CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2008-5659

    Last Modified: 23 Apr 2026

    The gnu.java.security.util.PRNG class in GNU Classpath 0.97.2 and earlier uses a predictable seed based on the system time, which makes it easier for context-dependent attackers to conduct brute force attacks against cryptographic routines that use this class for randomness, as demonstrated against DSA private keys.

    Published: 8 Dec 2008
    4.3
    Medium

    CVE-2008-6472

    Last Modified: 23 Apr 2026

    The WLCCP dissector in Wireshark 0.99.7 through 1.0.4 allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

    Published: 8 Dec 2008
    10
    Critical

    CVE-2008-5332

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e) delete.php, and others; and the (2) GLOBALS[pie][library_path] parameter to files in lib/share/ including (f) diff.php, (g) file.php, (h) locale.php, (i) mapfile.php, (j) page.php, and others.

    Published: 5 Dec 2008
    4.3
    Medium

    CVE-2008-5338

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2008-5337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2008-5336

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2007-6719

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2008-5333

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 Dec 2008
    6.8
    Medium

    CVE-2008-5335

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.

    Published: 5 Dec 2008
    10
    Critical

    CVE-2008-5334

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Published: 5 Dec 2008
    4.3
    Medium

    CVE-2008-5324

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2008
    4.9
    Medium

    CVE-2008-5079

    Last Modified: 23 Apr 2026

    net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.

    Published: 5 Dec 2008
    4.6
    Medium

    CVE-2008-4311

    Last Modified: 23 Apr 2026

    The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply.

    Published: 5 Dec 2008
    4.6
    Medium

    CVE-2008-4416

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

    Published: 5 Dec 2008
    4.3
    Medium

    CVE-2008-5325

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2008
    4.4
    Medium

    CVE-2008-5326

    Last Modified: 23 Apr 2026

    The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.

    Published: 5 Dec 2008
    6.5
    Medium

    CVE-2008-5327

    Last Modified: 23 Apr 2026

    The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.

    Published: 5 Dec 2008
    4.6
    Medium

    CVE-2008-5328

    Last Modified: 23 Apr 2026

    The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2008-5329

    Last Modified: 23 Apr 2026

    ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.

    Published: 5 Dec 2008
    4.3
    Medium

    CVE-2008-5330

    Last Modified: 23 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

    Published: 5 Dec 2008
    1.9
    Low

    CVE-2008-5700

    Last Modified: 23 Apr 2026

    libata in the Linux kernel before 2.6.27.9 does not set minimum timeouts for SG_IO requests, which allows local users to cause a denial of service (Programmed I/O mode on drives) via multiple simultaneous invocations of an unspecified test program.

    Published: 5 Dec 2008
    7.5
    High

    CVE-2008-5658

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the ZipArchive::extractTo function in PHP 5.2.6 and earlier allows context-dependent attackers to write arbitrary files via a ZIP file with a file whose name contains .. (dot dot) sequences.

    Published: 4 Dec 2008
    7.5
    High

    CVE-2008-5624

    Last Modified: 23 Apr 2026

    PHP 5 before 5.2.7 does not properly initialize the page_uid and page_gid global variables for use by the SAPI php_getuid function, which allows context-dependent attackers to bypass safe_mode restrictions via variable settings that are intended to be restricted to root, as demonstrated by a setting of /etc for the error_log variable.

    Published: 4 Dec 2008
    10
    Critical

    CVE-2008-5353

    Last Modified: 23 Apr 2026

    The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

    Published: 4 Dec 2008
    7.5
    High

    CVE-2008-5351

    Last Modified: 23 Apr 2026

    Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.

    Published: 4 Dec 2008
    5
    Medium

    CVE-2008-5618

    Last Modified: 23 Apr 2026

    imudp in rsyslog 4.x before 4.1.2, 3.21 before 3.21.9 beta, and 3.20 before 3.20.2 generates a message even when it is sent by an unauthorized sender, which allows remote attackers to cause a denial of service (disk consumption) via a large number of spurious messages.

    Published: 4 Dec 2008
    7.2
    High

    CVE-2008-5397

    Last Modified: 23 Apr 2026

    Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplementary group memberships of the Tor process.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5357

    Last Modified: 23 Apr 2026

    Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

    Published: 4 Dec 2008
    10
    Critical

    CVE-2008-5355

    Last Modified: 23 Apr 2026

    The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

    Published: 4 Dec 2008
    7.1
    High

    CVE-2008-5348

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.

    Published: 4 Dec 2008
    10
    Critical

    CVE-2008-5340

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

    Published: 4 Dec 2008
    7.5
    High

    CVE-2008-5625

    Last Modified: 23 Apr 2026

    PHP 5 before 5.2.7 does not enforce the error_log safe_mode restrictions when safe_mode is enabled through a php_admin_flag setting in httpd.conf, which allows context-dependent attackers to write to arbitrary files by placing a "php_value error_log" entry in a .htaccess file.

    Published: 4 Dec 2008
    6.4
    Medium

    CVE-2008-5360

    Last Modified: 23 Apr 2026

    Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5354

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5352

    Last Modified: 23 Apr 2026

    Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

    Published: 4 Dec 2008
    5
    Medium

    CVE-2008-5341

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-2086

    Last Modified: 23 Apr 2026

    Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.

    Published: 4 Dec 2008
    7.8
    High

    CVE-2008-4310

    Last Modified: 23 Apr 2026

    httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incomplete fix for CVE-2008-3656.

    Published: 4 Dec 2008
    5
    Medium

    CVE-2008-5339

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.

    Published: 4 Dec 2008
    5
    Medium

    CVE-2008-5342

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.

    Published: 4 Dec 2008
    9
    Critical

    CVE-2008-5343

    Last Modified: 23 Apr 2026

    Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.

    Published: 4 Dec 2008
    7.5
    High

    CVE-2008-5344

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.

    Published: 4 Dec 2008
    7.5
    High

    CVE-2008-5345

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.

    Published: 4 Dec 2008
    7.1
    High

    CVE-2008-5346

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

    Published: 4 Dec 2008
    5
    Medium

    CVE-2008-5350

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5356

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5358

    Last Modified: 23 Apr 2026

    Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5359

    Last Modified: 23 Apr 2026

    Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.

    Published: 4 Dec 2008
    9.3
    Critical

    CVE-2008-5398

    Last Modified: 23 Apr 2026

    Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream, which allows remote exit relays to have an unknown impact by mapping an internal IP address to the destination hostname of a refused stream.

    Published: 4 Dec 2008
    4.3
    Medium

    CVE-2008-5323

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 3 Dec 2008