Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-3057 | 1 Octeth | 1 Oempro | 2017-08-07 | 5.0 MEDIUM | N/A |
Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | |||||
CVE-2008-3058 | 1 Octeth | 1 Oempro | 2017-08-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_Email parameter (aka Email field) to index.php in (1) member/, (2) client/, or (3) admin/; or (4) the FormValue_SearchKeywords parameter to client/campaign_track.php. | |||||
CVE-2008-3059 | 1 Octeth | 1 Oempro | 2017-08-07 | 4.0 MEDIUM | N/A |
member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab. | |||||
CVE-2008-3060 | 1 V-webmail | 1 V-webmail | 2017-08-07 | 5.0 MEDIUM | N/A |
V-webmail 1.5.0 allows remote attackers to obtain sensitive information via (1) malformed input in the login page (includes/local.hooks.php) and (2) an invalid session ID, which reveals the installation path in an error message. | |||||
CVE-2008-3061 | 1 V-webmail | 1 V-webmail | 2017-08-07 | 4.3 MEDIUM | N/A |
Open redirect vulnerability in redirect.php in V-webmail 1.5.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the to parameter. | |||||
CVE-2008-3063 | 1 V-webmail | 1 V-webmail | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in login.php in V-webmail 1.5.0 might allow remote attackers to execute arbitrary SQL commands via the username parameter. | |||||
CVE-2008-3067 | 1 Suse | 1 Opensuse | 2017-08-07 | 2.1 LOW | N/A |
sudo in SUSE openSUSE 10.3 does not clear the stdin buffer when password entry times out, which might allow local users to obtain a password by reading stdin from the parent process after a sudo child process exits. | |||||
CVE-2008-3076 | 1 Vim | 1 Vim | 2017-08-07 | 9.3 HIGH | N/A |
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenames used by the execute and system functions within the (1) mz and (2) mc commands, as demonstrated by the netrw.v2 and netrw.v3 test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. | |||||
CVE-2008-3078 | 1 Opera | 1 Opera Browser | 2017-08-07 | 7.8 HIGH | N/A |
Opera before 9.51 does not properly manage memory within functions supporting the CANVAS element, which allows remote attackers to read uninitialized memory contents by using JavaScript to read a canvas image. | |||||
CVE-2008-3079 | 2 Microsoft, Opera | 2 Windows, Opera | 2017-08-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in Opera before 9.51 on Windows allows attackers to execute arbitrary code via unknown vectors. | |||||
CVE-2008-3081 | 1 Avaya | 1 Messaging Storage Server | 2017-08-07 | 6.5 MEDIUM | N/A |
Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0, and possibly Communication Manager 3.1.x, allow remote authenticated administrators to execute arbitrary commands as user vexvm via vectors related to (1) SFTP Remote Store configuration; (2) remote FTP storage settings; (3) name server lookup; (4) pinging another host; (5) TCP/IP Networking parameter configuration; (6) the external hosts configuration main page; (7) adding and changing external hosts; (8) Windows domain parameter configuration; (9) date, time, and NTP server configuration; (10) alarm settings; (11) the command line history form; (12) the maintenance form; and (13) the server events form. | |||||
CVE-2008-3082 | 1 Commtouch | 1 Enterprise Anti-spam Gateway | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway 4 and 5 allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. | |||||
CVE-2008-3090 | 1 Blognplus | 1 Blognplus | 2017-08-07 | 7.5 HIGH | N/A |
Multiple SQL injection vulnerabilities in index.php in BlognPlus (BURO GUN +) 2.5.5 MySQL and PostgreSQL editions allow remote attackers to execute arbitrary SQL commands via the (1) p, (2) e, (3) d, and (4) m parameters, a different vulnerability than CVE-2008-2819. | |||||
CVE-2008-3091 | 1 Drupal | 1 Taxonomy Autotagger Module | 2017-08-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2008-3092 | 1 Drupal | 1 Taxonomy Autotagger Module | 2017-08-07 | 6.5 MEDIUM | N/A |
SQL injection vulnerability in the Taxonomy Autotagger module 5.x before 5.x-1.8 for Drupal allows remote authenticated users, with create or edit post permissions, to execute arbitrary SQL commands via unspecified vectors. | |||||
CVE-2008-3095 | 1 Drupal | 1 Organic Groups Module | 2017-08-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the Organic Groups (OG) module 5.x before 5.x-7.3 and 6.x before 6.x-1.0-RC1, a module for Drupal, allows remote authenticated users, with group owner permissions, to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2008-3096 | 1 Drupal | 1 Outline Designer Module | 2017-08-07 | 6.5 MEDIUM | N/A |
The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, which might allow remote attackers to gain privileges. | |||||
CVE-2008-3097 | 1 Drupal | 1 Tinytax Taxonomy Block Module | 2017-08-07 | 3.5 LOW | N/A |
Cross-site scripting (XSS) vulnerability in the Tinytax module (aka Tinytax taxonomy block) 5.x before 5.x-1.10-1 for Drupal allows remote authenticated users to inject arbitrary web script or HTML, probably by creating a crafted taxonomy term. | |||||
CVE-2008-3121 | 1 Xerox | 1 Centreware Web | 2017-08-07 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2008-3122 | 1 Xerox | 1 Centreware Web | 2017-08-07 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in Xerox CentreWare Web (CWW) before 4.6.46 allow remote authenticated users to execute arbitrary SQL commands via the unspecified vectors. |