Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2008-4832
Disclosure Date: November 17, 2008 (last updated October 04, 2023)
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. NOTE: this issue exists because of a race condition in an incorrect fix for CVE-2008-3524. NOTE: exploitation may require an unusual scenario in which rc.sysinit is executed other than at boot time.
0
Attacker Value
Unknown
CVE-2008-3139
Disclosure Date: July 10, 2008 (last updated October 04, 2023)
The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 through 1.0.0 allows remote attackers to cause a denial of service (crash) via unknown vectors. NOTE: this might be due to a use-after-free error.
0
Attacker Value
Unknown
CVE-2008-3138
Disclosure Date: July 10, 2008 (last updated October 04, 2023)
The (1) PANA and (2) KISMET dissectors in Wireshark (formerly Ethereal) 0.99.3 through 1.0.0 allow remote attackers to cause a denial of service (application stop) via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-5962
Disclosure Date: May 22, 2008 (last updated October 04, 2023)
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows remote attackers to cause a denial of service (memory consumption) via a large number of CWD commands, as demonstrated by an attack on a daemon with the deny_file configuration option.
0
Attacker Value
Unknown
CVE-2008-2139
Disclosure Date: May 12, 2008 (last updated October 04, 2023)
The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.
0
Attacker Value
Unknown
CVE-2008-2140
Disclosure Date: May 12, 2008 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.
0
Attacker Value
Unknown
CVE-2008-1078
Disclosure Date: February 29, 2008 (last updated November 08, 2023)
expn in the am-utils and net-fs packages for Gentoo, rPath Linux, and other distributions, allows local users to overwrite arbitrary files via a symlink attack on the expn[PID] temporary file. NOTE: this is the same issue as CVE-2003-0308.1.
0
Attacker Value
Unknown
CVE-2007-5686
Disclosure Date: October 28, 2007 (last updated October 04, 2023)
initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.
0
Attacker Value
Unknown
CVE-2007-5194
Disclosure Date: October 04, 2007 (last updated October 04, 2023)
The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as /dev/port, which might allow local users to gain root privileges.
0
Attacker Value
Unknown
CVE-2007-4382
Disclosure Date: August 17, 2007 (last updated October 04, 2023)
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header.
0