Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-2038 | 1 Turnkey Solutions | 1 Sunshop Shopping Cart | 2017-08-07 | 6.5 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in admin/adminindex.php in Turnkey Web Tools SunShop Shopping Cart 4.1.0 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) orderby and (2) sort parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-2040 | 1 Peercast | 1 Peercast | 2017-08-07 | 7.5 HIGH | N/A |
Stack-based buffer overflow in the HTTP::getAuthUserPass function (core/common/http.cpp) in Peercast 0.1218 and gnome-peercast allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Basic Authentication string with a long (1) username or (2) password. | |||||
CVE-2008-2041 | 1 Egroupware | 1 Egroupware | 2017-08-07 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in eGroupWare before 1.4.004 have unspecified attack vectors and "grave" impact when the web server has write access to a directory under the web document root. | |||||
CVE-2008-2043 | 1 Cpanel | 1 Cpanel | 2017-08-07 | 4.3 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in cPanel, possibly 11.18.3 and 11.19.3, allow remote attackers to (1) execute arbitrary code via the command1 parameter to frontend/x2/cron/editcronsimple.html, and perform various administrative actions via (2) frontend/x2/sql/adddb.html, (3) frontend/x2/sql/adduser.html, and (4) frontend/x2/ftp/doaddftp.html. | |||||
CVE-2008-2046 | 1 Softpedia | 1 Sitexs Cms | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in index.php in Softpedia SiteXS CMS 0.1.1 Pre-Alpha allows remote attackers to inject arbitrary web script or HTML via the user parameter. | |||||
CVE-2008-2049 | 1 E-post Corporation | 1 Mail Server | 2017-08-07 | 4.3 MEDIUM | N/A |
The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, which displays the password in a POP3 error message. | |||||
CVE-2008-2052 | 1 Bitrix | 1 Bitrix Site Manager | 2017-08-07 | 4.3 MEDIUM | N/A |
Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the goto parameter. | |||||
CVE-2008-2053 | 1 Cisco | 1 Unified Customer Voice Portal | 2017-08-07 | 9.0 HIGH | N/A |
Unspecified vulnerability in Cisco Unified Customer Voice Portal (CVP) 4.0.x before 4.0(2)_ES14, 4.1.x before 4.1(1)_ES11, and 7.x before 7.0(1) allows remote authenticated users with administrator role privileges to create, modify, or delete a superuser account. | |||||
CVE-2008-2054 | 1 Cisco | 1 Ciscoworks Common Services | 2017-08-07 | 9.3 HIGH | N/A |
Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors. | |||||
CVE-2008-2060 | 1 Cisco | 1 Intrusion Prevention System | 2017-08-07 | 7.8 HIGH | N/A |
Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows remote attackers to cause a denial of service (panic), and possibly bypass intended restrictions on network traffic, via a "specific series of jumbo Ethernet frames." | |||||
CVE-2008-2064 | 1 Phpgedview | 1 Phpgedview | 2017-08-07 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGedView with external programs like content management systems." | |||||
CVE-2008-2068 | 1 Wordpress | 1 Wordpress | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in WordPress 2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2008-2077 | 1 Plain Black | 1 Webgui | 2017-08-07 | 10.0 HIGH | N/A |
Unspecified vulnerability in Plain Black WebGUI 7.4.34 has unknown impact and attack vectors related to "data form list view." | |||||
CVE-2008-2078 | 1 Robocode | 1 Robocode | 2017-08-07 | 7.5 HIGH | N/A |
Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT Event Queue. | |||||
CVE-2008-2080 | 1 Nasa Goddard Space Flight Center | 1 Common Data Format | 2017-08-07 | 7.5 HIGH | N/A |
Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags. | |||||
CVE-2008-2085 | 1 Icewalkers | 1 Sipp | 2017-08-07 | 7.5 HIGH | N/A |
Multiple stack-based buffer overflows in the (1) get_remote_ip_media and (2) get_remote_ipv6_media functions in call.cpp in SIPp 3.1 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted SIP message. | |||||
CVE-2008-2092 | 1 Linksys | 1 Spa-2102 Phone Adapter | 2017-08-07 | 7.8 HIGH | N/A |
Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: the severity of this issue has been disputed since there are limited attack scenarios. | |||||
CVE-2008-2103 | 1 Mozilla | 1 Bugzilla | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list. | |||||
CVE-2008-2104 | 1 Mozilla | 1 Bugzilla | 2017-08-07 | 4.0 MEDIUM | N/A |
The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check. | |||||
CVE-2008-2105 | 1 Mozilla | 1 Bugzilla | 2017-08-07 | 3.5 LOW | N/A |
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses. |