LiveActive security incident?Get immediate response
CVE archive

March 2008

Browse CVE records published in March 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 737 matching CVEs · Page 8 of 15.

Unknown · CVSS Not scored

CVE-2008-1482: Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buff...

Multiple integer overflows in xine-lib 1.1.11 and earlier allow remote attackers to trigger heap-based buffer overflows and possibly execute arbitrary code via (1) a crafted .FLV file, which triggers an overflow in demuxers/demux_flv.c; (2) a crafted .MOV file, which triggers an overflow in demuxers/demux_qt.c; (3) a crafted .RM file, which triggers an overflow in demuxers/demux_real.c; (4) a crafted .MVE file, which triggers an overflow in demuxers/demux_wc3movie.c; (5) a crafted .MKV file, which triggers an overflow in demuxers/ebml.c; or (6) a crafted .CAK file, which triggers an overflow in demuxers/demux_film.c.

Published Mar 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1523: ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ...

ZyXEL Prestige routers, including P-660, P-661, and P-662 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to obtain ISP and Dynamic DNS credentials by sending a direct request for (1) WAN.html, (2) wzPPPOE.html, and (3) rpDyDNS.html, and then reading the HTML source.

Published Mar 26, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1490: Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (ak...

Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659.

Published Mar 25, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1472: Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products...

Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.

Published Mar 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1484: The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system...

The password reset feature in PunBB 1.2.16 and earlier uses predictable random numbers based on the system time, which allows remote authenticated users to determine the new password via a brute force attack on a seed that is based on the approximate creation time of the targeted account. NOTE: this issue might be related to CVE-2006-5737.

Published Mar 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1467: CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell m...

CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URI, related to "received URLs in the message window." NOTE: this issue has been disputed due to the user-assisted nature, since the URL must be selected and launched by the victim

Published Mar 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1414: Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attack...

Cross-site scripting (XSS) vulnerability in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the tab parameter to (1) index.php, as demonstrated using mixed case and encoded whitespace characters in the tag; or (2) clientinfo.php, (3) invoices.php, (4) smartlinks.php, and (5) todo.php, as demonstrated using a META tag.

Published Mar 20, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1496: Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute...

Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

Published Mar 25, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1409: Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers...

Multiple directory traversal vulnerabilities in the Default theme in Exero CMS 1.0.1 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme parameter to (1) index.php, (2) editpassword.php, and (3) avatar.php in usercp/; (4) custompage.php; (5) errors/404.php; (6) memberslist.php and (7) profile.php in members/; (8) index.php and (9) fullview.php in news/; and (10) nopermission.php.

Published Mar 20, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1412: Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 throug...

Unspecified vulnerability in multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, and others, allows remote attackers to execute arbitrary code or cause a denial of service (hang or crash) via a malformed archive that triggers an unhandled exception, as demonstrated by the PROTOS GENOME test suite for Archive Formats.

Published Mar 20, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1463: Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server...

Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of an alert page.

Published Mar 24, 2008 · Updated Aug 7, 2024