Show filters
251 Total Results
Displaying 161-170 of 251
Sort by:
Attacker Value
Unknown
CVE-2008-0166
Disclosure Date: May 13, 2008 (last updated February 09, 2024)
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
0
Attacker Value
Unknown
CVE-2008-2108
Disclosure Date: May 07, 2008 (last updated February 15, 2024)
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy and simplifies brute force attacks against protection mechanisms that use the rand and mt_rand functions.
0
Attacker Value
Unknown
CVE-2008-2079
Disclosure Date: May 05, 2008 (last updated October 04, 2023)
MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are within the MySQL home data directory, which can point to tables that are created in the future.
0
Attacker Value
Unknown
CVE-2008-1375
Disclosure Date: May 02, 2008 (last updated October 04, 2023)
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-1887
Disclosure Date: April 18, 2008 (last updated October 04, 2023)
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when assert() is disabled and triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2008-1721
Disclosure Date: April 10, 2008 (last updated October 04, 2023)
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
0
Attacker Value
Unknown
CVE-2008-0063
Disclosure Date: March 19, 2008 (last updated February 09, 2024)
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
0
Attacker Value
Unknown
CVE-2008-0062
Disclosure Date: March 19, 2008 (last updated December 29, 2023)
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
0
Attacker Value
Unknown
CVE-2008-1195
Disclosure Date: March 06, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecified vectors related to JavaScript and Java APIs.
0
Attacker Value
Unknown
CVE-2007-6427
Disclosure Date: January 18, 2008 (last updated October 04, 2023)
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
0