Monthly Archives: April 2008



CVE-2008-1973 (subedit_player)

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Posted in Badware | Leave a comment

CVE-2008-1973 (subedit_player)

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Posted in Badware | Leave a comment

CVE-2008-1986 (Pixel Motion Blog)

Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

Posted in Badware | Leave a comment

CVE-2008-1973 (subedit_player)

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Posted in Badware | Leave a comment

CVE-2008-1973 (subedit_player)

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Posted in Badware | Leave a comment

CVE-2008-1973 (subedit_player)

Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.

Posted in Badware | Leave a comment

CVE-2008-1975 (e_reserve)

SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via the ID_loc parameter.

Posted in Badware | Leave a comment

CVE-2008-1986 (Pixel Motion Blog)

Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

Posted in Badware | Leave a comment

CVE-2008-1986 (Pixel Motion Blog)

Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attackers to inject arbitrary web script or HTML via the jours parameter.

Posted in Badware | Leave a comment

CVE-2008-1985 (digitalhive)

Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary web script or HTML via the mt parameter, possibly related to membres.php.

Posted in Badware | Leave a comment