Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75 967

Количество 75 967

ubuntu логотип

CVE-2008-2302

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2292

больше 18 лет назад

Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-2285

больше 18 лет назад

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-2276

больше 18 лет назад

Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-2266

больше 18 лет назад

uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.

CVSS2: 4.4
EPSS: Низкий
ubuntu логотип

CVE-2008-2238

почти 18 лет назад

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2237

почти 18 лет назад

Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2236

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the flav parameter (flavour variable). NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2235

около 18 лет назад

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2008-2232

около 18 лет назад

The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2008-2231

около 18 лет назад

SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-2230

около 18 лет назад

Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2008-2168

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2008-2152

около 18 лет назад

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-2149

больше 18 лет назад

Stack-based buffer overflow in the searchwn function in Wordnet 2.0, 2.1, and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-2148

больше 18 лет назад

The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.

CVSS2: 3.6
EPSS: Низкий
ubuntu логотип

CVE-2008-2147

больше 18 лет назад

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

CVSS2: 4.6
EPSS: Низкий
ubuntu логотип

CVE-2008-2146

больше 18 лет назад

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-2142

больше 18 лет назад

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2008-2137

около 18 лет назад

The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.

CVSS2: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2008-2302

Cross-site scripting (XSS) vulnerability in the login form in the administration application in Django 0.91 before 0.91.2, 0.95 before 0.95.3, and 0.96 before 0.96.2 allows remote attackers to inject arbitrary web script or HTML via the URI of a certain previous request.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2292

Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for Perl, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large OCTETSTRING in an attribute value pair (AVP).

CVSS2: 6.8
8%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2285

The ssh-vulnkey tool on Ubuntu Linux 7.04, 7.10, and 8.04 LTS does not recognize authorized_keys lines that contain options, which makes it easier for remote attackers to exploit CVE-2008-0166 by guessing a key that was not identified by this tool.

CVSS2: 5
2%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2276

Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to create new administrative users via a crafted link.

CVSS2: 6.8
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2266

uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.

CVSS2: 4.4
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2238

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

CVSS2: 9.3
7%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-2237

Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code via a crafted WMF file associated with a StarOffice/StarSuite document.

CVSS2: 9.3
6%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-2236

Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via the flav parameter (flavour variable). NOTE: some of these details are obtained from third party information.

CVSS2: 4.3
1%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-2235

OpenSC before 0.11.5 uses weak permissions (ADMIN file control information of 00) for the 5015 directory on smart cards and USB crypto tokens running Siemens CardOS M4, which allows physically proximate attackers to change the PIN.

CVSS2: 4.9
0%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2232

The expand_template function in afuse.c in afuse 0.2 allows local users to gain privileges via shell metacharacters in a pathname.

CVSS2: 4.6
0%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2231

SQL injection vulnerability in Slashdot Like Automated Storytelling Homepage (Slash) (aka Slashcode) R_2_5_0_94 and earlier allows remote attackers to execute SQL commands and read table information via the id parameter.

CVSS2: 7.5
2%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2230

Untrusted search path vulnerability in (1) reportbug 3.8 and 3.31, and (2) reportbug-ng before 0.2008.06.04, allows local users to execute arbitrary code via a malicious module file in the current working directory.

CVSS2: 4.6
1%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2168

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

CVSS2: 4.3
55%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2008-2152

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.

CVSS2: 9.3
6%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2149

Stack-based buffer overflow in the searchwn function in Wordnet 2.0, 2.1, and 3.0 might allow context-dependent attackers to execute arbitrary code via a long command line option. NOTE: this issue probably does not cross privilege boundaries except in cases in which Wordnet is used as a back end.

CVSS2: 7.5
4%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2148

The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which allows local users to modify file times of arbitrary files, possibly leading to a denial of service.

CVSS2: 3.6
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2147

Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current working directory.

CVSS2: 4.6
0%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2146

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

CVSS2: 7.5
3%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2142

Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.

CVSS2: 6.8
4%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2008-2137

The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.

CVSS2: 4.4
0%
Низкий
около 18 лет назад

Уязвимостей на страницу