Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2008-3933

почти 18 лет назад

Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.

CVSS2: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3932

почти 18 лет назад

Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-3931

почти 18 лет назад

javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3930

почти 18 лет назад

migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3929

почти 18 лет назад

gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2008-3928

почти 18 лет назад

test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2008-3927

почти 18 лет назад

genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2008-3920

почти 18 лет назад

Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-3916

почти 18 лет назад

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3915

почти 18 лет назад

Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3914

почти 18 лет назад

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-3913

почти 18 лет назад

Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-3912

почти 18 лет назад

libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-3911

почти 18 лет назад

The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read system call for the /proc/sys/sunrpc/transports file.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2008-3910

почти 18 лет назад

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-3909

почти 18 лет назад

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2008-3908

почти 18 лет назад

Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-3907

почти 18 лет назад

The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-3906

почти 18 лет назад

CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3905

почти 18 лет назад

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

CVSS2: 5.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-3933

Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.

CVSS2: 3.3
1%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3932

Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.

CVSS2: 5
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3931

javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3930

migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3929

gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/filelist temporary file.

CVSS2: 7.2
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3928

test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on a temporary file.

CVSS2: 6.9
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3927

genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.

CVSS2: 7.2
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3920

Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3916

Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename. NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3915

Buffer overflow in nfsd in the Linux kernel before 2.6.26.4, when NFSv4 is enabled, allows remote attackers to have an unknown impact via vectors related to decoding an NFSv4 acl.

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3914

Multiple unspecified vulnerabilities in ClamAV before 0.94 have unknown impact and attack vectors related to file descriptor leaks on the "error path" in (1) libclamav/others.c and (2) libclamav/sis.c.

CVSS2: 10
4%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3913

Multiple memory leaks in freshclam/manager.c in ClamAV before 0.94 might allow attackers to cause a denial of service (memory consumption) via unspecified vectors related to "error handling logic".

CVSS2: 5
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3912

libclamav in ClamAV before 0.94 allows attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an out-of-memory condition.

CVSS2: 5
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3911

The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read system call for the /proc/sys/sunrpc/transports file.

CVSS2: 7.2
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3910

dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.

CVSS2: 10
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3909

The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.

CVSS2: 5.8
1%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3908

Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file). NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.

CVSS2: 10
4%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3907

The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.

CVSS2: 6.8
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3906

CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.

CVSS2: 4.3
7%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-3905

resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.

CVSS2: 5.8
2%
Низкий
почти 18 лет назад

Уязвимостей на страницу