CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2008-5305

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

    Published: 10 Dec 2008
    7.8
    High

    CVE-2008-5410

    Last Modified: 23 Apr 2026

    The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attackers to cause a denial of service (failed cryptographic operations) via unspecified vectors, related to the (1) RSA_sign and (2) RSA_verify functions.

    Published: 10 Dec 2008
    10
    Critical

    CVE-2008-5414

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to "userNameToken."

    Published: 10 Dec 2008
    10
    Critical

    CVE-2008-5412

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.

    Published: 10 Dec 2008
    5
    Medium

    CVE-2008-5413

    Last Modified: 23 Apr 2026

    PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files. NOTE: this is probably a duplicate of CVE-2009-0434.

    Published: 10 Dec 2008
    4.3
    Medium

    CVE-2008-5304

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.

    Published: 10 Dec 2008
    5
    Medium

    CVE-2008-5411

    Last Modified: 23 Apr 2026

    IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 10 Dec 2008
    4.3
    Medium

    CVE-2008-5399

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 9 Dec 2008
    6.8
    Medium

    CVE-2008-5400

    Last Modified: 23 Apr 2026

    Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accounts, or (4) disable accounts as a product administrator via unspecified vectors, possibly related to HTTP Referer headers.

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5403

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-5409

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF file, possibly related to included compressed streams that were processed with the ASCIIHexDecode filter. NOTE: some of these details are obtained from third party information.

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5402

    Last Modified: 23 Apr 2026

    Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID."

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-5405

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.

    Published: 9 Dec 2008
    9.4
    Critical

    CVE-2008-5407

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allow remote attackers to bypass authentication, and read or delete files, via unknown vectors.

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5401

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the image tooltip implementation in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a long image filename, related to "AIM IMG Tag Parsing."

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5404

    Last Modified: 23 Apr 2026

    Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-5406

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one overflow."

    Published: 9 Dec 2008
    9
    Critical

    CVE-2008-5408

    Last Modified: 23 Apr 2026

    Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via unknown vectors. NOTE: this can be exploited by unauthenticated remote attackers by leveraging CVE-2008-5407.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2009-0259

    Last Modified: 23 Apr 2026

    The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-5381

    Last Modified: 23 Apr 2026

    Buffer overflow in the URL processing in ffdshow (aka ffdshow-tryout) before SVN revision 2347 allows remote attackers to execute arbitrary code via a long URL.

    Published: 9 Dec 2008
    6.9
    Medium

    CVE-2008-5384

    Last Modified: 23 Apr 2026

    crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.

    Published: 9 Dec 2008
    6.9
    Medium

    CVE-2008-5385

    Last Modified: 23 Apr 2026

    enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.

    Published: 9 Dec 2008
    6.9
    Medium

    CVE-2008-5386

    Last Modified: 23 Apr 2026

    Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5393

    Last Modified: 23 Apr 2026

    UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.

    Published: 9 Dec 2008
    10
    Critical

    CVE-2008-5619

    Last Modified: 23 Apr 2026

    html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is processed by the preg_replace function with the eval switch.

    Published: 9 Dec 2008
    7.2
    High

    CVE-2008-4917

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in VMware Workstation 5.5.8 and earlier, and 6.0.5 and earlier 6.x versions; VMware Player 1.0.8 and earlier, and 2.0.5 and earlier 2.x versions; VMware Server 1.0.9 and earlier; VMware ESXi 3.5; and VMware ESX 3.0.2 through 3.5 allows guest OS users to have an unknown impact by sending the virtual hardware a request that triggers an arbitrary physical-memory write operation, leading to memory corruption.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-5383

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .ewb file.

    Published: 9 Dec 2008
    7.2
    High

    CVE-2008-5394

    Last Modified: 23 Apr 2026

    /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry.

    Published: 9 Dec 2008
    4.9
    Medium

    CVE-2008-5395

    Last Modified: 23 Apr 2026

    The parisc_show_stack function in arch/parisc/kernel/traps.c in the Linux kernel before 2.6.28-rc7 on PA-RISC allows local users to cause a denial of service (system crash) via vectors associated with an attempt to unwind a stack that contains userspace addresses.

    Published: 9 Dec 2008
    5
    Medium

    CVE-2008-6123

    Last Modified: 23 Apr 2026

    The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does not properly parse hosts.allow rules, which allows remote attackers to bypass intended access restrictions and execute SNMP queries, related to "source/destination IP address confusion."

    Published: 9 Dec 2008
    7.5
    High

    CVE-2008-4390

    Last Modified: 23 Apr 2026

    The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by sniffing the network.

    Published: 9 Dec 2008
    9.3
    Critical

    CVE-2008-4391

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long invalid arguments.

    Published: 9 Dec 2008
    6.8
    Medium

    CVE-2008-5382

    Last Modified: 23 Apr 2026

    Cross-site request forgery (CSRF) vulnerability in I-O DATA DEVICE HDL-F160, HDL-F250, HDL-F300, and HDL-F320 firmware before 1.02 allows remote attackers to (1) change a configuration or (2) delete files as an authenticated user via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Dec 2008
    6.2
    Medium

    CVE-2008-5387

    Last Modified: 23 Apr 2026

    Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain privileges via unspecified vectors.

    Published: 9 Dec 2008
    6.9
    Medium

    CVE-2008-5367

    Last Modified: 23 Apr 2026

    ip-up in ppp-udeb 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the /tmp/resolv.conf.tmp temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5366

    Last Modified: 23 Apr 2026

    The postinst script in ppp 2.4.4rel on Debian GNU/Linux allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/probe-finished or (2) /tmp/ppp-errors temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5376

    Last Modified: 23 Apr 2026

    editcomment in crip 3.7 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.tag.tmp temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5377

    Last Modified: 23 Apr 2026

    pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5378

    Last Modified: 23 Apr 2026

    arb-kill in arb 0.0.20071207.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/arb_pids_*_* temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5379

    Last Modified: 23 Apr 2026

    netdisco-mibs-installer 1.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/netdisco-mibs-0.6.tar.gz temporary file, related to the (1) netdisco-mibs-install and (2) netdisco-mibs-download scripts.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5375

    Last Modified: 23 Apr 2026

    cmus-status-display in cmus 2.2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/cmus-status temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5372

    Last Modified: 23 Apr 2026

    sdm-login in sdm-terminal 0.4.0b allows local users to overwrite arbitrary files via a symlink attack on the /tmp/sdm.autologin.once temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5371

    Last Modified: 23 Apr 2026

    screenie in screenie 1.30.0 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.screenie.##### temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5370

    Last Modified: 23 Apr 2026

    pvpgn-support-installer in pvpgn 1.8.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pvpgn-support-1.0.tar.gz temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5369

    Last Modified: 23 Apr 2026

    noip2 in noip2 2.1.7 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/noip2 temporary file.

    Published: 8 Dec 2008
    6.9
    Medium

    CVE-2008-5368

    Last Modified: 23 Apr 2026

    muttprint in muttprint 0.72d allows local users to overwrite arbitrary files via a symlink attack on the /tmp/muttprint.log temporary file.

    Published: 8 Dec 2008
    7.5
    High

    CVE-2008-5365

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute arbitrary SQL commands via the AccountID parameter.

    Published: 8 Dec 2008
    9.3
    Critical

    CVE-2008-5364

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the getPlus ActiveX control in gp.ocx 1.2.2.50 in NOS Microsystems getPlus Download Manager, as used for the Adobe Reader 8.1 installation process and other downloads, allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2008-4817.

    Published: 8 Dec 2008
    4.7
    Medium

    CVE-2009-3564

    Last Modified: 23 Apr 2026

    puppetmasterd in puppet 0.24.6 does not reset supplementary groups when it switches to a different user, which might allow local users to access restricted files.

    Published: 8 Dec 2008
    7.5
    High

    CVE-2008-5844

    Last Modified: 23 Apr 2026

    PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, which might make it easier for context-dependent attackers to conduct SQL injection attacks and unspecified other attacks.

    Published: 8 Dec 2008