LiveActive security incident?Get immediate response
CVE archive

April 2008

Browse CVE records published in April 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 659 matching CVEs · Page 11 of 14.

Unknown · CVSS Not scored

CVE-2008-1729: The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) ed...

The menu system in Drupal 6 before 6.2 has incorrect menu settings, which allows remote attackers to (1) edit the profile pages of arbitrary users, and obtain sensitive information from (2) tracker and (3) blog pages, related to a missing check for the "access content" permission; and (4) allows remote authenticated users, with administration page view access, to edit content types.

Published Apr 11, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1693: The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Ev...

The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.

Published Apr 18, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1690: WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a...

WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a long URI in HTTP requests to TCP port 801. NOTE: some of these details are obtained from third party information.

Published Apr 7, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1637: PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP sourc...

PowerDNS Recursor before 3.1.5 uses insufficient randomness to calculate (1) TRXID values and (2) UDP source port numbers, which makes it easier for remote attackers to poison a DNS cache, related to (a) algorithmic deficiencies in rand and random functions in external libraries, (b) use of a 32-bit seed value, and (c) choice of the time of day as the sole seeding information.

Published Apr 2, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1654: Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote att...

Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to perform Cross-Site Request Forgery (CSRF) style attacks by using the Flash navigateToURL function to send a SOAP message to a UPnP control point, as demonstrated by changing the primary DNS server.

Published Apr 2, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-1642: Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include a...

Directory traversal vulnerability in index.php in Sava's GuestBook 2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Apr 2, 2008 · Updated Aug 7, 2024