Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-1595 | 1 Ibm | 1 Aix | 2017-09-28 | 4.9 MEDIUM | N/A |
The proc filesystem in the kernel in IBM AIX 5.2 and 5.3 does not properly enforce directory permissions when a file executing from a directory has weaker permissions than the directory itself, which allows local users to obtain sensitive information. | |||||
CVE-2008-1593 | 1 Ibm | 1 Aix | 2017-09-28 | 7.2 HIGH | N/A |
The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to read and modify portions of memory and gain privileges via unspecified vectors involving a restart of a 64-bit process, probably related to the as_getadsp64 function. | |||||
CVE-2008-1376 | 1 Redhat | 2 Enterprise Linux, Nfs Utils | 2017-09-28 | 7.5 HIGH | N/A |
A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allow remote attackers to bypass intended access restrictions. | |||||
CVE-2008-1230 | 1 Jspwiki | 1 Jspwiki | 2017-09-28 | 9.3 HIGH | N/A |
Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspecified manipulation that attaches a .jsp file to an "entry page." | |||||
CVE-2008-1187 | 1 Sun | 3 Jdk, Jre, Sdk | 2017-09-28 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms. | |||||
CVE-2008-1139 | 1 Deslock | 1 Deslock | 2017-09-28 | 7.2 HIGH | N/A |
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, aka the "ring0 link list zero SYSTEM" vulnerability. | |||||
CVE-2008-1140 | 1 Deslock | 1 Deslock | 2017-09-28 | 7.2 HIGH | N/A |
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Control that overwrites a data structure associated with a mounted pseudo-filesystem, aka the "ring0 SYSTEM" vulnerability. | |||||
CVE-2007-3849 | 1 Redhat | 1 Enterprise Linux | 2017-09-28 | 1.9 LOW | N/A |
Red Hat Enterprise Linux (RHEL) 5 ships the rpm for the Advanced Intrusion Detection Environment (AIDE) before 0.13.1 with a database that lacks checksum information, which allows context-dependent attackers to bypass file integrity checks and modify certain files. | |||||
CVE-2007-3740 | 1 Linux | 1 Linux Kernel | 2017-09-28 | 4.4 MEDIUM | N/A |
The CIFS filesystem in the Linux kernel before 2.6.22, when Unix extension support is enabled, does not honor the umask of a process, which allows local users to gain privileges. | |||||
CVE-2007-6416 | 1 Xen | 1 Xen | 2017-09-28 | 4.6 MEDIUM | N/A |
The copy_to_user function in the PAL emulation functionality for Xen 3.1.2 and earlier, when running on ia64 systems, allows HVM guest users to access arbitrary physical memory by triggering certain mapping operations. | |||||
CVE-2007-6479 | 1 Dokeos | 1 Dokeos | 2017-09-28 | 4.9 MEDIUM | N/A |
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile" page) in Dokeos 1.8.4 allows remote authenticated users to upload and execute arbitrary PHP files via a filename with a double extension, which can then be accessed through a URI under main/upload/users/. | |||||
CVE-2007-6246 | 2 Adobe, Linux | 2 Flash Player, Linux Kernel | 2017-09-28 | 4.4 MEDIUM | N/A |
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0, when running on Linux, uses insecure permissions for memory, which might allow local users to gain privileges. | |||||
CVE-2007-6243 | 1 Adobe | 1 Flash Player | 2017-09-28 | 9.3 HIGH | N/A |
Adobe Flash Player 9.x up to 9.0.48.0, 8.x up to 8.0.35.0, and 7.x up to 7.0.70.0 does not sufficiently restrict the interpretation and usage of cross-domain policy files, which makes it easier for remote attackers to conduct cross-domain and cross-site scripting (XSS) attacks. | |||||
CVE-2007-5907 | 1 Xensource Inc | 1 Xen | 2017-09-28 | 4.7 MEDIUM | N/A |
Xen 3.1.1 does not prevent modification of the CR4 TSC from applications, which allows pv guests to cause a denial of service (crash). | |||||
CVE-2007-5644 | 1 Lussumo | 1 Vanilla | 2017-09-28 | 7.5 HIGH | N/A |
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities. | |||||
CVE-2007-5447 | 2 Ioncube, Php | 2 Php Encoder, Php | 2017-09-28 | 4.3 MEDIUM | N/A |
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_functions restrictions, which allows context-dependent attackers to bypass intended limitations, as demonstrated by reading arbitrary files via the ioncube_read_file function. | |||||
CVE-2007-5278 | 1 Zomplog | 1 Zomplog | 2017-09-28 | 4.3 MEDIUM | N/A |
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable. | |||||
CVE-2007-5237 | 1 Sun | 2 Jdk, Jre | 2017-09-28 | 7.1 HIGH | N/A |
Java Web Start in Sun JDK and JRE 6 Update 2 and earlier does not properly enforce access restrictions for untrusted applications, which allows user-assisted remote attackers to read and modify local files via an untrusted application, aka "two vulnerabilities." | |||||
CVE-2007-5062 | 1 Adam Scheinberg | 1 Flip | 2017-09-28 | 7.5 HIGH | N/A |
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register action. | |||||
CVE-2007-4647 | 1 2coolcode | 1 Our Space | 2017-09-28 | 5.0 MEDIUM | N/A |
newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably involving unrestricted functionality in uploadmedia.cgi. |