Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-3883 | 1 Caudium | 1 Caudium | 2017-08-07 | 7.2 HIGH | N/A |
configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file. | |||||
CVE-2008-3884 | 1 Blogn | 1 Blogn | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-6176. | |||||
CVE-2008-3885 | 1 Blogn | 1 Blogn | 2017-08-07 | 6.8 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make content modifications. NOTE: some of these details are obtained from third party information. | |||||
CVE-2008-3886 | 1 Dotproject | 1 Dotproject | 2017-08-07 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action. | |||||
CVE-2008-3887 | 1 Dotproject | 1 Dotproject | 2017-08-07 | 6.0 MEDIUM | N/A |
Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action. | |||||
CVE-2008-3890 | 2 Amd, Freebsd | 2 Amd64, Freebsd | 2017-08-07 | 7.2 HIGH | N/A |
The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local users to gain privileges by triggering a GPF during the kernel's return from (1) an interrupt, (2) a trap, or (3) a system call. | |||||
CVE-2008-3903 | 2 Asterisk, Trixbox | 2 P B X, Pbx | 2017-08-07 | 3.5 LOW | N/A |
Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled, generates different responses depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames. | |||||
CVE-2008-3904 | 1 Lxde | 2 Gpicview, Lightweight X11 Desktop Environment | 2017-08-07 | 7.5 HIGH | N/A |
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. | |||||
CVE-2008-3907 | 1 Newsbeuter | 1 Newsbeuter | 2017-08-07 | 6.8 MEDIUM | N/A |
The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL. | |||||
CVE-2008-3910 | 1 Hsc | 1 Dns2tcp | 2017-08-07 | 10.0 HIGH | N/A |
dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact. | |||||
CVE-2008-3911 | 1 Linux | 1 Linux Kernel | 2017-08-07 | 7.2 HIGH | N/A |
The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read system call for the /proc/sys/sunrpc/transports file. | |||||
CVE-2008-3915 | 1 Linux | 1 Linux Kernel | 2017-08-07 | 9.3 HIGH | N/A |
Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl. | |||||
CVE-2008-3918 | 1 Ovidentia | 1 Ovidentia | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-3919 | 1 Justsystems | 1 Ichitaro | 2017-08-07 | 9.3 HIGH | N/A |
Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as exploited in the wild in August 2008. | |||||
CVE-2008-3920 | 1 Bitlbee | 1 Bitlbee | 2017-08-07 | 7.5 HIGH | N/A |
Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors. | |||||
CVE-2008-3927 | 1 Tiger | 1 Tiger | 2017-08-07 | 7.2 HIGH | N/A |
genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files. | |||||
CVE-2008-3928 | 1 Debian | 1 Honeyd Common | 2017-08-07 | 6.9 MEDIUM | N/A |
test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||||
CVE-2008-3929 | 1 Ampache | 1 Ampache | 2017-08-07 | 7.2 HIGH | N/A |
gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file. | |||||
CVE-2008-3930 | 1 Debian | 1 Citadel Server | 2017-08-07 | 6.9 MEDIUM | N/A |
migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |||||
CVE-2008-3931 | 1 R Foundation | 1 R | 2017-08-07 | 6.9 MEDIUM | N/A |
javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files. |