284

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topic arguments.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0281

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0280

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0255

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0256

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (b) thumb.asp, and (c) thumbricerca.asp and the (2) ricerca parameter to (d) thumbricerca.asp.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0257

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0258

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in PHP Running Management (phpRunMan) before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 15 Jan 2008
    6.4
    Medium

    CVE-2008-0259

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) thumbcat and (2) thumb parameters.

    Published: 15 Jan 2008
    5
    Medium

    CVE-2008-0260

    Last Modified: 23 Apr 2026

    minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, which calls the phpinfo function.

    Published: 15 Jan 2008
    5
    Medium

    CVE-2008-0261

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the search component and module in Mambo 4.5.x and 4.6.x allows remote attackers to cause a denial of service (query flood) via unspecified vectors.

    Published: 15 Jan 2008
    6.8
    Medium

    CVE-2008-0254

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the userName parameter.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0265

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the Search function in the web management interface in F5 BIG-IP 9.4.3 allow remote attackers to inject arbitrary web script or HTML via the SearchString parameter to (1) list_system.jsp, (2) list_pktfilter.jsp, (3) list_ltm.jsp, (4) resources_audit.jsp, and (5) list_asm.jsp in tmui/Control/jspmap/tmui/system/log/; and (6) list.jsp in certain directories.

    Published: 15 Jan 2008
    2.6
    Low

    CVE-2008-0266

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrative tasks. NOTE: either the old password must be known, or the attacker must leverage a separate SQL injection vulnerability.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0267

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to search.php; and allow remote authenticated administrators to execute arbitrary SQL commands via the (4) msg and (5) password parameters to admin.php.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0268

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 15 Jan 2008
    4.9
    Medium

    CVE-2008-0269

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the dotoprocs function in Sun Solaris 10 allows local users to cause a denial of service (panic) via unspecified vectors.

    Published: 15 Jan 2008
    5
    Medium

    CVE-2008-0275

    Last Modified: 23 Apr 2026

    The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3) bodies, which might allow remote attackers to gain access to syndicated content.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0276

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.

    Published: 15 Jan 2008
    8.5
    High

    CVE-2008-0277

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Fileshare module for Drupal allows remote authenticated users with node-creation privileges to execute arbitrary code via unspecified vectors.

    Published: 15 Jan 2008
    6
    Medium

    CVE-2008-0278

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0173

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0272

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the aggregator module in Drupal 4.7.x before 4.7.11 and 5.x before 5.6 allows remote attackers to delete items from a feed as privileged users.

    Published: 15 Jan 2008
    5
    Medium

    CVE-2008-0263

    Last Modified: 23 Apr 2026

    The SIP module in Ingate Firewall before 4.6.1 and SIParator before 4.6.1 does not reuse SIP media ports in unspecified call hold and send-only stream scenarios, which allows remote attackers to cause a denial of service (port exhaustion) via unspecified vectors.

    Published: 15 Jan 2008
    6.8
    Medium

    CVE-2008-0264

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Meta Tags (aka Nodewords) 5.x-1.6 module for Drupal, when images are permitted in node bodies, allows remote authenticated users to execute arbitrary code via unspecified vectors involving creation of a node.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0271

    Last Modified: 23 Apr 2026

    The editor deletion form in BUEditor 4.7.x before 4.7.x-1.0 and 5.x before 5.x-1.1, a module for Drupal, does not follow Drupal's Forms API submission model, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete custom editor interfaces.

    Published: 15 Jan 2008
    2.6
    Low

    CVE-2008-0274

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Drupal 4.7.x and 5.x, when certain .htaccess protections are disabled, allows remote attackers to inject arbitrary web script or HTML via crafted links involving theme .tpl.php files.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0253

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.

    Published: 15 Jan 2008
    7.5
    High

    CVE-2008-0262

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute arbitrary SQL commands via the articlecat parameter.

    Published: 15 Jan 2008
    6
    Medium

    CVE-2008-0270

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sContext parameter.

    Published: 15 Jan 2008
    4.3
    Medium

    CVE-2008-0273

    Last Modified: 23 Apr 2026

    Interpretation conflict in Drupal 4.7.x before 4.7.11 and 5.x before 5.6, when Internet Explorer 6 is used, allows remote attackers to conduct cross-site scripting (XSS) attacks via invalid UTF-8 byte sequences, which are not processed as UTF-8 by Drupal's HTML filtering, but are processed as UTF-8 by Internet Explorer, effectively removing characters from the document and defeating the HTML protection mechanism.

    Published: 15 Jan 2008