VYPR

CVEs

384,141 total · page 7015 of 7,683

  • CVE-2008-5166Nov 19, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in riddle.php in Riddles Website 1.2.1 allows remote attackers to execute arbitrary SQL commands via the riddleid parameter.

  • CVE-2008-5165Nov 19, 2008
    risk 0.00cvss —epss 0.01

    Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.

  • CVE-2008-5164Nov 19, 2008
    risk 0.03cvss —epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) viewarticle.php and (b) viewarticle2.php and the (2) PATH_INFO to viewarticle.php.

  • CVE-2008-5163Nov 19, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in The Rat CMS Pre-Alpha 2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) viewarticle.php and (2) viewarticle2.php.

  • CVE-2008-5161LowNov 19, 2008
    risk 0.29cvss 3.7epss 0.19

    Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and…

  • CVE-2008-5160Nov 18, 2008
    risk 0.03cvss —epss 0.03

    Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via multiple invalid requests with the HTTP GET, DELETE, OPTIONS, and possibly other methods, related to a "204 No Content error."

  • CVE-2008-5159Nov 18, 2008
    risk 0.08cvss —epss 0.60

    Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.

  • CVE-2008-5158Nov 18, 2008
    risk 0.00cvss —epss 0.02

    Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to bypass authentication and perform administrative actions via vectors involving "simply skipping the auth stage."

  • CVE-2008-5157Nov 18, 2008
    risk 0.00cvss —epss 0.00

    tau 2.16.4 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/makefile.tau.*.##### or (2) /tmp/makefile.tau*.##### temporary file, related to the (a) tau_cxx, (b) tau_f90, and (c) tau_cc scripts.

  • CVE-2008-5156Nov 18, 2008
    risk 0.00cvss —epss 0.00

    si_mkbootserver in systemimager-server 3.6.3 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.inetd.conf or (2) /tmp/pxe.conf.*.tmp temporary file.

  • CVE-2008-5155Nov 18, 2008
    risk 0.00cvss —epss 0.01

    mail2sms.sh in smsclient 2.0.8z allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/header.##### or (2) /tmp/body.##### temporary file, or append data to arbitrary files via a symlink attack on the (3) /tmp/sms.log temporary file.

  • CVE-2008-5154Nov 18, 2008
    risk 0.00cvss —epss 0.00

    bluetooth.rc in p3nfs 5.19 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/blue.log temporary file.

  • CVE-2008-5153Nov 18, 2008
    risk 0.00cvss —epss 0.00

    spell-check-logic.cgi in Moodle 1.8.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/spell-check-debug.log, (2) /tmp/spell-check-before, or (3) /tmp/spell-check-after temporary file.

  • CVE-2008-5152Nov 18, 2008
    risk 0.00cvss —epss 0.00

    inmail-show in mh-book 200605 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/inmail#####.log or (2) /tmp/inmail#####.stdin temporary file.

  • CVE-2008-5151Nov 18, 2008
    risk 0.00cvss —epss 0.00

    test_parser.py in mayavi 1.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/err.log temporary file.

  • CVE-2008-5150Nov 18, 2008
    risk 0.00cvss —epss 0.00

    sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file.

  • CVE-2008-5149Nov 18, 2008
    risk 0.00cvss —epss 0.00

    fwd_check.sh in libncbi6 6.1.20080302 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.

  • CVE-2008-5148Nov 18, 2008
    risk 0.00cvss —epss 0.00

    sch2eaglepos.sh in geda-gnetlist 1.4.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.

  • CVE-2008-5147Nov 18, 2008
    risk 0.00cvss —epss 0.00

    test-pipe-to-pyodconverter.org.sh in docvert 2.4 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/outer.odt temporary file.

  • CVE-2008-5146Nov 18, 2008
    risk 0.00cvss —epss 0.00

    add-accession-numbers in ctn 3.0.6 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/accession temporary file.

  • CVE-2008-5145Nov 18, 2008
    risk 0.00cvss —epss 0.00

    ltpmenu in ltp 20060918 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/runltp.mainmenu.##### temporary file.

  • CVE-2008-5144Nov 18, 2008
    risk 0.00cvss —epss 0.00

    nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvidia-cg-toolkit-manifest temporary file.

  • CVE-2008-5143Nov 18, 2008
    risk 0.00cvss —epss 0.00

    mgt-helper in multi-gnome-terminal 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/*.debug or (2) /tmp/*.env temporary file.

  • CVE-2008-5142Nov 18, 2008
    risk 0.00cvss —epss 0.00

    sendbug in freebsd-sendpr 3.113+5.3 on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pr.##### temporary file.

  • CVE-2008-5141Nov 18, 2008
    risk 0.00cvss —epss 0.00

    flamethrower in flamethrower 0.1.8 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/multicast.tar.##### temporary file.

  • CVE-2008-5140Nov 18, 2008
    risk 0.00cvss —epss 0.00

    trend-autoupdate.new in mailscanner 4.55.10 and other versions before 4.74.16-1 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/opr.ini.##### or (2) /tmp/lpt*.zip temporary file.

  • CVE-2008-5139Nov 18, 2008
    risk 0.00cvss —epss 0.00

    updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.

  • CVE-2008-5138Nov 18, 2008
    risk 0.00cvss —epss 0.00

    passwdehd in libpam-mount 0.43 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/passwdehd.##### temporary file.

  • CVE-2008-5137Nov 18, 2008
    risk 0.00cvss —epss 0.00

    tkman in tkman 2.2 allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/tkman##### or (2) /tmp/ll temporary file.

  • CVE-2008-5136Nov 18, 2008
    risk 0.00cvss —epss 0.00

    tkusr in tkusr 0.82 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/tkusr.pgm temporary file.

  • CVE-2008-5135Nov 18, 2008
    risk 0.00cvss —epss 0.00

    os-prober in os-prober 1.17 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/mounted-map or (2) /tmp/raided-map temporary file. NOTE: the vendor disputes this issue, stating "the insecure code path should only ever run inside a d-i…

  • CVE-2008-5134Nov 18, 2008
    risk 0.00cvss —epss 0.05

    Buffer overflow in the lbs_process_bss function in drivers/net/wireless/libertas/scan.c in the libertas subsystem in the Linux kernel before 2.6.27.5 allows remote attackers to have an unknown impact via an "invalid beacon/probe response."

  • CVE-2008-5133Nov 18, 2008
    risk 0.00cvss —epss 0.02

    ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass…

  • CVE-2008-5132Nov 18, 2008
    risk 0.03cvss —epss 0.02

    SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header.

  • CVE-2008-5131Nov 18, 2008
    risk 0.03cvss —epss 0.01

    Multiple SQL injection vulnerabilities in Develop It Easy News And Article System 1.4 allow remote attackers to execute arbitrary SQL commands via (1) the aid parameter to article_details.php, and the (2) username and (3) password to the admin panel (admin/index.php).

  • CVE-2008-5130Nov 18, 2008
    risk 0.00cvss —epss 0.01

    Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12cal.mdb.

  • CVE-2008-5129Nov 18, 2008
    risk 0.00cvss —epss 0.01

    Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12poll.mdb.

  • CVE-2008-5128Nov 18, 2008
    risk 0.00cvss —epss 0.01

    Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12member.mdb.

  • CVE-2008-5127Nov 18, 2008
    risk 0.00cvss —epss 0.01

    Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request to o12con.mdb.

  • CVE-2008-5126Nov 18, 2008
    risk 0.03cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web script or HTML via the search_query parameter.

  • CVE-2008-5125Nov 18, 2008
    risk 0.03cvss —epss 0.02

    admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

  • CVE-2008-5124Nov 18, 2008
    risk 0.00cvss —epss 0.02

    JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

  • CVE-2008-5123Nov 18, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

  • CVE-2008-5122Nov 18, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in WorkArea/ContentRatingGraph.aspx in Ektron CMS400.NET 7.5.2 and earlier allows remote attackers to execute arbitrary SQL commands via the res parameter.

  • CVE-2008-5121Nov 18, 2008
    risk 0.03cvss —epss 0.01

    dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl…

  • CVE-2008-5120Nov 18, 2008
    risk 0.04cvss —epss 0.10

    Stack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbitrary code via a long request string.

  • CVE-2008-5119Nov 18, 2008
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in search.php in Scripts4Profit DXShopCart 4.30mc allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

  • CVE-2008-5118Nov 18, 2008
    risk 0.00cvss —epss 0.02

    Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "frame injection."

  • CVE-2008-5117Nov 18, 2008
    risk 0.00cvss —epss 0.03

    Open redirect vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

  • CVE-2008-5116Nov 18, 2008
    risk 0.00cvss —epss 0.04

    Directory traversal vulnerability in idm/includes/helpServer.jsp in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to read arbitrary files in the filesystem of the IDM server via directory traversal sequences in the ext parameter.