CVE-2008-5023
- EPSS 3.26%
- Veröffentlicht 13.11.2008 11:30:01
- Zuletzt bearbeitet 16.06.2026 22:59:05
Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR f...
CVE-2008-5024
- EPSS 3.64%
- Veröffentlicht 13.11.2008 11:30:01
- Zuletzt bearbeitet 16.06.2026 22:59:05
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection at...
CVE-2008-4989
- EPSS 1.88%
- Veröffentlicht 13.11.2008 01:00:01
- Zuletzt bearbeitet 16.06.2026 22:58:53
The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers t...
CVE-2008-4934
- EPSS 3.29%
- Veröffentlicht 05.11.2008 15:00:14
- Zuletzt bearbeitet 16.06.2026 22:58:47
The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (syste...
- EPSS 8.99%
- Veröffentlicht 30.10.2008 20:56:54
- Zuletzt bearbeitet 16.06.2026 22:58:33
The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitra...
CVE-2008-4582
- EPSS 10.19%
- Veröffentlicht 15.10.2008 20:08:02
- Zuletzt bearbeitet 16.06.2026 22:58:06
Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the...
CVE-2008-4359
- EPSS 4.35%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 16.06.2026 22:57:40
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive inform...
CVE-2008-4360
- EPSS 4.35%
- Veröffentlicht 03.10.2008 17:41:40
- Zuletzt bearbeitet 16.06.2026 22:57:40
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access r...
CVE-2008-4302
- EPSS 0.62%
- Veröffentlicht 29.09.2008 17:17:29
- Zuletzt bearbeitet 16.06.2026 22:57:33
fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a deni...
CVE-2008-3837
- EPSS 3.27%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 16.06.2026 22:56:38
Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted...