Vulnerability index

Browse CVEs

6,062 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
Iprint Client HIGH 9.3
CVE-2008-2436

Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 al…

Patch available
Fix from $1,950 2008-09-05
Ichitaro HIGH 9.3
CVE-2008-3919

Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as …

Mitigation only
Fix from $1,950 2008-09-04
Awstats Totals HIGH 9.3
CVE-2008-3922EPSS 53%

awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which…

Patch available
Fix from $1,950 2008-09-04
Zoneminder HIGH 10.0
CVE-2008-3882

Unspecified "Command Injection" vulnerability in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands via (1) the exec…

Fix: after 1.23.3
Fix from $1,950 2008-09-02
Lacoodast HIGH 10.0
CVE-2008-3737

Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and earlier allows remote attacke…

Fix: after 2.1.3
Fix from $1,950 2008-08-27
Freeway MEDIUM 6.8
CVE-2008-3769

PHP remote file inclusion vulnerability in admin/create_order_new.php in Freeway 1.4.1.171, when register_globals is enabled, allows remote attackers…

Mitigation only
Fix from $1,600 2008-08-22
Php Live Helper HIGH 7.5
CVE-2008-3764

Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to execute arbitrary PHP code via…

Fix: after 2.0.1
Fix from $1,950 2008-08-21
Dmcms HIGH 7.5
CVE-2008-3721

PHP remote file inclusion vulnerability in user_language.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary PHP code via a …

No fix yet
Fix from $1,950 2008-08-20
Cyboards Php Lite HIGH 7.5
CVE-2008-3707

Multiple PHP remote file inclusion vulnerabilities in CyBoards PHP Lite 1.21 allow remote attackers to execute arbitrary PHP code via a URL in the sc…

Mitigation only
Fix from $1,950 2008-08-19
Openwsman HIGH 7.5
CVE-2008-2233

The client in Openwsman 1.2.0 and 2.0.0, in unknown configurations, allows remote Openwsman servers to replay SSL sessions via unspecified vectors.

Patch available
Fix from $1,950 2008-08-18
Office HIGH 9.3
CVE-2008-3018EPSS 30%

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows rem…

Mitigation only
Fix from $1,950 2008-08-12
Txtsql HIGH 9.3
CVE-2008-3595

PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code…

No fix yet
Fix from $1,950 2008-08-12
Symphony HIGH 8.5
CVE-2008-3592EPSS 7%

Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and earlier allows remote attacker…

Fix: after 1.7.01
Fix from $1,950 2008-08-11
Africa Be Gone HIGH 7.5
CVE-2008-3570

PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arbitrary PHP code via a URL in …

No fix yet
Fix from $1,950 2008-08-10
Ezcontents Cms HIGH 7.5
CVE-2008-3575

PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers to execute arbitrary PHP code …

Mitigation only
Fix from $1,950 2008-08-10
Lovecms HIGH 7.5
CVE-2008-3509

LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in system/admin/, which allows …

No fix yet
Fix from $1,950 2008-08-07
Coppermine Photo Gallery HIGH 7.5
CVE-2008-3481

themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct req…

Fix: after 1.4.18
Fix from $1,950 2008-08-05
Php Hosting Directory HIGH 10.0
CVE-2008-3455

PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attackers to execute arbitrary PHP c…

No fix yet
Fix from $1,950 2008-08-04
Download Accelerator Plus HIGH 7.5
CVE-2008-3433

SpeedBit Download Accelerator Plus (DAP) before 8.6.3.9 does not properly verify the authenticity of updates, which allows man-in-the-middle attacker…

Fix: after 8.6
Fix from $1,950 2008-08-01
Itunes HIGH 7.5
CVE-2008-3434

Apple iTunes before 10.5.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code v…

Fix: after 6.0.5
Fix from $1,950 2008-08-01
Browser Toolbar HIGH 7.5
CVE-2008-3435

LinkedIn Browser Toolbar 3.0.3.1100 and earlier does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to exe…

Fix: after 3.0.3.1100
Fix from $1,950 2008-08-01
Notepad\+\+ HIGH 7.5
CVE-2008-3436

The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attacke…

Fix: after 2.2
Fix from $1,950 2008-08-01
Openoffice.org HIGH 7.5
CVE-2008-3437

OpenOffice.org (OOo) before 2.1.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2008-08-01
Speedbit Video Accelerator HIGH 7.5
CVE-2008-3439

SpeedBit Video Acceleration before 2.2.1.8 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute …

Fix: after 2.2.0.7
Fix from $1,950 2008-08-01
Java HIGH 7.5
CVE-2008-3440

Sun Java 1.6.0_03 and earlier versions, and possibly later versions, does not properly verify the authenticity of updates, which allows man-in-the-mi…

Fix: after 1.6.0
Fix from $1,950 2008-08-01
Winamp HIGH 7.5
CVE-2008-3441

Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code …

Fix: 5.24+
Fix from $1,950 2008-08-01
Winzip HIGH 7.5
CVE-2008-3442

WinZip before 11.0 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Tro…

Mitigation only
Fix from $1,950 2008-08-01
Xrms Crm MEDIUM 6.8
CVE-2008-3399

PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote att…

No fix yet
Fix from $1,600 2008-07-31
Hiox Random Ad HIGH 7.5
CVE-2008-3401

PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execute arbitrary PHP code via a U…

No fix yet
Fix from $1,950 2008-07-31
Hiox Random Ad HIGH 7.5
CVE-2008-3402

Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a UR…

No fix yet
Fix from $1,950 2008-07-31