Show filters
106 Total Results
Displaying 91-100 of 106
Sort by:
Attacker Value
Unknown

CVE-2008-5018

Disclosure Date: November 13, 2008 (last updated October 04, 2023)
The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.
0
Attacker Value
Unknown

CVE-2008-5024

Disclosure Date: November 13, 2008 (last updated October 04, 2023)
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.
0
Attacker Value
Unknown

CVE-2008-5022

Disclosure Date: November 13, 2008 (last updated October 04, 2023)
The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.
0
Attacker Value
Unknown

CVE-2008-4989

Disclosure Date: November 13, 2008 (last updated February 09, 2024)
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed certificate for any Distinguished Name (DN).
Attacker Value
Unknown

CVE-2008-4934

Disclosure Date: November 05, 2008 (last updated October 04, 2023)
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image.
0
Attacker Value
Unknown

CVE-2008-4306

Disclosure Date: November 04, 2008 (last updated October 04, 2023)
Buffer overflow in enscript before 1.6.4 has unknown impact and attack vectors, possibly related to the font escape sequence.
0
Attacker Value
Unknown

CVE-2008-4577

Disclosure Date: October 15, 2008 (last updated January 21, 2024)
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
Attacker Value
Unknown

CVE-2008-4582

Disclosure Date: October 15, 2008 (last updated October 04, 2023)
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.
0
Attacker Value
Unknown

CVE-2008-4098

Disclosure Date: September 18, 2008 (last updated October 04, 2023)
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097.
0
Attacker Value
Unknown

CVE-2008-3529

Disclosure Date: September 12, 2008 (last updated October 04, 2023)
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
0