CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2008-5452

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9.18 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-5458

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10 and CU2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-5451

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the JD Edwards Tools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.5 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-5457

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jan 2009
    6.8
    Medium

    CVE-2008-5461

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remote attackers to affect confidentiality, integrity, and availability, related to WLS. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is cross-site scripting.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-3978

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-4015

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Streams component in Oracle Database 10.1.0.5 allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_STREAMS_AUTH.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-5439

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SQL*Plus Windows GUI component in Oracle Database 10.2.0.4 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-5441

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2008-5442 and CVE-2008-5443.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-5436

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote authenticated users to affect integrity and availability via unknown vectors.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-5437

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Job Queue component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.6 allows remote authenticated users to affect confidentiality and integrity, related to DBMS_IJOB.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-5448

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5444 and CVE-2008-5449.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-3974

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.0.2.8 and 9.2.0.8DV allows remote authenticated users to affect availability, related to SYS.OLAPIMPL_T.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-4006

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-5444

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and CVE-2008-5449.

    Published: 14 Jan 2009
    1.7
    Low

    CVE-2008-3973

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SQL*Plus Windows GUI component in Oracle Database allows local users to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    5.5
    Medium

    CVE-2008-3979

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a SQL injection vulnerability that allows remote authenticated users to gain MDSYS privileges via the MDSYS.SDO_TOPO_DROP_FTBL trigger.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-3999

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 allows remote authenticated users to affect availability, related to SYS.OLAPIMPL_T.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-3981

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.1 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 14 Jan 2009
    4
    Medium

    CVE-2008-3997

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect availability, related to SYS.DBMS_XSOQ_ODBO.

    Published: 14 Jan 2009
    5
    Medium

    CVE-2008-5442

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect availability via unknown vectors, a different vulnerability than CVE-2008-5441 and CVE-2008-5443.

    Published: 14 Jan 2009
    7.5
    High

    CVE-2008-5440

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the TimesTen Data Server component in Oracle Database 7.0.5.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2009 CPU. Oracle has not commented on reliable researcher claims that this is a format string vulnerability via the msg parameter in the evtdump CGI module.

    Published: 14 Jan 2009
    10
    Critical

    CVE-2008-5449

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5444 and CVE-2008-5448.

    Published: 14 Jan 2009
    7.1
    High

    CVE-2010-0006

    Last Modified: 11 Apr 2025

    The ipv6_hop_jumbo function in net/ipv6/exthdrs.c in the Linux kernel before 2.6.32.4, when network namespaces are enabled, allows remote attackers to cause a denial of service (NULL pointer dereference) via an invalid IPv6 jumbogram, a related issue to CVE-2007-4567.

    Published: 14 Jan 2009
    7.5
    High

    CVE-2008-5517

    Last Modified: 23 Apr 2026

    The web interface in git (gitweb) 1.5.x before 1.5.6 allows remote attackers to execute arbitrary commands via shell metacharacters related to (1) git_snapshot and (2) git_object.

    Published: 13 Jan 2009
    7.2
    High

    CVE-2009-0024

    Last Modified: 23 Apr 2026

    The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileges via unspecified vectors, related to the vm_file structure member, and the mmap_region and do_munmap functions.

    Published: 13 Jan 2009
    Unknown

    CVE-2009-0242

    Last Modified: 7 Nov 2023

    gmetad in Ganglia 3.1.1, when supporting multiple requests per connection on an interactive port, allows remote attackers to cause a denial of service via a request to the gmetad service with a path that does not exist, which causes Ganglia to (1) perform excessive CPU computation and (2) send the entire tree, which consumes network bandwidth. NOTE: the vendor and original researcher have disputed this issue, since legitimate requests can generate the same amount of resource consumption. CVE concurs with the dispute, so this identifier should not be used

    Published: 13 Jan 2009
    4.9
    Medium

    CVE-2008-5913

    Last Modified: 23 Apr 2026

    The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, uses a random number generator that is seeded only once per browser session, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack."

    Published: 13 Jan 2009
    7.5
    High

    CVE-2009-0241

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmetad service with a long pathname.

    Published: 13 Jan 2009
    7.8
    High

    CVE-2008-5883

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list arbitrary directories via a full pathname in the sDir parameter.

    Published: 12 Jan 2009
    4.3
    Medium

    CVE-2008-5884

    Last Modified: 23 Apr 2026

    AyeView 2.20 allows user-assisted attackers to cause a denial of service (application crash) via a GIF file with a malformed header.

    Published: 12 Jan 2009
    5
    Medium

    CVE-2008-5886

    Last Modified: 23 Apr 2026

    TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for _private/discussion.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5890

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Jan 2009
    4.3
    Medium

    CVE-2008-5891

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    2.6
    Low

    CVE-2008-5893

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in admin_dblayers.asp in ClickAndEmail allows remote attackers to inject arbitrary web script or HTML via the tablename parameter in an update action.

    Published: 12 Jan 2009
    6.8
    Medium

    CVE-2008-5894

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5898

    Last Modified: 23 Apr 2026

    CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CADirectory.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5899

    Last Modified: 23 Apr 2026

    CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFFAPage.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5900

    Last Modified: 23 Apr 2026

    CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5901

    Last Modified: 23 Apr 2026

    iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing a password via a direct request for db/iyziforum.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    5
    Medium

    CVE-2008-5887

    Last Modified: 23 Apr 2026

    phplist before 2.10.8 allows remote attackers to include files via unknown vectors, related to a "local file include vulnerability."

    Published: 12 Jan 2009
    5
    Medium

    CVE-2008-5885

    Last Modified: 23 Apr 2026

    The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for admin/quote.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5892

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1) the ID parameter to admin_dblayers.asp in an update action, (2) the adminid parameter to admin_loginCheck.asp (aka the USERNAME field in admin_main.asp), and (3) the PassWord parameter to admin_loginCheck.asp (aka the PASSWORD field in admin_main.asp). NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5895

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5888

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hitcounter.asp, (2) user_delete.asp, and (3) user_update.asp; (4) the userid parameter to admin_login.asp (aka the USERNAME field in admin.asp); and (5) the PassWord parameter to admin_login.asp (aka the PASSWORD field in admin.asp). NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    4.3
    Medium

    CVE-2008-5889

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5896

    Last Modified: 23 Apr 2026

    CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CARateMySite.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    7.5
    High

    CVE-2008-5897

    Last Modified: 23 Apr 2026

    CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFreeWallpaper.mdb. NOTE: some of these details are obtained from third party information.

    Published: 12 Jan 2009
    4.9
    Medium

    CVE-2009-1214

    Last Modified: 23 Apr 2026

    GNU screen 4.0.3 creates the /tmp/screen-exchange temporary file with world-readable permissions, which might allow local users to obtain sensitive session information.

    Published: 11 Jan 2009
    4.9
    Medium

    CVE-2009-0745

    Last Modified: 23 Apr 2026

    The ext4_group_add function in fs/ext4/resize.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 does not properly initialize the group descriptor during a resize (aka resize2fs) operation, which might allow local users to cause a denial of service (OOPS) by arranging for crafted values to be present in available memory.

    Published: 11 Jan 2009