Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2008-6560

больше 17 лет назад

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

CVSS2: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6552

больше 17 лет назад

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-6549

больше 17 лет назад

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6548

больше 17 лет назад

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6547

больше 17 лет назад

schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-6539

больше 17 лет назад

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2008-6538

больше 17 лет назад

DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6536

больше 17 лет назад

Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-6533

больше 17 лет назад

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-6532

больше 17 лет назад

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-6514

больше 17 лет назад

The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.

CVSS2: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2008-6507

больше 17 лет назад

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6506

больше 17 лет назад

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-6505

больше 17 лет назад

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.

CVSS2: 5
EPSS: Высокий
ubuntu логотип

CVE-2008-6472

больше 17 лет назад

The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-6428

больше 17 лет назад

The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-6398

больше 17 лет назад

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-6397

больше 17 лет назад

rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2008-6393

больше 17 лет назад

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2008-6373

больше 17 лет назад

Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external commands," and "writing newlines and submitting service comments."

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-6560

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and memory corruption) via a cluster.conf file with many lines. NOTE: it is not clear whether this issue crosses privilege boundaries in realistic uses of the product.

CVSS2: 7.8
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6552

Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.

CVSS2: 6.9
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6549

The password_checker function in config/multiconfig.py in MoinMoin 1.6.1 uses the cracklib and python-crack features even though they are not thread-safe, which allows remote attackers to cause a denial of service (segmentation fault and crash) via unknown vectors.

CVSS2: 5
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6548

The rst parser (parser/text_rst.py) in MoinMoin 1.6.1 does not check the ACL of an included page, which allows attackers to read unauthorized include files via unknown vectors.

CVSS2: 5
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6547

schema.py in FormEncode for Python (python-formencode) 1.0 does not apply the chained_validators feature, which allows attackers to bypass intended access restrictions via unknown vectors.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6539

Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.

CVSS2: 6.5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6538

DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.

CVSS2: 5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6536

Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).

CVSS2: 10
3%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6533

Drupal 5.x before 5.13 and 6.x before 6.7 does not delete all related content when an input format is deleted, which prevents the content from being properly filtered and allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6532

Multiple cross-site request forgery (CSRF) vulnerabilities in the update feature in Drupal 5.x before 5.13 and 6.x before 6.7 allow remote attackers to perform unauthorized actions as the superuser via unspecified vectors, as demonstrated by causing the superuser to "execute old updates" that modify the database.

CVSS2: 6.8
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6514

The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using Expo mouse shortcuts, a related issue to CVE-2007-3920.

CVSS2: 6.2
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6507

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.

CVSS2: 5
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6506

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknown vectors.

CVSS2: 5
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6505

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.x and (2) DefaultStaticContentLoader in 2.1.x.

CVSS2: 5
73%
Высокий
больше 17 лет назад
ubuntu логотип
CVE-2008-6472

The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6428

The CGI framework in Kaya 0.4.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6398

sng_regress in SNG 1.0.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/recompiled$$.png, (2) /tmp/decompiled$$.sng, and (3) /tmp/canonicalized$$.sng temporary files.

CVSS2: 6.9
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6397

rlatex in AlcoveBook sgml2x 1.0.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 4.4
0%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-6393

PSI Jabber client before 0.12.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a file transfer request with a negative value in a SOCKS5 option, which bypasses a signed integer check and triggers an integer overflow and a heap-based buffer overflow.

CVSS2: 10
18%
Средний
больше 17 лет назад
ubuntu логотип
CVE-2008-6373

Unspecified vulnerability in Nagios before 3.0.6 has unspecified impact and remote attack vectors related to CGI programs, "adaptive external commands," and "writing newlines and submitting service comments."

CVSS2: 5
5%
Низкий
больше 17 лет назад

Уязвимостей на страницу