CVE-2008-2108
- EPSS 5.61%
- Veröffentlicht 07.05.2008 21:20:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy a...
- EPSS 38.88%
- Veröffentlicht 05.05.2008 17:20:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
CVE-2008-2079
- EPSS 0.56%
- Veröffentlicht 05.05.2008 16:20:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
MySQL 4.1.x before 4.1.24, 5.0.x before 5.0.60, 5.1.x before 5.1.24, and 6.0.x before 6.0.5 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY argume...
CVE-2008-1375
- EPSS 0.07%
- Veröffentlicht 02.05.2008 16:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors.
CVE-2008-1887
- EPSS 2.39%
- Veröffentlicht 18.04.2008 17:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Python 2.5.2 and earlier allows context-dependent attackers to execute arbitrary code via multiple vectors that cause a negative size value to be provided to the PyString_FromStringAndSize function, which allocates less memory than expected when asse...
CVE-2008-1721
- EPSS 28.41%
- Veröffentlicht 10.04.2008 19:05:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Integer signedness error in the zlib extension module in Python 2.5.2 and earlier allows remote attackers to execute arbitrary code via a negative signed integer, which triggers insufficient memory allocation and a buffer overflow.
CVE-2008-0062
- EPSS 16.26%
- Veröffentlicht 19.03.2008 10:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer derefe...
CVE-2008-0063
- EPSS 4.9%
- Veröffentlicht 19.03.2008 10:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
CVE-2008-0888
- EPSS 19.04%
- Veröffentlicht 17.03.2008 21:44:00
- Zuletzt bearbeitet 01.05.2025 15:33:00
The NEEDBITS macro in the inflate_dynamic function in inflate.c for unzip can be invoked using invalid buffers, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a ...
CVE-2008-1195
- EPSS 14.43%
- Veröffentlicht 06.03.2008 21:44:00
- Zuletzt bearbeitet 23.04.2026 00:35:47
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via uns...