CVE-2008-0062
- EPSS 10.14%
- Veröffentlicht 19.03.2008 10:44:00
- Zuletzt bearbeitet 16.06.2026 22:48:51
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer derefe...
CVE-2008-0063
- EPSS 3.48%
- Veröffentlicht 19.03.2008 10:44:00
- Zuletzt bearbeitet 16.06.2026 22:48:51
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
CVE-2008-0888
- EPSS 6.29%
- Veröffentlicht 17.03.2008 21:44:00
- Zuletzt bearbeitet 16.06.2026 22:50:32
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a ...
CVE-2007-6415
- EPSS 3.67%
- Veröffentlicht 25.01.2008 00:00:00
- Zuletzt bearbeitet 16.06.2026 22:48:01
scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o options.
CVE-2007-6427
- EPSS 4.28%
- Veröffentlicht 18.01.2008 23:00:00
- Zuletzt bearbeitet 16.06.2026 22:48:03
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.
- EPSS 2.57%
- Veröffentlicht 12.01.2008 02:46:00
- Zuletzt bearbeitet 16.06.2026 22:47:44
The xmlCurrentChar function in libxml2 before 2.6.31 allows context-dependent attackers to cause a denial of service (infinite loop) via XML containing invalid UTF-8 sequences.
CVE-2008-0226
- EPSS 91.6%
- Veröffentlicht 10.01.2008 23:46:00
- Zuletzt bearbeitet 16.06.2026 22:49:10
Multiple buffer overflows in yaSSL 1.7.5 and earlier, as used in MySQL and possibly other products, allow remote attackers to execute arbitrary code via (1) the ProcessOldClientHello function in handshake.cpp or (2) "input_buffer& operator>>" in yass...
- EPSS 3.81%
- Veröffentlicht 09.01.2008 21:46:00
- Zuletzt bearbeitet 16.06.2026 22:44:45
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted reg...
CVE-2007-6601
- EPSS 1.57%
- Veröffentlicht 09.01.2008 21:46:00
- Zuletzt bearbeitet 16.06.2026 22:48:24
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. N...
CVE-2007-6599
- EPSS 1.66%
- Veröffentlicht 04.01.2008 02:46:00
- Zuletzt bearbeitet 16.06.2026 22:48:24
Race condition in fileserver in OpenAFS 1.3.50 through 1.4.5 and 1.5.0 through 1.5.27 allows remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks, which causes the handler for the Giv...