|
312251
|
6.4 |
MEDIUM
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a di…
|
CWE-16
環境設定
|
CVE-2008-4099
|
2008-09-19 13:00 |
2008-09-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312252
|
6.4 |
MEDIUM
|
debian
|
python-dns
|
PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote a…
|
CWE-16
環境設定
|
CVE-2008-4126
|
2008-09-19 13:00 |
2008-09-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312253
|
4.6 |
MEDIUM
|
lxde
|
lightweight_x11_desktop_environment
|
src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.
|
CWE-59
リンク解釈の問題
|
CVE-2008-3791
|
2008-09-17 14:35 |
2008-09-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312254
|
1.9 |
LOW
|
apple
|
iphone
|
Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an …
|
CWE-264
認可・権限・アクセス制御
|
CVE-2008-3876
|
2008-09-17 14:35 |
2008-09-2 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312255
|
4.3 |
MEDIUM
|
six_apart
|
movable_type
|
Cross-site scripting (XSS) vulnerability in Movable Type (MT) 4.x through 4.20, and 3.36 and earlier; Movable Type Enterprise 4.x through 4.20, and 1.54 and earlier; and Movable Type Community Soluti…
|
CWE-79
クロスサイト・スクリプティング(XSS)
|
CVE-2008-4079
|
2008-09-16 00:14 |
2008-09-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312256
|
7.5 |
HIGH
|
texmedia
|
million_pixel_script
|
SQL injection vulnerability in tops_top.php in Million Pixel Ad Script (Million Pixel Script) allows remote attackers to execute arbitrary SQL commands via the id_cat parameter.
|
CWE-89
SQLインジェクション
|
CVE-2008-4055
|
2008-09-12 13:00 |
2008-09-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312257
|
2.6 |
LOW
|
apple
|
itunes
|
Apple iTunes before 8.0 on Mac OS X 10.4.11, when iTunes Music Sharing is enabled but blocked by the host-based firewall, presents misleading information about firewall security, which might allow re…
|
CWE-200
情報漏えい
|
CVE-2008-3634
|
2008-09-11 13:00 |
2008-09-11 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312258
|
10.0 |
HIGH
|
opensuse
|
opensuse
|
Multiple off-by-one errors in opensuse-updater in openSUSE 10.2 have unspecified impact and attack vectors. NOTE: the vendor states that these "can be considered no security problem."
|
NVD-CWE-noinfo CWE-189
数値処理の問題
|
CVE-2008-2388
|
2008-09-11 10:10 |
2008-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312259
|
4.9 |
MEDIUM
|
opensuse
|
opensuse
|
opensuse-updater in openSUSE 10.2 allows local users to access arbitrary files via a symlink attack.
|
CWE-59
リンク解釈の問題
|
CVE-2008-2389
|
2008-09-11 10:10 |
2008-06-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312260
|
7.5 |
HIGH
|
xine
|
xine-lib
|
Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Title, (2) Author, or (3…
|
CWE-119
バッファエラー
|
CVE-2008-0238
|
2008-09-11 10:04 |
2008-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312261
|
7.5 |
HIGH
|
xine
|
xine-lib
|
Please see the following link for more information regarding the exploit:
http://aluigi.altervista.org/adv/xinermffhof-adv.txt
|
CWE-119
バッファエラー
|
CVE-2008-0238
|
2008-09-11 10:04 |
2008-01-12 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312262
|
9.3 |
HIGH
|
softartisans
|
xfile
|
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.4.0 allow remote attackers to execute arbitrary code via unspecified calls to t…
|
CWE-119
バッファエラー
|
CVE-2007-1682
|
2008-09-11 09:51 |
2008-08-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312263
|
10.0 |
HIGH
|
php
|
php
|
The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers to bypass safe_mode restrictions and read arbitrary files via a file path speci…
|
NVD-CWE-Other
|
CVE-2007-0448
|
2008-09-11 09:49 |
2007-05-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312264
|
7.2 |
HIGH
|
redhat
|
linux
|
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfa…
|
NVD-CWE-Other
|
CVE-2003-0019
|
2008-09-11 09:05 |
2003-02-19 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312265
|
7.2 |
HIGH
|
jean-jacques_sarton
|
mtink
|
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2003-0034
|
2008-09-11 09:05 |
2003-02-7 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312266
|
7.5 |
HIGH
|
apple
|
mac_os_x mac_os_x_server
|
Apple File Protocol (AFP) in Mac OS X before 10.2.4 allows administrators to log in as other users by using the administrator password.
|
NVD-CWE-Other
|
CVE-2003-0049
|
2008-09-11 09:05 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312267
|
7.2 |
HIGH
|
apple
|
mac_os_x
|
TruBlueEnvironment for MacOS 10.2.3 and earlier allows local users to overwrite or create arbitrary files and gain root privileges by setting a certain environment variable that is used to write debu…
|
NVD-CWE-Other
|
CVE-2003-0088
|
2008-09-11 09:05 |
2003-03-3 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312268
|
5.0 |
MEDIUM
|
oracle
|
oracle8i oracle9i
|
TNS Listener in Oracle Net Services for Oracle 9i 9.2.x and 9.0.x, and Oracle 8i 8.1.x, allows remote attackers to cause a denial of service (hang or crash) via a SERVICE_CURLOAD command.
|
NVD-CWE-Other
|
CVE-2002-1118
|
2008-09-11 09:03 |
2002-10-28 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312269
|
7.5 |
HIGH
|
matt_blaze
|
cfs
|
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.
|
NVD-CWE-Other
|
CVE-2002-0351
|
2008-09-11 09:01 |
2002-06-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312270
|
2.1 |
LOW
|
sgi
|
irix
|
netstat in SGI IRIX before 6.5.12 allows local users to determine the existence of files on the system, even if the users do not have the appropriate permissions.
|
NVD-CWE-Other
|
CVE-2002-0355
|
2008-09-11 09:01 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312271
|
7.2 |
HIGH
|
sgi
|
irix
|
Vulnerability in XFS filesystem reorganizer (fsr_xfs) in SGI IRIX 6.5.10 and earlier allows local users to gain root privileges by overwriting critical system files.
|
NVD-CWE-Other
|
CVE-2002-0356
|
2008-09-11 09:01 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312272
|
7.2 |
HIGH
|
sgi
|
irix
|
Unknown vulnerability in rpc.passwd in the nfs.sw.nis subsystem of SGI IRIX 6.5.15 and earlier allows local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0357
|
2008-09-11 09:01 |
2002-06-18 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312273
|
5.0 |
MEDIUM
|
martin_roesch
|
snort
|
Snort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of service (crash and core dump) via a malformed ICMP packet.
|
NVD-CWE-Other
|
CVE-2002-0115
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312274
|
2.1 |
LOW
|
palm
|
palm_desktop
|
Apple Palm Desktop 4.0b76 and 4.0b77 creates world-readable backup files and folders when a hotsync is performed, which could allow a local user to obtain sensitive information.
|
NVD-CWE-Other
|
CVE-2002-0120
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312275
|
2.1 |
LOW
|
php
|
php
|
PHP 4.0 through 4.1.1 stores session IDs in temporary files whose name contains the session ID, which allows local users to hijack web connections.
|
NVD-CWE-Other
|
CVE-2002-0121
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312276
|
5.0 |
MEDIUM
|
siemens
|
3568i_wap
|
Siemens 3568i WAP mobile phones allows remote attackers to cause a denial of service (crash) via an SMS message containing unusual characters.
|
NVD-CWE-Other
|
CVE-2002-0122
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312277
|
7.5 |
HIGH
|
mdg_computer_services
|
web_server_4d_ecommerce
|
MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP re…
|
NVD-CWE-Other
|
CVE-2002-0123
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312278
|
5.0 |
MEDIUM
|
mdg_computer_services
|
web_server_4d_ecommerce
|
MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request.
|
NVD-CWE-Other
|
CVE-2002-0124
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312279
|
7.2 |
HIGH
|
clanlib
|
clanlib
|
Buffer overflow in ClanLib library 0.5 may allow local users to execute arbitrary code in games that use the library, such as (1) Super Methane Brothers, (2) Star War, (3) Kwirk, (4) Clankanoid, and …
|
NVD-CWE-Other
|
CVE-2002-0125
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312280
|
7.5 |
HIGH
|
selom_ofori
|
blackmoon_ftp_server
|
Buffer overflow in BlackMoon FTP Server 1.0 through 1.5 allows remote attackers to execute arbitrary code via a long argument to (1) USER, (2) PASS, or (3) CWD.
|
NVD-CWE-Other
|
CVE-2002-0126
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312281
|
7.2 |
HIGH
|
chinput
|
chinput
|
Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2002-0132
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312282
|
5.0 |
MEDIUM
|
netopia
|
timbuktu_pro
|
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).
|
NVD-CWE-Other
|
CVE-2002-0135
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312283
|
7.5 |
HIGH
|
pi-soft
|
spoonftp
|
Pi-Soft SpoonFTP 1.1 and earlier allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
|
NVD-CWE-Other
|
CVE-2002-0139
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312284
|
7.5 |
HIGH
|
dnrd
|
dnrd
|
Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and possibly execute arbitrary code via a long or malformed DNS reply, which is not han…
|
NVD-CWE-Other
|
CVE-2002-0140
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312285
|
4.6 |
MEDIUM
|
enlightenment michael_jennings
|
imlib eterm
|
Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
|
NVD-CWE-Other
|
CVE-2002-0143
|
2008-09-11 09:00 |
2002-03-25 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312286
|
7.5 |
HIGH
|
stephen_turner
|
analog
|
Cross-site scripting vulnerability in analog before 5.22 allows remote attackers to execute Javascript via an HTTP request containing the script, which is entered into a web logfile and not properly …
|
NVD-CWE-Other
|
CVE-2002-0166
|
2008-09-11 09:00 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312287
|
7.5 |
HIGH
|
enlightenment
|
imlib
|
Imlib before 1.9.13 sometimes uses the NetPBM package to load trusted images, which could allow attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain weakness…
|
NVD-CWE-Other
|
CVE-2002-0167
|
2008-09-11 09:00 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312288
|
7.5 |
HIGH
|
enlightenment
|
imlib
|
Vulnerability in Imlib before 1.9.13 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code by manipulating arguments that are passed to malloc, which results in a …
|
NVD-CWE-Other
|
CVE-2002-0168
|
2008-09-11 09:00 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312289
|
4.6 |
MEDIUM
|
redhat
|
docbook_stylesheets docbook_utils
|
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an u…
|
NVD-CWE-Other
|
CVE-2002-0169
|
2008-09-11 09:00 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312290
|
7.5 |
HIGH
|
sgi
|
irisconsole
|
IRISconsole 2.0 may allow users to log into the icadmin account with an incorrect password in some circumstances, which could allow users to gain privileges.
|
NVD-CWE-Other
|
CVE-2002-0171
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312291
|
2.1 |
LOW
|
sgi
|
irix
|
/dev/ipfilter on SGI IRIX 6.5 is installed by /dev/MAKEDEV with insecure default permissions (644), which could allow a local user to cause a denial of service (traffic disruption).
|
NVD-CWE-Other
|
CVE-2002-0172
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312292
|
7.2 |
HIGH
|
sgi
|
irix
|
Buffer overflow in cpr for the eoe.sw.cpr SGI Checkpoint-Restart Software package on SGI IRIX 6.5.10 and earlier may allow local users to gain root privileges.
|
NVD-CWE-Other
|
CVE-2002-0173
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312293
|
7.2 |
HIGH
|
sgi
|
irix
|
nsd on SGI IRIX before 6.5.11 allows local users to overwrite arbitrary files and gain root privileges via a symlink attack on the nsd.dump file.
|
NVD-CWE-Other
|
CVE-2002-0174
|
2008-09-11 09:00 |
2002-05-29 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312294
|
4.6 |
MEDIUM
|
avaya
|
libsafe
|
libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not li…
|
NVD-CWE-Other
|
CVE-2002-0175
|
2008-09-11 09:00 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312295
|
4.6 |
MEDIUM
|
avaya
|
libsafe
|
The printf wrappers in libsafe 2.0-11 and earlier do not properly handle argument indexing specifiers, which could allow attackers to exploit certain function calls through arguments that are not ver…
|
NVD-CWE-Other
|
CVE-2002-0176
|
2008-09-11 09:00 |
2002-04-22 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312296
|
6.4 |
MEDIUM
|
acd_incorporated
|
cwpapi
|
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in oth…
|
NVD-CWE-Other
|
CVE-2002-0196
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312297
|
3.6 |
LOW
|
paintbbs
|
paintbbs
|
PaintBBS 1.2 installs certain files and directories with insecure permissions, which allows local users to (1) obtain the encrypted server password via the world-readable oekakibbs.conf file, or (2) …
|
NVD-CWE-Other
|
CVE-2002-0202
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312298
|
5.0 |
MEDIUM
|
nortel
|
alteon_acedirector
|
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled, allows remote attackers to determine the real IP address of a web server with …
|
NVD-CWE-Other
|
CVE-2002-0209
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312299
|
7.2 |
HIGH
|
tolis_group
|
bru
|
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/brutest.$$ temporary file.
|
NVD-CWE-Other
|
CVE-2002-0210
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312300
|
2.1 |
LOW
|
intel
|
intel_pro_wireless_2011b_lan_usb_device_driver
|
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allow…
|
NVD-CWE-Other
|
CVE-2002-0214
|
2008-09-11 09:00 |
2002-05-16 |
表示
|
GitHub
Exploit DB
Packet Storm
|
|
|