VYPR

CVEs

384,118 total · page 7018 of 7,683

  • CVE-2008-5000Nov 10, 2008
    risk 0.03cvss —epss 0.01

    SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via uppercase characters in the news_id parameter.

  • CVE-2008-4915Nov 10, 2008
    risk 0.00cvss —epss 0.00

    The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0.x through 2.0.5 and earlier, and 1.0.x through 1.0.7; Server 1.0.x through 1.0.7; ESX 2.5.4 through 3.5; and ESXi 3.5, when…

  • CVE-2008-4831Nov 10, 2008
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensitive information or possibly gain privileges, via unknown vectors.

  • CVE-2008-4823Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors related to loose interpretation of an ActionScript attribute.

  • CVE-2008-4822Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Adobe Flash Player 9.0.124.0 and earlier does not properly interpret policy files, which allows remote attackers to bypass a non-root domain policy.

  • CVE-2008-4821Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Adobe Flash Player 9.0.124.0 and earlier, when a Mozilla browser is used, does not properly interpret jar: URLs, which allows attackers to obtain sensitive information via unknown vectors.

  • CVE-2008-4820Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.

  • CVE-2008-4819Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Unspecified vulnerability in Adobe Flash Player 9.0.124.0 and earlier makes it easier for remote attackers to conduct DNS rebinding attacks via unknown vectors.

  • CVE-2008-4818Nov 10, 2008
    risk 0.00cvss —epss 0.05

    Cross-site scripting (XSS) vulnerability in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP response headers.

  • CVE-2008-4281Nov 10, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in VMWare ESXi 3.5 before ESXe350-200810401-O-UG and ESX 3.5 before ESX350-200810201-UG allows administrators with the Datastore.FileManagement privilege to gain privileges via unknown vectors.

  • CVE-2008-4999Nov 7, 2008
    risk 0.03cvss —epss 0.04

    Nortel Networks UNIStim IP Phone 0604DAS allows remote attackers to cause a denial of service (crash) via a long ping packet ("ping of death"). NOTE: this issue could not be reproduced by a third party, who tested it on 0604DAD. In addition, the original researcher was not able…

  • CVE-2008-4998Nov 7, 2008
    risk 0.00cvss —epss 0.00

    postinst in twiki 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/twiki temporary file. NOTE: the vendor disputes this vulnerability, stating "this bug is invalid.

  • CVE-2008-4997Nov 7, 2008
    risk 0.00cvss —epss 0.00

    dfxml-invoice in datafreedom-perl 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/zenity temporary file. NOTE: the vendor disputes this vulnerability, stating that the vector is solely "an EXAMPLE used in the manpage.

  • CVE-2008-4996MedNov 7, 2008
    risk 0.36cvss 5.5epss 0.00

    init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs.debug temporary file. NOTE: the vendor disputes this vulnerability, stating that "init is [used in] a single-user context; there's no possibility that this…

  • CVE-2008-4995Nov 7, 2008
    risk 0.00cvss —epss 0.00

    redirect.pl in bk2site 1.1.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/redirect.log temporary file. NOTE: this vulnerability is only limited to debug mode, which is disabled by default.

  • CVE-2008-4994Nov 7, 2008
    risk 0.00cvss —epss 0.00

    The (1) ncsarmt and (2) ncsawrap scripts in xmcd 2.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.*pid temporary file.

  • CVE-2008-4993Nov 7, 2008
    risk 0.00cvss —epss 0.00

    qemu-dm.debug in Xen 3.2.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/args temporary file.

  • CVE-2008-4992Nov 7, 2008
    risk 0.00cvss —epss 0.00

    The SPARC hypervisor in Sun System Firmware 6.6.3 through 6.6.5 and 7.1.3 through 7.1.3.e on UltraSPARC T1, T2, and T2+ processors allows logical domain users to access memory in other logical domains via unknown vectors.

  • CVE-2008-4414Nov 7, 2008
    risk 0.00cvss —epss 0.00

    Unspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vectors.

  • CVE-2008-4991Nov 6, 2008
    risk 0.00cvss —epss 0.01

    SQL injection vulnerability in LOCKON CO.,LTD. EC-CUBE 2.3.0 and earlier, 1.4.7 and earlier, and 1.5.0-beta2 and earlier; and Community Edition 1.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the parameter.

  • CVE-2008-4988Nov 6, 2008
    risk 0.00cvss —epss 0.00

    pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pscal##### temporary file.

  • CVE-2008-4987Nov 6, 2008
    risk 0.00cvss —epss 0.00

    xastir 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/ldconfig.tmp, (b) /tmp/ldconf.tmp, and (c) /tmp/ld.so.conf temporary files, related to the (1) get-maptools.sh and (2) get_shapelib.sh scripts.

  • CVE-2008-4986Nov 6, 2008
    risk 0.00cvss —epss 0.00

    wims 3.62 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/env#####, (b) /tmp/sed#####, and (c) /tmp/referer-home.log temporary files, related to the (1) coqweb and (2) account.sh scripts.

  • CVE-2008-4985Nov 6, 2008
    risk 0.00cvss —epss 0.00

    vdrleaktest in Video Disk Recorder (aka vdr-dbg or vdr) 1.6.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/memleaktest.log temporary file.

  • CVE-2008-4984Nov 6, 2008
    risk 0.00cvss —epss 0.00

    scratchbox2 1.99.0.24 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/dpkg.#####.tmp, (b) /tmp/missing_deps.#####, and (c) /tmp/sb2-pkg-chk.$tstamp.##### temporary files, related to the (1) dpkg-checkbuilddeps and (2) sb2-check-pkg-mappings…

  • CVE-2008-4983Nov 6, 2008
    risk 0.00cvss —epss 0.00

    scilab-bin 4.1.2 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/SciLink#####1, (b) /tmp/SciLink#####2, (c) /tmp/SciLink#####3, (d) /tmp/*.#####, (e) /tmp/*.#####.res, (f) /tmp/*.#####.err, and (g) /tmp/*.#####.diff temporary files, related to…

  • CVE-2008-4982Nov 6, 2008
    risk 0.00cvss —epss 0.00

    rkhunter in rkhunter 1.3.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rkhunter-debug temporary file. NOTE: this is probably a different vulnerability than CVE-2005-1270.

  • CVE-2008-4981Nov 6, 2008
    risk 0.00cvss —epss 0.00

    perl.robot in realtimebattle 1.0.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/perl.robot.log temporary file.

  • CVE-2008-4980Nov 6, 2008
    risk 0.00cvss —epss 0.00

    delqueueask in rccp 0.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cccp_tmp.txt temporary file.

  • CVE-2008-4979Nov 6, 2008
    risk 0.00cvss —epss 0.00

    getipacctg in rancid 2.3.2~a8 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/ipacct.#####.prefixes, (2) /tmp/ipacct.#####.sorted, (3) /tmp/ipacct.#####.pl, and (4) /tmp/ipacct.##### temporary files.

  • CVE-2008-4978Nov 6, 2008
    risk 0.00cvss —epss 0.00

    radiance 3R9+20080530 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/opt.fmt, (b) /tmp/out#####.fmt, (c) /tmp/tf#####.dat, (d) /tmp/gsf#####, (e) /tmp/sc#####.sh, (f) /tmp/il#####.pic, (g) /tmp/tl#####.pic, (h) /tmp/ds#####.pic, (i)…

  • CVE-2008-4977Nov 6, 2008
    risk 0.00cvss —epss 0.00

    postfix_groups.pl in Postfix 2.5.2 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/postfix_groups.stdout, (2) /tmp/postfix_groups.stderr, and (3) /tmp/postfix_groups.message temporary files. NOTE: the vendor disputes this vulnerability,…

  • CVE-2008-4976Nov 6, 2008
    risk 0.00cvss —epss 0.00

    ogle 0.9.2 and ogle-mmx 0.9.2 allow local users to overwrite arbitrary files via a symlink attack on (a) /tmp/ogle_audio.#####, (b) /tmp/ogle_cli.#####, (c) /tmp/ogle_ctrl.#####, (d) /tmp/ogle_gui.#####, (e) /tmp/ogle_mpeg_ps.#####, (f) /tmp/ogle_mpeg_vs.#####, (g)…

  • CVE-2008-4975Nov 6, 2008
    risk 0.00cvss —epss 0.00

    mkmailpost in newsgate 1.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mmp##### temporary file.

  • CVE-2008-4974Nov 6, 2008
    risk 0.00cvss —epss 0.00

    rrdedit in netmrg 0.20 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*.xml and (2) /tmp/*.backup temporary files.

  • CVE-2008-4973Nov 6, 2008
    risk 0.00cvss —epss 0.00

    i2myspell in myspell 3.1 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/i2my#####.1 and (2) /tmp/i2my#####.2 temporary files.

  • CVE-2008-4972Nov 6, 2008
    risk 0.00cvss —epss 0.00

    mailgo in mgt 2.31 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/mailgo##### temporary file.

  • CVE-2008-4971Nov 6, 2008
    risk 0.00cvss —epss 0.00

    mafft-homologs in mafft 6.240 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/_vf#?????, (2) /tmp/_if#?????, (3) /tmp/_pf#?????, (4) /tmp/_af#?????, (5) /tmp/_rid#?????, (6) /tmp/_res#?????, (7) /tmp/_q#?????, and (8) /tmp/_bf#????? temporary…

  • CVE-2008-4970Nov 6, 2008
    risk 0.00cvss —epss 0.00

    runiozone in lustre 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/iozone.log temporary file.

  • CVE-2008-4969Nov 6, 2008
    risk 0.00cvss —epss 0.00

    ltp-network-test 20060918 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/vsftpd.conf, (b) /tmp/udp/2/*, (c) /tmp/tcp/2/*, (d) /tmp/udp/3/*, (e) /tmp/tcp/3/*, (f) /tmp/nfs_fsstress.udp.2.log, (g) /tmp/nfs_fsstress.udp.3.log, (h)…

  • CVE-2008-4968Nov 6, 2008
    risk 0.00cvss —epss 0.00

    The (1) rccs and (2) STUFF scripts in lmbench 3.0-a7 allow local users to overwrite arbitrary files via a symlink attack on a /tmp/sdiff.##### temporary file.

  • CVE-2008-4967Nov 6, 2008
    risk 0.00cvss —epss 0.00

    linuxtrade 3.65 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/bwk, (b) /tmp/zzz, and (c) /tmp/ggg temporary files, related to the (1) linuxtrade.bwkvol, (2) linuxtrade.wn, and (3) moneyam.helper scripts.

  • CVE-2008-4966Nov 6, 2008
    risk 0.00cvss —epss 0.00

    linux-patch-openswan 2.4.12 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/snap##### and (b) /tmp/nightly##### temporary files, related to the (1) maysnap and (2) maytest scripts.

  • CVE-2008-4965Nov 6, 2008
    risk 0.00cvss —epss 0.00

    liguidsoap.py in liguidsoap 0.3.8.1+2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/liguidsoap.liq, (2) /tmp/lig.#####.log, and (3) /tmp/emission.ogg temporary files.

  • CVE-2008-4964Nov 6, 2008
    risk 0.00cvss —epss 0.00

    filters/any-UTF8 in konwert 1.8 allows local users to delete arbitrary files via a symlink attack on a /tmp/any-##### temporary file.

  • CVE-2008-4963Nov 6, 2008
    risk 0.00cvss —epss 0.02

    Unspecified vulnerability in the VLAN Trunking Protocol (VTP) implementation on Cisco IOS and CatOS, when the VTP operating mode is not transparent, allows remote attackers to cause a denial of service (device reload or hang) via a crafted VTP packet sent to a switch interface…

  • CVE-2008-4395Nov 6, 2008
    risk 0.00cvss —epss 0.02

    Multiple buffer overflows in the ndiswrapper module 1.53 for the Linux kernel 2.6 allow remote attackers to execute arbitrary code by sending packets over a local wireless network that specify long ESSIDs.

  • CVE-2008-4960Nov 5, 2008
    risk 0.00cvss —epss 0.00

    impose in impose+ 0.2 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*-tmp.ps and (2) /tmp/bboxx-* temporary files.

  • CVE-2008-4959Nov 5, 2008
    risk 0.00cvss —epss 0.00

    geo-code in gpsdrive-scripts 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/geo.google, (2) /tmp/geo.yahoo, (3) /tmp/geo.coords, and (4) /tmp/geo#####.coords temporary files.

  • CVE-2008-4958Nov 5, 2008
    risk 0.00cvss —epss 0.00

    gdrae in gdrae 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gdrae/palabra temporary file.