Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-3940 | 1 Hp | 1 Openvms | 2017-08-07 | 4.4 MEDIUM | N/A |
Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file. | |||||
CVE-2008-3942 | 1 Ozsari | 1 Full Php Emlak Script | 2017-08-07 | 7.5 HIGH | N/A |
SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||||
CVE-2008-3946 | 1 Hp | 1 Openvms | 2017-08-07 | 4.9 MEDIUM | N/A |
The finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to read arbitrary files via a link corresponding to a (1) .plan or (2) .project file. | |||||
CVE-2008-3947 | 1 Hp | 1 Openvms | 2017-08-07 | 7.2 HIGH | N/A |
DCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line. | |||||
CVE-2008-3949 | 1 Suse | 1 Suse Linux | 2017-08-07 | 7.2 HIGH | N/A |
emacs/lisp/progmodes/python.el in Emacs 22.1 and 22.2 imports Python script from the current working directory during editing of a Python file, which allows local users to execute arbitrary code via a Trojan horse Python file. | |||||
CVE-2008-3956 | 1 Microsoft | 1 Organization Chart | 2017-08-07 | 9.3 HIGH | N/A |
orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file. | |||||
CVE-2008-3957 | 1 Microsoft | 1 Windows Image Acquisition Logger | 2017-08-07 | 9.3 HIGH | N/A |
The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument to the Save method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2008-3958 | 1 Ibm | 1 Db2 | 2017-08-07 | 7.5 HIGH | N/A |
IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. NOTE: this may overlap CVE-2008-3858. NOTE: this issue exists because of an incomplete fix for CVE-2008-3959. | |||||
CVE-2008-3959 | 1 Ibm | 1 Db2 | 2017-08-07 | 5.0 MEDIUM | N/A |
IBM DB2 UDB 8.1 before FixPak 16, 8.2 before FixPak 9, and 9.1 before FixPak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted SQLJRA packet within a CONNECT/ATTACH data stream that simulates a V7 client connect/attach request. | |||||
CVE-2008-3960 | 1 Ibm | 1 Db2 Universal Database | 2017-08-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the JDBC Applet Server Service (aka db2jds) in IBM DB2 UDB 8 before Fixpak 17 allows remote attackers to cause a denial of service (service crash) via "malicious packets." | |||||
CVE-2008-3961 | 1 Adobe | 1 Illustrator | 2017-08-07 | 9.3 HIGH | N/A |
Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbitrary code via a crafted AI file. | |||||
CVE-2008-3962 | 1 Ssmtp | 1 Ssmtp | 2017-08-07 | 2.6 LOW | N/A |
The from_format function in ssmtp.c in ssmtp 2.61 and 2.62, in certain configurations, uses uninitialized memory for the From: field of an e-mail message, which might allow remote attackers to obtain sensitive information (memory contents) in opportunistic circumstances by reading a message. | |||||
CVE-2008-3968 | 1 Punbb | 1 Punbb | 2017-08-07 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in userlist.php in PunBB before 1.2.20 allows remote attackers to inject arbitrary web script or HTML via the p parameter. | |||||
CVE-2008-3970 | 1 Pam Mount | 1 Pam Mount | 2017-08-07 | 6.9 MEDIUM | N/A |
pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. | |||||
CVE-2008-3971 | 1 Gmanedit2 | 1 Gmanedit | 2017-08-07 | 9.3 HIGH | N/A |
Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported using a configuration file, but that vector does not have a scenario that crosses privilege boundaries. | |||||
CVE-2008-3972 | 2 Opensc-project, Siemens | 2 Opensc, Cardos | 2017-08-07 | 6.6 MEDIUM | N/A |
pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235. | |||||
CVE-2008-3975 | 1 Oracle | 1 Application Server | 2017-08-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3977. | |||||
CVE-2008-3976 | 1 Oracle | 2 Database 10g, Database 9i | 2017-08-07 | 5.5 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-3413 and CVE-2009-3414. | |||||
CVE-2008-3977 | 1 Oracle | 1 Application Server | 2017-08-07 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975. | |||||
CVE-2008-3980 | 1 Oracle | 1 Database 10g | 2017-08-07 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in the Upgrade component in Oracle Database 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. |