- EPSS 0.81%
- Published 11.09.2008 01:13:47
- Last modified 09.04.2025 00:30:58
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because ...
CVE-2008-3282
- EPSS 0.62%
- Published 29.08.2008 18:41:00
- Last modified 09.04.2025 00:30:58
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly exec...
CVE-2008-3281
- EPSS 0.8%
- Published 27.08.2008 20:41:00
- Last modified 09.04.2025 00:30:58
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
CVE-2008-3424
- EPSS 0.65%
- Published 31.07.2008 22:41:00
- Last modified 09.04.2025 00:30:58
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions...
CVE-2008-2951
- EPSS 0.6%
- Published 27.07.2008 22:41:00
- Last modified 09.04.2025 00:30:58
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
CVE-2008-3218
- EPSS 0.52%
- Published 18.07.2008 16:41:00
- Last modified 09.04.2025 00:30:58
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, a...
CVE-2008-3219
- EPSS 0.58%
- Published 18.07.2008 16:41:00
- Last modified 09.04.2025 00:30:58
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS...
CVE-2008-3220
- EPSS 0.4%
- Published 18.07.2008 16:41:00
- Last modified 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
CVE-2008-3221
- EPSS 0.42%
- Published 18.07.2008 16:41:00
- Last modified 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
CVE-2008-3222
- EPSS 1.06%
- Published 18.07.2008 16:41:00
- Last modified 09.04.2025 00:30:58
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.