10
    Critical

    CVE-2008-4008

    Last Modified: 9 Mar 2011

    Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue is a stack-based buffer overflow in the WebLogic Apache Connector, related to an invalid parameter.

    Source:Metasploit
    Published:14 Oct 2008
    5.5
    Medium

    CVE-2008-3984

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3983.

    Source:sh2kerr
    Published:14 Oct 2008
    5.5
    Medium

    CVE-2008-3983

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to SYS.LT and WMSYS.LT, a different vulnerability than CVE-2008-3982 and CVE-2008-3984.

    Source:sh2kerr
    Published:14 Oct 2008
    5.5
    Medium

    CVE-2008-3979

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a SQL injection vulnerability that allows remote authenticated users to gain MDSYS privileges via the MDSYS.SDO_TOPO_DROP_FTBL trigger.

    Source:sh2kerr
    Published:14 Jan 2009
    4
    Medium

    CVE-2008-3963

    Last Modified: 19 Mar 2014

    MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-quote) token, aka an empty bit-string literal, which allows remote attackers to cause a denial of service (daemon crash) by using this token in a SQL statement.

    Source:Kay Roepke
    Published:10 Aug 2008
    9.3
    Critical

    CVE-2008-3957

    Last Modified: 18 Mar 2014

    The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Ciph3r
    Published:9 Sept 2008
    9.3
    Critical

    CVE-2008-3956

    Last Modified: 19 Mar 2014

    orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.

    Source:Ivan Sanchez
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-3955

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the ordercode parameter in a veiworderstatus page.

    Source:BugReport.IR
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-3954

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.

    Source:r45c4l
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-3953

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to execute arbitrary SQL commands via the tage parameter.

    Source:e.wiZz!
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-3952

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the idcat parameter.

    Source:SuB-ZeRo
    Published:9 Sept 2008
    7.5
    High

    CVE-2008-3951

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in view_ann.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the ann_id parameter.

    Source:DeViL iRaQ
    Published:9 Sept 2008
    5
    Medium

    CVE-2008-3950

    Last Modified: 18 Mar 2014

    Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iPhone 1.1.4 and 2.0 and iPod touch 1.1.4 and 2.0 allows remote attackers to cause a denial of service (browser crash) via a JavaScript alert call with an argument that lacks breakable characters and has a length that is a multiple of the memory page size, leading to an out-of-bounds read.

    Source:Nicolas Economou
    Published:16 Sept 2008
    7.5
    High

    CVE-2008-3945

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.

    Source:Hussin X
    Published:5 Sept 2008
    7.5
    High

    CVE-2008-3944

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.

    Source:Hussin X
    Published:5 Sept 2008
    7.5
    High

    CVE-2008-3943

    Last Modified: 21 Dec 2016

    SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Source:Hussin X
    Published:5 Sept 2008
    7.5
    High

    CVE-2008-3942

    Last Modified: 17 Mar 2014

    SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hussin X
    Published:5 Sept 2008
    4.3
    Medium

    CVE-2008-3941

    Last Modified: 17 Mar 2014

    Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI.

    Source:Am!r
    Published:5 Sept 2008
    6.1
    Medium

    CVE-2008-3937

    Last Modified: 17 Mar 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.

    Source:C1c4Tr1Z
    Published:5 Sept 2008
    5.8
    Medium

    CVE-2008-3926

    Last Modified: 20 Dec 2016

    Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action to index.php, or (2) create arbitrary directories via a .. (dot dot) in the env parameter in a login action to admin.php.

    Source:SirGod
    Published:4 Sept 2008
    4.3
    Medium

    CVE-2008-3925

    Last Modified: 20 Dec 2016

    Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.

    Source:SirGod
    Published:4 Sept 2008
    4.3
    Medium

    CVE-2008-3924

    Last Modified: 20 Dec 2016

    The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.

    Source:SirGod
    Published:4 Sept 2008
    4.3
    Medium

    CVE-2008-3923

    Last Modified: 20 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.

    Source:SirGod
    Published:4 Sept 2008
    9.3
    Critical

    CVE-2008-3922

    Last Modified: 21 Dec 2016

    awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.

    Source:Ricardo Almeida
    Published:4 Sept 2008
    7.5
    High

    CVE-2008-3918

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Khashayar Fereidani
    Published:4 Sept 2008
    4.3
    Medium

    CVE-2008-3917

    Last Modified: 14 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.

    Source:ThE dE@Th
    Published:4 Sept 2008
    4.3
    Medium

    CVE-2008-3906

    Last Modified: 17 Mar 2014

    CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

    Source:Juraj Skripsky
    Published:4 Sept 2008
    10
    Critical

    CVE-2008-3892

    Last Modified: 23 Apr 2026

    Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.

    Source:shinnai
    Published:3 Sept 2008
    7.5
    High

    CVE-2008-3888

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action.

    Source:S@BUN
    Published:2 Sept 2008
    9.3
    Critical

    CVE-2008-3879

    Last Modified: 23 Apr 2026

    The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.

    Source:shinnai
    Published:2 Sept 2008
    9.3
    Critical

    CVE-2008-3878

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.

    Source:shinnai
    Published:2 Sept 2008
    9.3
    Critical

    CVE-2008-3877

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file. NOTE: it was later reported that version 3 is also affected.

    Source:SkD
    Published:2 Sept 2008
    7.5
    High

    CVE-2008-3861

    Last Modified: 20 Dec 2016

    Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php.

    Source:~!Dok_tOR!~
    Published:29 Aug 2008
    5
    Medium

    CVE-2008-3859

    Last Modified: 20 Dec 2016

    Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a direct request to conf/admins.php.

    Source:SirGod
    Published:29 Aug 2008
    5
    Medium

    CVE-2008-3851

    Last Modified: 23 Apr 2026

    Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php; and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php. NOTE: the issue involving vectors 1 through 3 reportedly exists because of an incomplete fix for CVE-2008-3194.

    Source:DSecRG
    Published:27 Aug 2008
    4.3
    Medium

    CVE-2008-3850

    Last Modified: 16 Mar 2014

    Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html.

    Source:Eric Beaulieu
    Published:27 Aug 2008
    7.5
    High

    CVE-2008-3848

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:cOndemned
    Published:27 Aug 2008
    7.5
    High

    CVE-2008-3845

    Last Modified: 5 Jan 2018

    Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to execute arbitrary SQL commands via the department parameter to (1) is_xmlhttp.php and (2) is_flush.php.

    Source:GulfTech Security
    Published:27 Aug 2008
    2.1
    Low

    CVE-2008-3834

    Last Modified: 23 Apr 2026

    The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error.

    Source:Jon Oberheide
    Published:27 Sept 2008
    4.9
    Medium

    CVE-2008-3832

    Last Modified: 4 Sept 2016

    A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of service (NULL pointer dereference and system crash or hang) via a call to the utrace_control function.

    Source:Michael Simms
    Published:2 Oct 2008
    4.3
    Medium

    CVE-2008-3824

    Last Modified: 19 Mar 2014

    Cross-site scripting (XSS) vulnerability in (1) Text_Filter/Filter/xss.php in Horde 3.1.x before 3.1.9 and 3.2.x before 3.2.2 and (2) externalinput.php in Popoon r22196 and earlier allows remote attackers to inject arbitrary web script or HTML by using / (slash) characters as replacements for spaces in an HTML e-mail message.

    Source:Alexios Fakos
    Published:12 Sept 2008
    4.3
    Medium

    CVE-2008-3823

    Last Modified: 19 Mar 2014

    Cross-site scripting (XSS) vulnerability in MIME/MIME/Contents.php in the MIME library in Horde 3.2.x before 3.2.2 allows remote attackers to inject arbitrary web script or HTML via the filename of a MIME attachment in an e-mail message.

    Source:Alexios Fakos
    Published:12 Sept 2008
    4.3
    Medium

    CVE-2008-3821

    Last Modified: 7 Apr 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the HTTP server in Cisco IOS 11.0 through 12.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the ping program or (2) unspecified other aspects of the URI.

    Source:Adrian Pastor
    Published:16 Jan 2009
    10
    Critical

    CVE-2008-3795

    Last Modified: 23 Apr 2026

    Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message response."

    Source:securfrog
    Published:27 Aug 2008
    6.8
    Medium

    CVE-2008-3794

    Last Modified: 23 Apr 2026

    Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i allows remote attackers to execute arbitrary code via a crafted mmst link with a negative size value, which bypasses a size check and triggers an integer overflow followed by a heap-based buffer overflow.

    Source:g_
    Published:26 Aug 2008
    5
    Medium

    CVE-2008-3790

    Last Modified: 21 Dec 2016

    The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers to cause a denial of service (CPU consumption) via an XML document with recursively nested entities, aka an "XML entity explosion."

    Source:Luka Treiber
    Published:23 Aug 2008
    6.8
    Medium

    CVE-2008-3788

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PICTURESPRO Photo Cart 3.9, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) qtitle, (2) qid, and (3) qyear parameters to (a) search.php, and the (4) email and (5) password parameters to (b) _login.php.

    Source:~!Dok_tOR!~
    Published:26 Aug 2008
    7.5
    High

    CVE-2008-3787

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the name parameter.

    Source:~!Dok_tOR!~
    Published:26 Aug 2008
    4.3
    Medium

    CVE-2008-3786

    Last Modified: 16 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in PICTURESPRO Photo Cart 3.9 allows remote attackers to inject arbitrary web script or HTML via the qtitle parameter (aka "Gallery or event name" field) in a search action.

    Source:Tyler Trioxide
    Published:26 Aug 2008
    7.5
    High

    CVE-2008-3785

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) view, (2) category, or (3) blogsection action to index.php.

    Source:~!Dok_tOR!~
    Published:26 Aug 2008