270401
|
- |
|
apache
|
geronimo
|
The init script for Apache Geronimo on SUSE Linux follows symlinks when performing a chown operation, which might allow local users to obtain access to unspecified files or directories.
|
CWE-59
Link Following
|
CVE-2008-0732
|
2008-09-6 06:35 |
2008-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270402
|
- |
|
loris
|
hotel_reservation_system
|
Cross-site scripting (XSS) vulnerability in search.cgi in Loris Hotel Reservation System 3.01 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the hotel_name pa…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0774
|
2008-09-6 06:35 |
2008-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270403
|
- |
|
freebsd
|
freebsd
|
The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0777
|
2008-09-6 06:35 |
2008-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270404
|
- |
|
sam_lantinga
|
splitvt
|
misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-0162
|
2008-09-6 06:34 |
2008-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270405
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site scripting (XSS) vulnerability in the Enterprise Admin Session Monitoring component in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the …
|
CWE-79
Cross-site Scripting
|
CVE-2008-0178
|
2008-09-6 06:34 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270406
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site scripting (XSS) vulnerability in service/impl/UserLocalServiceImpl.java in Liferay Portal 4.3.6 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP heade…
|
CWE-79
Cross-site Scripting
|
CVE-2008-0179
|
2008-09-6 06:34 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270407
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site scripting (XSS) vulnerability in themes/_unstyled/templates/init.vm in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Greeting field …
|
CWE-79
Cross-site Scripting
|
CVE-2008-0180
|
2008-09-6 06:34 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270408
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site scripting (XSS) vulnerability in the Admin portlet in Liferay Portal 4.3.6 allows remote authenticated users to inject arbitrary web script or HTML via the Shutdown message.
|
CWE-79
Cross-site Scripting
|
CVE-2008-0181
|
2008-09-6 06:34 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270409
|
- |
|
liferay
|
liferay_enterprise_portal
|
Cross-site request forgery (CSRF) vulnerability in the Admin portlet in Liferay Portal before 4.4.0 allows remote authenticated users to perform unspecified actions as unspecified other authenticated…
|
CWE-352
Origin Validation Error
|
CVE-2008-0182
|
2008-09-6 06:34 |
2008-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
270410
|
- |
|
ngircd
|
ngircd
|
ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dereference.
|
NVD-CWE-Other
|
CVE-2008-0285
|
2008-09-6 06:34 |
2008-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|