CVE-2008-2725
- EPSS 2.49%
- Veröffentlicht 24.06.2008 19:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, and 1.8.7 before 1.8.7-p22; and (2) the rb_ary_replace function in 1.6.x allows context-dependent attackers to trigger mem...
CVE-2008-2726
- EPSS 2.82%
- Veröffentlicht 24.06.2008 19:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer overflow in the (1) rb_ary_splice function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2; and (2) the rb_ary_replace function in 1.6.x allows context-dependent at...
- EPSS 9.64%
- Veröffentlicht 23.06.2008 20:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
php_imap.c in PHP 5.2.5, 5.2.6, 4.x, and other versions, uses obsolete API calls that allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long IMAP request, which triggers an "rfc822.c lega...
CVE-2008-2712
- EPSS 16.97%
- Veröffentlicht 16.06.2008 21:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3)...
- EPSS 2.21%
- Veröffentlicht 13.06.2008 18:41:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...
CVE-2008-1105
- EPSS 85.73%
- Veröffentlicht 29.05.2008 16:32:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Heap-based buffer overflow in the receive_smb_raw function in util/sock.c in Samba 3.0.0 through 3.0.29 allows remote attackers to execute arbitrary code via a crafted SMB response.
CVE-2008-1672
- EPSS 18.97%
- Veröffentlicht 29.05.2008 16:32:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
CVE-2008-2009
- EPSS 4.34%
- Veröffentlicht 16.05.2008 12:54:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Xiph.org libvorbis before 1.0 does not properly check for underpopulated Huffman trees, which allows remote attackers to cause a denial of service (crash) via a crafted OGG file that triggers memory corruption during execution of the _make_decode_tre...
CVE-2008-2136
- EPSS 23.49%
- Veröffentlicht 16.05.2008 12:54:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Memory leak in the ipip6_rcv function in net/ipv6/sit.c in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3 allows remote attackers to cause a denial of service (memory consumption) via network traffic to a Simple Internet Transition (SIT...
CVE-2008-0166
- EPSS 4.05%
- Veröffentlicht 13.05.2008 17:20:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptograp...