Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-2290 | 1 Symantec | 1 Altiris Deployment Solution | 2017-08-07 | 7.2 HIGH | N/A |
Unspecified vulnerability in the Agent user interface in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors. | |||||
CVE-2008-2289 | 1 Symantec | 1 Altiris Deployment Solution | 2017-08-07 | 7.2 HIGH | N/A |
Unspecified vulnerability in a tooltip element in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain privileges via unknown attack vectors. | |||||
CVE-2008-2288 | 1 Symantec | 1 Altiris Deployment Solution | 2017-08-07 | 3.6 LOW | N/A |
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 has insufficient access control for deletion and modification of registry keys, which allows local users to cause a denial of service or obtain sensitive information. | |||||
CVE-2008-2287 | 1 Symantec | 1 Altiris Deployment Solution | 2017-08-07 | 7.2 HIGH | N/A |
Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to gain privileges by replacing an application component with a Trojan horse. | |||||
CVE-2008-2300 | 1 Citrix | 4 Access Essentials, Citrix Presentation Server, Desktop Server and 1 more | 2017-08-07 | 6.5 MEDIUM | N/A |
Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors. | |||||
CVE-2008-2232 | 1 Afuse | 1 Afuse | 2017-08-07 | 4.6 MEDIUM | N/A |
The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname. | |||||
CVE-2008-2226 | 1 Openkm | 1 Openkm | 2017-08-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-2174 | 1 Shelter Manager | 1 Animal Shelter Manager | 2017-08-07 | 6.5 MEDIUM | N/A |
Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related to "various areas where security was missing." | |||||
CVE-2008-2146 | 1 Wordpress | 1 Wordpress | 2017-08-07 | 7.5 HIGH | N/A |
wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages. | |||||
CVE-2008-2139 | 1 Rpath | 1 Appliance Platform Agent | 2017-08-07 | 6.5 MEDIUM | N/A |
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account. | |||||
CVE-2008-2105 | 1 Mozilla | 1 Bugzilla | 2017-08-07 | 3.5 LOW | N/A |
email_in.pl in Bugzilla 2.23.4, 3.0.x before 3.0.4, and 3.1.x before 3.1.4 allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses. | |||||
CVE-2008-2148 | 1 Linux | 1 Linux Kernel | 2017-08-07 | 3.6 LOW | N/A |
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service. | |||||
CVE-2008-2104 | 1 Mozilla | 1 Bugzilla | 2017-08-07 | 4.0 MEDIUM | N/A |
The WebService in Bugzilla 3.1.3 allows remote authenticated users without canconfirm privileges to create NEW or ASSIGNED bug entries via a request to the XML-RPC interface, which bypasses the canconfirm check. | |||||
CVE-2008-2078 | 1 Robocode | 1 Robocode | 2017-08-07 | 7.5 HIGH | N/A |
Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT Event Queue. | |||||
CVE-2008-1940 | 1 Grsecurity | 1 Grsecurity Kernel Patch | 2017-08-07 | 4.6 MEDIUM | N/A |
The RBAC functionality in grsecurity before 2.1.11-2.6.24.5 and 2.1.11-2.4.36.2 does not enforce user_transition_deny and user_transition_allow rules for the (1) sys_setfsuid and (2) sys_setfsgid calls, which allows local users to bypass restrictions for those calls. | |||||
CVE-2008-1937 | 1 Moinmoin | 1 Moinmoin | 2017-08-07 | 6.8 MEDIUM | N/A |
The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, which allows remote attackers to gain privileges. | |||||
CVE-2008-1877 | 1 Debian | 1 Tss | 2017-08-07 | 2.1 LOW | N/A |
tss 0.8.1 allows local users to read arbitrary files via the -a parameter, which is processed while tss is running with privileges. | |||||
CVE-2008-1834 | 1 Swfdec | 1 Swfdec | 2017-08-07 | 4.3 MEDIUM | N/A |
swfdec_load_object.c in Swfdec before 0.6.4 does not properly restrict local file access from untrusted sandboxes, which allows remote attackers to read arbitrary files via a crafted Flash file. | |||||
CVE-2008-1810 | 2 Linux, Sap | 2 Linux Kernel, Maxdb | 2017-08-07 | 4.4 MEDIUM | N/A |
Untrusted search path vulnerability in dbmsrv in SAP MaxDB 7.6.03.15 on Linux allows local users to gain privileges via a modified PATH environment variable. | |||||
CVE-2008-2147 | 1 Videolan | 1 Vlc | 2017-08-07 | 4.6 MEDIUM | N/A |
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory. |