271211
|
- |
|
geda
|
gnetlist
|
sch2eaglepos.sh in geda-gnetlist 1.4.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/##### temporary file.
|
CWE-59
Link Following
|
CVE-2008-5148
|
2008-12-3 15:46 |
2008-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271212
|
- |
|
sentex
|
jhead
|
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows local users to delete arbitrary files via vectors involving a modified input filename in which (1) a final "z" chara…
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4640
|
2008-12-3 15:45 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271213
|
- |
|
sentex
|
jhead
|
The DoCommand function in jhead.c in Matthias Wandel jhead 2.84 and earlier allows attackers to execute arbitrary commands via shell metacharacters in unspecified input.
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2008-4641
|
2008-12-3 15:45 |
2008-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271214
|
- |
|
cisco
|
ios
|
The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi networks, has insufficient countermeasures agains…
|
CWE-310
Cryptographic Issues
|
CVE-2008-5230
|
2008-12-3 14:00 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271215
|
- |
|
cisco
|
ios
|
The impact of this vulnerability has yet to be determined. The full list of affected platforms is subject to change. The NVD will continue to monitor this vulnerability and adjust the configurations …
|
CWE-310
Cryptographic Issues
|
CVE-2008-5230
|
2008-12-3 14:00 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271216
|
- |
|
ghh
|
google_hack_honeypot_file_upload_manager
|
Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this inform…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5283
|
2008-12-2 14:00 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271217
|
- |
|
south_river_technologies
|
titan_ftp_server
|
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a long DELE command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5281
|
2008-12-1 14:00 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271218
|
- |
|
calendarix
|
basic
|
Multiple SQL injection vulnerabilities in Calendarix Basic 0.8.20071118 allow remote attackers to execute arbitrary SQL commands via (1) the catsearch parameter to cal_search.php or (2) the catview p…
|
CWE-89
SQL Injection
|
CVE-2008-2429
|
2008-11-26 14:00 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271219
|
- |
|
novell
|
iprint
|
Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory…
|
CWE-200
Information Exposure
|
CVE-2008-2432
|
2008-11-26 14:00 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
271220
|
- |
|
adobe
|
flash_media_server
|
The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers to make copies of vi…
|
CWE-16
Configuration
|
CVE-2008-5109
|
2008-11-26 14:00 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|