CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2008-0159

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in eggBlog 3.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the eggblogpassword parameter in a cookie.

    Published: 9 Jan 2008
    9.3
    Critical

    CVE-2007-0069

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."

    Published: 8 Jan 2008
    7.2
    High

    CVE-2007-5352

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows local users to gain privileges via a crafted local procedure call (LPC) request.

    Published: 8 Jan 2008
    7.1
    High

    CVE-2007-0066

    Last Modified: 23 Apr 2026

    The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, aka "Windows Kernel TCP/IP/ICMP Vulnerability."

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0143

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM Broadcaster, allows remote attackers to execute arbitrary PHP code via a URL in the commonpath parameter.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2008-0135

    Last Modified: 23 Apr 2026

    Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum/snitz_forums_2000.mdb.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2007-6676

    Last Modified: 23 Apr 2026

    The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to uber_uploader_file.js, a different issue than CVE-2007-0123. NOTE: the vendor disputes the severity of the issue, noting that it is the administrator's responsibility to "add file extensions that you may or may not want uploaded."

    Published: 8 Jan 2008
    5
    Medium

    CVE-2008-0136

    Last Modified: 23 Apr 2026

    Snitz Forums 2000 3.4.05 allows remote attackers to obtain sensitive information via a direct request to forum/whereami.asp, which reveals the database path.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0144

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in NetRisk 1.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged for local file inclusion using directory traversal sequences.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0141

    Last Modified: 23 Apr 2026

    actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it easier for remote attackers to obtain access to any account via a lostpass action.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2007-6674

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Default.asp in RapidShare Database allows remote attackers to inject arbitrary web script or HTML via the Arayalim parameter.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2007-6675

    Last Modified: 23 Apr 2026

    The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows remote attackers to read the comments in restricted modules.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0133

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2008-0134

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Forums/setup.asp in Snitz Forums 2000 3.4.06 and earlier allows remote attackers to inject arbitrary web script or HTML via the MAIL parameter.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0137

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to execute arbitrary PHP code via a URL in the path_escape parameter.

    Published: 8 Jan 2008
    6.8
    Medium

    CVE-2008-0138

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter.

    Published: 8 Jan 2008
    6.8
    Medium

    CVE-2008-0139

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to execute arbitrary PHP code via the template parameter.

    Published: 8 Jan 2008
    6.4
    Medium

    CVE-2008-0140

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the selected_theme parameter, a different vector than CVE-2007-3172.

    Published: 8 Jan 2008
    6.8
    Medium

    CVE-2008-0142

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL commands via the user_name parameter to actions.php, and unspecified other vectors.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0145

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in glob in PHP before 4.4.8, when open_basedir is enabled, has unknown impact and attack vectors. NOTE: this issue reportedly exists because of a regression related to CVE-2007-4663.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2008-0146

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the error page in W3-mSQL allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the top-level URI.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2007-6672

    Last Modified: 23 Apr 2026

    Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2007-6673

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Makale Scripti allows remote attackers to inject arbitrary web script or HTML via the ara parameter to the default URI under Ara/ in a search action.

    Published: 8 Jan 2008
    6.8
    Medium

    CVE-2008-0129

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0130

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Username parameter, a different vulnerability than CVE-2007-6671. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2008-0131

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to inject arbitrary web script or HTML via the msg parameter, a different product than CVE-2006-6022. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2008-0132

    Last Modified: 23 Apr 2026

    Pragma FortressSSH 5.0 Build 4 Revision 293 and earlier handles long input to sshd.exe by creating an error-message window and waiting for the administrator to click in this window before terminating the sshd.exe process, which allows remote attackers to cause a denial of service (connection slot exhaustion) via a flood of SSH connections with long data objects, as demonstrated by (1) a long list of keys and (2) a long username.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2007-6671

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in login_form.asp in Instant Softwares Dating Site allows remote attackers to execute arbitrary SQL commands via the Password parameter, a different product than CVE-2006-6021. NOTE: some of these details are obtained from third party information.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2007-6670

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to execute arbitrary SQL commands via the string parameter.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0096

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0097

    Last Modified: 23 Apr 2026

    Format string vulnerability in the log function in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username field, as demonstrated by a certain LoginPassword message.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2007-6668

    Last Modified: 23 Apr 2026

    admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestricted file uploads, as demonstrated by uploading (1) a .php file and (2) a .php%00.jpeg file.

    Published: 8 Jan 2008
    6.4
    Medium

    CVE-2008-0094

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.

    Published: 8 Jan 2008
    6.8
    Medium

    CVE-2008-0099

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2007-6669

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in PHCDownload 1.1.0 allows remote attackers to inject arbitrary web script or HTML via the string parameter.

    Published: 8 Jan 2008
    5
    Medium

    CVE-2008-0095

    Last Modified: 23 Apr 2026

    The SIP channel driver in Asterisk Open Source 1.4.x before 1.4.17, Business Edition before C.1.0-beta8, AsteriskNOW before beta7, Appliance Developer Kit before Asterisk 1.4 revision 95946, and Appliance s800i 1.0.x before 1.0.3.4 allows remote attackers to cause a denial of service (daemon crash) via a BYE message with an Also (Also transfer) header, which triggers a NULL pointer dereference.

    Published: 8 Jan 2008
    10
    Critical

    CVE-2008-0098

    Last Modified: 23 Apr 2026

    Buffer overflow in RealPlayer 11 build 6.0.14.748 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: As of 20080103, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0101

    Last Modified: 23 Apr 2026

    Format string vulnerability in the swDebugf function in DuneApp.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a .WRL file.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0100

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Scene::errorf function in Scene.cpp in White_Dune 0.29 beta791 and earlier allows remote attackers to execute arbitrary code via a long string in a .WRL file.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2008-0093

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via the (1) Name and (2) Subject parameters.

    Published: 8 Jan 2008
    6.9
    Medium

    CVE-2008-1483

    Last Modified: 23 Apr 2026

    OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port, as demonstrated by opening TCP port 6010 (IPv4) and sniffing a cookie sent by Emacs.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2008-0674

    Last Modified: 23 Apr 2026

    Buffer overflow in PCRE before 7.6 allows remote attackers to execute arbitrary code via a regular expression containing a character class with a large number of characters with Unicode code points greater than 255.

    Published: 8 Jan 2008
    6.4
    Medium

    CVE-2008-0225

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 and earlier allows remote attackers to execute arbitrary code via the SDP Abstract attribute in an RTSP session, related to the rmff_dump_header function and related to disregarding the max field. NOTE: some of these details are obtained from third party information.

    Published: 8 Jan 2008
    4.3
    Medium

    CVE-2007-0012

    Last Modified: 23 Apr 2026

    Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.

    Published: 8 Jan 2008
    7.5
    High

    CVE-2007-5360

    Last Modified: 23 Apr 2026

    Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.

    Published: 8 Jan 2008
    10
    Critical

    CVE-2008-0882

    Last Modified: 23 Apr 2026

    Double free vulnerability in the process_browse_data function in CUPS 1.3.5 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via crafted UDP Browse packets to the cupsd port (631/udp), related to an unspecified manipulation of a remote printer. NOTE: some of these details are obtained from third party information.

    Published: 7 Jan 2008
    4
    Medium

    CVE-2007-4772

    Last Modified: 23 Apr 2026

    The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

    Published: 7 Jan 2008
    6.5
    Medium

    CVE-2007-6600

    Last Modified: 23 Apr 2026

    PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.

    Published: 7 Jan 2008
    7.2
    High

    CVE-2007-6601

    Last Modified: 23 Apr 2026

    The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.

    Published: 7 Jan 2008
    6.8
    Medium

    CVE-2007-4769

    Last Modified: 23 Apr 2026

    The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.

    Published: 7 Jan 2008