|
272781
|
- |
|
limesurvey
|
limesurvey
|
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2008-2570
|
2023-11-7 11:02 |
2008-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272782
|
- |
|
limesurvey
|
limesurvey
|
Cross-site request forgery (CSRF) vulnerability in LimeSurvey (formerly PHPSurveyor) before 1.71 allows remote attackers to change arbitrary quotas as administrators via a "modify quota" action.
|
CWE-79
Cross-site Scripting
|
CVE-2008-2571
|
2023-11-7 11:02 |
2008-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272783
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1035. Reason: This candidate is a reservation duplicate of CVE-2008-1035. Notes: All CVE users should reference CVE-2008-103…
|
CWE-20
Improper Input Validation
|
CVE-2008-2007
|
2023-11-7 11:02 |
2008-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272784
|
- |
|
fireftp
|
fireftp
|
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in resp…
|
CWE-22
Path Traversal
|
CVE-2008-2399
|
2023-11-7 11:02 |
2008-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272785
|
- |
|
gnu
|
gnutls
|
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hel…
|
CWE-189
Numeric Errors
|
CVE-2008-1948
|
2023-11-7 11:02 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272786
|
- |
|
gnu
|
gnutls
|
The _gnutls_recv_client_kx_message function in lib/gnutls_kx.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 continues to process Client Hello messages within a TLS message after one has already…
|
CWE-287
Improper Authentication
|
CVE-2008-1949
|
2023-11-7 11:02 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272787
|
- |
|
gnu
|
gnutls
|
Integer signedness error in the _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in libgnutls in GnuTLS before 2.2.4 allows remote attackers to cause a denial of service (buffer over-rea…
|
CWE-189
Numeric Errors
|
CVE-2008-1950
|
2023-11-7 11:02 |
2008-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272788
|
- |
|
linux
|
linux_kernel
|
The utimensat system call (sys_utimensat) in Linux kernel 2.6.22 and other versions before 2.6.25.3 does not check file permissions when certain UTIME_NOW and UTIME_OMIT combinations are used, which …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2148
|
2023-11-7 11:02 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272789
|
- |
|
videolan
|
vlc
|
Untrusted search path vulnerability in VideoLAN VLC before 0.9.0 allows local users to execute arbitrary code via a malicious library under the modules/ or plugins/ subdirectories of the current work…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-2147
|
2023-11-7 11:02 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272790
|
- |
|
cpanel
|
cpanel
|
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordere…
|
CWE-79
Cross-site Scripting
|
CVE-2008-2070
|
2023-11-7 11:02 |
2008-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|