Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-0657 | 1 Sun | 2 Jdk, Jre | 2017-09-28 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs. | |||||
CVE-2008-0588 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors. | |||||
CVE-2008-0584 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) swap, (2) swapoff, and (3) swapon programs. | |||||
CVE-2008-0573 | 1 Safenet | 3 Ipsecdrv.sys, Safenet Highassurance Remote, Softremote Vpn Client | 2017-09-28 | 7.2 HIGH | N/A |
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL request. | |||||
CVE-2008-0425 | 1 Frimousse | 1 Frimousse | 2017-09-28 | 5.0 MEDIUM | N/A |
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary directories via a full pathname in the name parameter. | |||||
CVE-2008-0350 | 1 Evilsentinel | 1 Evilsentinel | 2017-09-28 | 7.5 HIGH | N/A |
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes. | |||||
CVE-2008-0329 | 1 Julien Plesniak | 1 Lulieblog | 2017-09-28 | 5.0 MEDIUM | N/A |
LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which allows remote attackers to accept comments, delete comments, and delete articles via the id parameter. | |||||
CVE-2008-0233 | 1 Zero Cms | 1 Zero Cms | 2017-09-28 | 7.5 HIGH | N/A |
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by uploading an avatar file with an accepted Content-Type such as image/jpeg. | |||||
CVE-2008-0246 | 1 Uploadscript | 2 Uploadimage, Uploadscript | 2017-09-28 | 10.0 HIGH | N/A |
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | |||||
CVE-2008-0245 | 1 Uploadscript | 2 Uploadimage, Uploadscript | 2017-09-28 | 7.5 HIGH | N/A |
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | |||||
CVE-2007-6638 | 1 March Networks | 1 3204 Dvr | 2017-09-28 | 10.0 HIGH | N/A |
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz. | |||||
CVE-2007-6603 | 1 Hotscripts | 1 Hot Or Not Clone | 2017-09-28 | 5.0 MEDIUM | N/A |
Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php. | |||||
CVE-2008-1946 | 1 Gnu | 1 Coreutils | 2017-09-28 | 4.4 MEDIUM | N/A |
The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command line, related to improper use of the pam_succeed_if.so module. | |||||
CVE-2008-1790 | 1 Iscripts | 1 Socialware | 2017-09-28 | 6.5 MEDIUM | N/A |
Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo file in the "Manage Settings" functionality. NOTE: remote exploitation is facilitated by a separate SQL injection vulnerability. | |||||
CVE-2008-1784 | 1 Prozilla | 1 Topsites | 2017-09-28 | 7.5 HIGH | N/A |
Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php in siteadmin/. | |||||
CVE-2008-1783 | 1 Prozilla | 1 Reviews | 2017-09-28 | 6.4 MEDIUM | N/A |
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.php. | |||||
CVE-2008-1710 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable. | |||||
CVE-2008-1668 | 1 Hp | 1 Hp-ux | 2017-09-28 | 10.0 HIGH | N/A |
ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which PAM authentication can succeed even though no passwd entry is available for a user, which allows remote attackers to gain privileges, as demonstrated by a login attempt for an LDAP account when nsswitch.conf does not specify LDAP for passwd information. | |||||
CVE-2008-1600 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a different vulnerability than CVE-2004-1329. | |||||
CVE-2008-1599 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoking (1) atmstat, (2) entstat, (3) fddistat, (4) hdlcstat, or (5) tokstat. |