CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-0279

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitrary SQL commands via the topic parameter. NOTE: the categorie parameter might also be affected.

    Published: 15 Jan 2008
    5
    Medium

    CVE-2010-0417

    Last Modified: 11 Apr 2025

    Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.

    Published: 14 Jan 2008
    10
    Critical

    CVE-2008-0122

    Last Modified: 23 Apr 2026

    Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted input that triggers memory corruption.

    Published: 14 Jan 2008
    4.3
    Medium

    CVE-2008-0299

    Last Modified: 23 Apr 2026

    common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

    Published: 13 Jan 2008
    7.2
    High

    CVE-2008-0242

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in libdevinfo in Sun Solaris 10 allows local users to access files and gain privileges via unknown vectors, related to login device permissions.

    Published: 12 Jan 2008
    7.8
    High

    CVE-2008-0243

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

    Published: 12 Jan 2008
    10
    Critical

    CVE-2008-0244

    Last Modified: 23 Apr 2026

    SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands, which are executed when MaxDB invokes cons.exe.

    Published: 12 Jan 2008
    9.3
    Critical

    CVE-2008-0248

    Last Modified: 23 Apr 2026

    Buffer overflow in an ActiveX control in ccpm_0237.dll for StreamAudio ChainCast ProxyManager allows remote attackers to execute arbitrary code via a long URL argument to the InternalTuneIn method.

    Published: 12 Jan 2008
    5
    Medium

    CVE-2008-0249

    Last Modified: 23 Apr 2026

    PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if a call to /usr/bin/mysqldump fails. NOTE: this might only be an issue in limited environments.

    Published: 12 Jan 2008
    9.3
    Critical

    CVE-2008-0250

    Last Modified: 23 Apr 2026

    Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.

    Published: 12 Jan 2008
    7.5
    High

    CVE-2008-0245

    Last Modified: 23 Apr 2026

    admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.

    Published: 12 Jan 2008
    10
    Critical

    CVE-2008-0251

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.

    Published: 12 Jan 2008
    10
    Critical

    CVE-2008-0246

    Last Modified: 23 Apr 2026

    admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action.

    Published: 12 Jan 2008
    10
    Critical

    CVE-2008-0247

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbitrary code via a packet with a large length value.

    Published: 12 Jan 2008
    7.5
    High

    CVE-2008-0252

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.

    Published: 12 Jan 2008
    4.3
    Medium

    CVE-2008-0123

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML via the dbname parameter. NOTE: this issue only exists until the installation is complete.

    Published: 12 Jan 2008
    7.8
    High

    CVE-2007-6423

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue

    Published: 12 Jan 2008
    4.3
    Medium

    CVE-2007-6420

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecified vectors.

    Published: 12 Jan 2008
    3.6
    Low

    CVE-2008-0001

    Last Modified: 23 Apr 2026

    VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might allow local users to bypass intended permissions and remove directories.

    Published: 12 Jan 2008
    5
    Medium

    CVE-2008-2109

    Last Modified: 23 Apr 2026

    field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0', which triggers an infinite loop.

    Published: 12 Jan 2008
    4.3
    Medium

    CVE-2008-0240

    Last Modified: 23 Apr 2026

    /idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via the helpUrl parameter, aka "frame injection."

    Published: 11 Jan 2008
    4.3
    Medium

    CVE-2008-0239

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web script via the (1) cntry or lang parameters to /idm/login.jsp, (2) resultsForm parameter to /idm/account/findForSelect.jsp, or (3) activeControl parameter to /idm/user/main.jsp.

    Published: 11 Jan 2008
    5.8
    Medium

    CVE-2008-0241

    Last Modified: 23 Apr 2026

    Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the nextPage parameter.

    Published: 11 Jan 2008
    9.3
    Critical

    CVE-2008-0234

    Last Modified: 23 Apr 2026

    Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Reason-Phrase response to an rtsp:// request, as demonstrated using a 404 error message.

    Published: 11 Jan 2008
    10
    Critical

    CVE-2008-0235

    Last Modified: 23 Apr 2026

    The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.

    Published: 11 Jan 2008
    5.8
    Medium

    CVE-2008-0236

    Last Modified: 23 Apr 2026

    An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.

    Published: 11 Jan 2008
    7.5
    High

    CVE-2008-0233

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg.

    Published: 11 Jan 2008
    6.8
    Medium

    CVE-2008-0237

    Last Modified: 23 Apr 2026

    The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.

    Published: 11 Jan 2008
    5
    Medium

    CVE-2007-6284

    Last Modified: 23 Apr 2026

    The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.

    Published: 11 Jan 2008
    5
    Medium

    CVE-2008-0171

    Last Modified: 23 Apr 2026

    regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.

    Published: 11 Jan 2008
    7.5
    High

    CVE-2008-0232

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to index.php, or the (2) f or t parameters to forums/index.php.

    Published: 11 Jan 2008
    7.5
    High

    CVE-2008-0230

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121dir parameter.

    Published: 11 Jan 2008
    7.5
    High

    CVE-2008-0231

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange Cutout, (4) Lonely Maple, (5) Endless, (6) Classic Theme, and (7) Music Theme webpage templates allow remote attackers to include and execute arbitrary files via ".." sequences in the page parameter. NOTE: this can be leveraged for remote file inclusion when running in some PHP 5 environments.

    Published: 11 Jan 2008
    5
    Medium

    CVE-2008-0172

    Last Modified: 23 Apr 2026

    The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.

    Published: 11 Jan 2008
    2.1
    Low

    CVE-2007-6680

    Last Modified: 23 Apr 2026

    Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to an error in the support for links in the TSD_FILES_LOCK policy.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0219

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in soporte_horizontal_w.php in PHP Webquest 2.6 allows remote attackers to execute arbitrary SQL commands via the id_actividad parameter, a different vector than CVE-2007-4920.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0220

    Last Modified: 23 Apr 2026

    Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allow remote attackers to execute arbitrary code via a long string in the (1) second or (2) fourth argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.

    Published: 10 Jan 2008
    9.3
    Critical

    CVE-2008-0221

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1.0.0.1 in Gateway Weblaunch allows remote attackers to execute arbitrary programs via a ..\ (dot dot backslash) in the second argument to the DoWebLaunch method. NOTE: some of these details are obtained from third party information.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0227

    Last Modified: 23 Apr 2026

    yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allows remote attackers to cause a denial of service (crash) via a Hello packet containing a large size value, which triggers a buffer over-read in the HASHwithTransform::Update function in hash.cpp.

    Published: 10 Jan 2008
    9.3
    Critical

    CVE-2008-0228

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0224

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attackers to execute arbitrary SQL commands via the Client-Ip parameter.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0218

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin/index.html in Merak IceWarp Mail Server allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Jan 2008
    9.3
    Critical

    CVE-2008-0223

    Last Modified: 23 Apr 2026

    Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0222

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors.

    Published: 10 Jan 2008
    7.5
    High

    CVE-2008-0226

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yassl_imp.cpp.

    Published: 10 Jan 2008
    10
    Critical

    CVE-2008-0229

    Last Modified: 23 Apr 2026

    The telnet service in LevelOne WBR-3460 4-Port ADSL 2/2+ Wireless Modem Router with firmware 1.00.11 and 1.00.12 does not require authentication, which allows remote attackers on the local or wireless network to obtain administrative access.

    Published: 10 Jan 2008
    10
    Critical

    CVE-2007-6679

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.

    Published: 10 Jan 2008
    Unknown

    CVE-2007-6678

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-6167. Reason: This candidate is a duplicate of CVE-2007-6167. Notes: All CVE users should reference CVE-2007-6167 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0197

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) wpcf_email, (2) wpcf_subject, (3) wpcf_question, (4) wpcf_answer, (5) wpcf_success_msg, (6) wpcf_error_msg, or (7) wpcf_msg parameter to wp-admin/admin.php, or (8) the SRC attribute of an IFRAME element.

    Published: 10 Jan 2008
    4.3
    Medium

    CVE-2008-0198

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in wp-contact-form/options-contactform.php in the WP-ContactForm 1.5 alpha and earlier plugin for WordPress allow remote attackers to perform actions as administrators via the (1) wpcf_question, (2) wpcf_success_msg, or (3) wpcf_error_msg parameter to wp-admin/admin.php.

    Published: 10 Jan 2008