CVE-2008-3219
- EPSS 0.58%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS...
CVE-2008-3220
- EPSS 0.4%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
CVE-2008-3221
- EPSS 0.42%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
CVE-2008-3222
- EPSS 1.06%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
CVE-2008-3223
- EPSS 1.14%
- Veröffentlicht 18.07.2008 16:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL commands via vectors related to "an inappropriate placeholder for 'numeric' fields."
CVE-2008-2371
- EPSS 4.13%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in pcre_compile.c in the Perl-Compatible Regular Expression (PCRE) library 7.7 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a regular expression that begins ...
CVE-2008-2374
- EPSS 6.45%
- Veröffentlicht 07.07.2008 23:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspeci...
- EPSS 2.21%
- Veröffentlicht 13.06.2008 18:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service...
CVE-2008-2575
- EPSS 0.99%
- Veröffentlicht 06.06.2008 22:32:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
CVE-2008-2108
- EPSS 5.61%
- Veröffentlicht 07.05.2008 21:20:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
The GENERATE_SEED macro in PHP 4.x before 4.4.8 and 5.x before 5.2.5, when running on 64-bit systems, performs a multiplication that generates a portion of zero bits during conversion due to insufficient precision, which produces 24 bits of entropy a...