Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 63 796

Количество 63 796

ubuntu логотип

CVE-2008-6767

почти 17 лет назад

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-6762

почти 17 лет назад

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-6755

почти 17 лет назад

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6680

почти 17 лет назад

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6679

почти 17 лет назад

Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6621

почти 17 лет назад

Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6603

почти 17 лет назад

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6594

почти 17 лет назад

SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-6587

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, allows remote attackers to hijack the authentication of users for requests that force the download of arbitrary torrent files via the upurl parameter.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6585

почти 17 лет назад

Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6584

почти 17 лет назад

html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extension in the url_upload parameter, which is downloaded by TorrentFlux and can be accessed via a direct request in a html/downloads/ user directory.

CVSS2: 6
EPSS: Низкий
ubuntu логотип

CVE-2008-6560

почти 17 лет назад

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6552

почти 17 лет назад

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-6549

почти 17 лет назад

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6548

почти 17 лет назад

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6547

почти 17 лет назад

schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-6539

почти 17 лет назад

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2008-6538

почти 17 лет назад

DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6536

почти 17 лет назад

Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-6533

почти 17 лет назад

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-6767

wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to upgrade the application, and possibly cause a denial of service (application outage), via a direct request.

CVSS2: 10
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6762

Open redirect vulnerability in wp-admin/upgrade.php in WordPress, probably 2.6.x, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the backto parameter.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6755

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modify this file by accessing it through a (1) PHP or (2) CGI script.

CVSS2: 5
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6680

libclamav/pe.c in ClamAV before 0.95 allows remote attackers to cause a denial of service (crash) via a crafted EXE file that triggers a divide-by-zero error.

CVSS2: 5
7%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6679

Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.

CVSS2: 5
6%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6621

Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.

CVSS2: 7.8
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6603

MoinMoin 1.6.2 and 1.7 does not properly enforce ACL checks when acl_hierarchic is set to True, which might allow remote attackers to bypass intended access restrictions, a different vulnerability than CVE-2008-1937.

CVSS2: 6.8
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6594

SQL injection vulnerability in the cm_rdfexport extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS2: 7.5
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6587

Cross-site request forgery (CSRF) vulnerability in index.tmpl in Vuze (formerly Azureus HTML WebUI), probably 0.7.6, allows remote attackers to hijack the authentication of users for requests that force the download of arbitrary torrent files via the upurl parameter.

CVSS2: 6.8
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6585

Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack the authentication of administrators for requests that add new accounts via the addUser action.

CVSS2: 6.8
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6584

html/index.php in TorrentFlux 2.3 allows remote authenticated users to execute arbitrary code via a URL with a file containing an executable extension in the url_upload parameter, which is downloaded by TorrentFlux and can be accessed via a direct request in a html/downloads/ user directory.

CVSS2: 6
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6560

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

CVSS2: 7.8
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

CVSS2: 6.9
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6549

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.

CVSS2: 5
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6548

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

CVSS2: 5
0%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6547

schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

CVSS2: 7.5
1%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6539

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

CVSS2: 6.5
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6538

DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

CVSS2: 5
3%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6536

Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).

CVSS2: 10
2%
Низкий
почти 17 лет назад
ubuntu логотип
CVE-2008-6533

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
0%
Низкий
почти 17 лет назад

Уязвимостей на страницу