CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2008-0889

    Last Modified: 23 Apr 2026

    Red Hat Directory Server 8.0, when running on Red Hat Enterprise Linux, uses insecure permissions for the redhat-idm-console script, which allows local users to execute arbitrary code by modifying the script.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1003

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to sites that set the document.domain property or have the same document.domain.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1004

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to the Web Inspector.

    Published: 19 Mar 2008
    2.1
    Low

    CVE-2008-1005

    Last Modified: 23 Apr 2026

    WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1002

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1 allows remote attackers to inject arbitrary web script or HTML via a crafted javascript: URL.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1008

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via the document.domain property.

    Published: 19 Mar 2008
    6.8
    Medium

    CVE-2008-1010

    Last Modified: 23 Apr 2026

    Buffer overflow in WebKit, as used in Apple Safari before 3.1, allows remote attackers to execute arbitrary code via crafted regular expressions in JavaScript.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1001

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Apple Safari before 3.1, when running on Windows XP or Vista, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is not properly handled in the error page.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1011

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML via a frame that calls a method instance in another frame.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1007

    Last Modified: 23 Apr 2026

    WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1006

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary web script or HTML by using the window.open function to change the security context of a web page.

    Published: 19 Mar 2008
    4.3
    Medium

    CVE-2008-1009

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in WebCore, as used in Apple Safari before 3.1, allows remote attackers to inject arbitrary JavaScript by modifying the history object.

    Published: 19 Mar 2008
    6.8
    Medium

    CVE-2008-0052

    Last Modified: 23 Apr 2026

    CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.

    Published: 18 Mar 2008
    6.4
    Medium

    CVE-2008-0054

    Last Modified: 23 Apr 2026

    Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0056

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Foundation in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a "long pathname with an unexpected structure" that triggers the overflow in NSFileManager.

    Published: 18 Mar 2008
    5.8
    Medium

    CVE-2008-0059

    Last Modified: 23 Apr 2026

    Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."

    Published: 18 Mar 2008
    4.3
    Medium

    CVE-2008-0988

    Last Modified: 23 Apr 2026

    Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.

    Published: 18 Mar 2008
    6.9
    Medium

    CVE-2008-0989

    Last Modified: 23 Apr 2026

    Format string vulnerability in mDNSResponderHelper in Apple Mac OS X 10.5.2 allows local users to execute arbitrary code via format string specifiers in the local hostname.

    Published: 18 Mar 2008
    6.9
    Medium

    CVE-2008-0998

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass authorization and execute arbitrary code via crafted distributed objects.

    Published: 18 Mar 2008
    7.2
    High

    CVE-2008-0055

    Last Modified: 23 Apr 2026

    Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permissions afterward, which allows local users to modify copied files to cause a denial of service and possibly gain privileges.

    Published: 18 Mar 2008
    5.8
    Medium

    CVE-2008-0058

    Last Modified: 23 Apr 2026

    Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.

    Published: 18 Mar 2008
    1.7
    Low

    CVE-2008-0996

    Last Modified: 23 Apr 2026

    The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0060

    Last Modified: 23 Apr 2026

    Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0987

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in Image Raw in Apple Mac OS X 10.5.2, and Digital Camera RAW Compatibility before Update 2.0 for Aperture 2 and iPhoto 7.1.2, allows remote attackers to execute arbitrary code via a crafted Adobe Digital Negative (DNG) image.

    Published: 18 Mar 2008
    2.1
    Low

    CVE-2008-0993

    Last Modified: 23 Apr 2026

    Podcast Capture in Podcast Producer for Apple Mac OS X 10.5.2 invokes a subtask with passwords in command line arguments, which allows local users to read the passwords via process listings.

    Published: 18 Mar 2008
    2.6
    Low

    CVE-2008-0994

    Last Modified: 23 Apr 2026

    Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.

    Published: 18 Mar 2008
    2.6
    Low

    CVE-2008-0995

    Last Modified: 23 Apr 2026

    The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.

    Published: 18 Mar 2008
    8.5
    High

    CVE-2008-1000

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.

    Published: 18 Mar 2008
    4.4
    Medium

    CVE-2008-0990

    Last Modified: 23 Apr 2026

    notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.

    Published: 18 Mar 2008
    7.1
    High

    CVE-2008-0999

    Last Modified: 23 Apr 2026

    Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference.

    Published: 18 Mar 2008
    7.1
    High

    CVE-2008-0045

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.

    Published: 18 Mar 2008
    5
    Medium

    CVE-2008-0046

    Last Modified: 23 Apr 2026

    The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" radio button that might cause the user to believe that the button is used to restrict access only to specific services and applications, which might allow attackers to bypass intended access restrictions.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0048

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via the a long file name to the NSDocument API.

    Published: 18 Mar 2008
    6.9
    Medium

    CVE-2008-0051

    Last Modified: 23 Apr 2026

    Integer overflow in CoreFoundation in Apple Mac OS X 10.4.11 might allow local users to execute arbitrary code via crafted time zone data.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0997

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in AppKit in Apple Mac OS X 10.4.11 allows user-assisted remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted PostScript Printer Description (PPD) file that is not properly handled when querying a network printer.

    Published: 18 Mar 2008
    1.9
    Low

    CVE-2008-1383

    Last Modified: 23 Apr 2026

    The docert function in ssl-cert.eclass, when used by src_compile or src_install on Gentoo Linux, stores the SSL key in a binpkg, which allows local users to extract the key from the binpkg, and causes multiple systems that use this binpkg to have the same SSL key and certificate.

    Published: 18 Mar 2008
    5
    Medium

    CVE-2008-0050

    Last Modified: 23 Apr 2026

    CFNetwork in Apple Mac OS X 10.4.11 allows remote HTTPS proxy servers to spoof secure websites via data in a 502 Bad Gateway error.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-0057

    Last Modified: 23 Apr 2026

    Multiple integer overflows in a "legacy serialization format" parser in AppKit in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via a crafted serialized property list.

    Published: 18 Mar 2008
    5.8
    Medium

    CVE-2008-0044

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in AFP Client in Apple Mac OS X 10.4.11 and 10.5.2 allow remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted afp:// URL.

    Published: 18 Mar 2008
    1.9
    Low

    CVE-2008-0049

    Last Modified: 23 Apr 2026

    AppKit in Apple Mac OS X 10.4.11 inadvertently makes an NSApplication mach port available for inter-process communication instead of inter-thread communication, which allows local users to execute arbitrary code via crafted messages to privileged applications.

    Published: 18 Mar 2008
    10
    Critical

    CVE-2008-1369

    Last Modified: 23 Apr 2026

    A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that configure root logins in a manner unintended by the vendor, which allows remote attackers to gain privileges via unspecified vectors.

    Published: 18 Mar 2008
    3.6
    Low

    CVE-2008-1371

    Last Modified: 23 Apr 2026

    Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and execute arbitrary files via a full pathname in the d_root parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Mar 2008
    6.8
    Medium

    CVE-2008-1370

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Mar 2008
    3.5
    Low

    CVE-2008-1330

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Windows client API in Novell GroupWise 7 before SP3 and 6.5 before SP6 Update 3 allows remote authenticated users to access the non-shared stored e-mail messages of another user who has shared at least one folder with the attacker.

    Published: 18 Mar 2008
    10
    Critical

    CVE-2008-0053

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in the HP-GL/2-to-PostScript filter in CUPS before 1.3.6 might allow remote attackers to execute arbitrary code via a crafted HP-GL/2 file.

    Published: 18 Mar 2008
    4.9
    Medium

    CVE-2008-1514

    Last Modified: 23 Apr 2026

    arch/s390/kernel/ptrace.c in Linux kernel 2.6.9, and other versions before 2.6.27-rc6, on s390 platforms allows local users to cause a denial of service (kernel panic) via the user-area-padding test from the ptrace testsuite in 31-bit mode, which triggers an invalid dereference.

    Published: 18 Mar 2008
    9.3
    Critical

    CVE-2008-0047

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the cgiCompileSearch function in CUPS 1.3.5, and other versions including the version bundled with Apple Mac OS X 10.5.2, when printer sharing is enabled, allows remote attackers to execute arbitrary code via crafted search expressions.

    Published: 18 Mar 2008
    8.5
    High

    CVE-2008-0727

    Last Modified: 23 Apr 2026

    Multiple buffer overflows in oninit.exe in IBM Informix Dynamic Server (IDS) 7.x through 11.x allow (1) remote attackers to execute arbitrary code via a long password and (2) remote authenticated users to execute arbitrary code via a long DBPATH value.

    Published: 18 Mar 2008
    10
    Critical

    CVE-2008-0949

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in IBM Informix Dynamic Server (IDS) 7.x through 11.x allows remote attackers to gain privileges via a malformed connection request packet.

    Published: 18 Mar 2008
    9.3
    Critical

    CVE-2008-0948

    Last Modified: 23 Apr 2026

    Buffer overflow in the RPC library (lib/rpc/rpc_dtablesize.c) used by libgssrpc and kadmind in MIT Kerberos 5 (krb5) 1.2.2, and probably other versions before 1.3, when running on systems whose unistd.h does not define the FD_SETSIZE macro, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering a large number of open file descriptors.

    Published: 18 Mar 2008