257521
|
- |
|
xine
|
xine-lib
|
Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vectors that send ID3 data to the (1) id3v22_interp_frame and (2) id3v24_interp_fra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2008-5246
|
2017-08-8 10:33 |
2008-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257522
|
- |
|
virtualox
|
virtualox
|
The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary fil…
|
CWE-59
Link Following
|
CVE-2008-5256
|
2017-08-8 10:33 |
2008-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257523
|
- |
|
ibm
|
tivoli_access_manager_for_e-business
|
webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of service (crash or hang) via HTTP requests, as demonstrated by a McAfee vulnerabil…
|
CWE-20
Improper Input Validation
|
CVE-2008-5257
|
2017-08-8 10:33 |
2008-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257524
|
- |
|
toddwoolums
|
todd_woolums_asp_news_management
|
Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) viewnews.asp. NOTE: the provenance of this informa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-5274
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257525
|
- |
|
net2ftp
|
net2ftp
|
Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attackers to create, read, …
|
CWE-22
Path Traversal
|
CVE-2008-5275
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257526
|
- |
|
powerdns
|
powerdns
|
PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.
|
NVD-CWE-noinfo CWE-16
Configuration
|
CVE-2008-5277
|
2017-08-8 10:33 |
2008-12-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257527
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5278
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257528
|
- |
|
wordpress
|
wordpress
|
http://wordpress.org/development/2008/11/wordpress-265/
The security issue is an XSS exploit discovered by Jeremias Reith that fortunately only affects IP-based virtual servers running on Apache 2…
|
CWE-79
Cross-site Scripting
|
CVE-2008-5278
|
2017-08-8 10:33 |
2008-11-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257529
|
- |
|
gallery
|
gallery
|
Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies. NOTE: some of …
|
CWE-287
Improper Authentication
|
CVE-2008-5296
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257530
|
- |
|
karakas-online
|
chm2pdf
|
chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.
|
NVD-CWE-Other
|
CVE-2008-5298
|
2017-08-8 10:33 |
2008-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|