LiveActive security incident?Get immediate response
CVE archive

March 2008

Browse CVE records published in March 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 737 matching CVEs · Page 6 of 15.

Unknown · CVSS Not scored

CVE-2008-4563: Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup serv...

Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attackers to execute arbitrary code via a crafted length value.

Published Mar 11, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4564: Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus...

Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.

Published Mar 18, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1596: Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write...

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to modify trusted files, related to missing checks in the TSD_FILES_LOCK policy for modifications performed via hard links, a different vulnerability than CVE-2007-6680.

Published Mar 31, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1593: The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect ker...

The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function.

Published Mar 31, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1591: The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_run...

The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabled, which allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, as demonstrated by the CLIENT_IP HTTP header (HTTP_CLIENT_IP variable).

Published Mar 31, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1468: Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to i...

Cross-site scripting (XSS) vulnerability in namazu.cgi in Namazu before 2.0.18 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded input, related to failure to set the charset, a different vector than CVE-2004-1318 and CVE-2001-1350. NOTE: some of these details are obtained from third party information.

Published Mar 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1552: The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing...

The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness error, and a buffer overflow. NOTE: the researcher describes this as an integer overflow, but CVE uses the "underflow" term in cases of wraparound from unsigned subtraction.

Published Mar 31, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1545: The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict...

The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling attacks via a POST containing a "Transfer-Encoding: chunked" header and a request body with an incorrect chunk size.

Published Mar 28, 2008 · Updated Aug 7, 2024