CVE-2008-4068
- EPSS 0.27%
- Veröffentlicht 24.09.2008 20:37:04
- Zuletzt bearbeitet 23.04.2026 00:35:47
Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive inf...
CVE-2008-4098
- EPSS 0.35%
- Veröffentlicht 18.09.2008 15:04:27
- Zuletzt bearbeitet 23.04.2026 00:35:47
MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and ...
- EPSS 56.63%
- Veröffentlicht 12.09.2008 16:56:20
- Zuletzt bearbeitet 23.04.2026 00:35:47
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a long XML entity name.
CVE-2007-6716
- EPSS 0.05%
- Veröffentlicht 04.09.2008 17:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.
CVE-2008-3281
- EPSS 0.8%
- Veröffentlicht 27.08.2008 20:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-3275
- EPSS 0.08%
- Veröffentlicht 12.08.2008 23:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2.6.25.15 do not prevent creation of a child dentry for a deleted (aka S_DEAD) directory, which allows local users to cause a denia...
CVE-2008-1945
- EPSS 0.09%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
QEMU 0.9.0 does not properly handle changes to removable media, which allows guest OS users to read arbitrary files on the host OS by using the diskformat: parameter in the -usbdevice option to modify the disk-image header to identify a different for...
CVE-2008-3534
- EPSS 0.05%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The shmem_delete_inode function in mm/shmem.c in the tmpfs implementation in the Linux kernel before 2.6.26.1 allows local users to cause a denial of service (system crash) via a certain sequence of file create, remove, and overwrite operations, as d...
CVE-2008-3535
- EPSS 0.05%
- Veröffentlicht 08.08.2008 19:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Off-by-one error in the iov_iter_advance function in mm/filemap.c in the Linux kernel before 2.6.27-rc2 allows local users to cause a denial of service (system crash) via a certain sequence of file I/O operations with readv and writev, as demonstrate...
CVE-2008-3272
- EPSS 0.06%
- Veröffentlicht 08.08.2008 18:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain da...