|
306221
|
7.8 |
HIGH
Local
|
getfiregpg
|
iceweasel-firegpg
|
A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
|
CWE-59
Link Following
|
CVE-2008-7273
|
2024-11-21 09:58 |
2019-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306222
|
5.5 |
MEDIUM
Local
|
alsa-project
|
alsa
|
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.
|
CWE-59
Link Following
|
CVE-2009-0035
|
2024-11-21 09:58 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306223
|
9.8 |
CRITICAL
Network
|
gri_project debian
|
gri debian_linux
|
gri before 2.12.18 generates temporary files in an insecure way.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2008-7291
|
2024-11-21 09:58 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306224
|
7.5 |
HIGH
Network
|
getfiregpg
|
firegpg
|
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure commun…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2008-7272
|
2024-11-21 09:58 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306225
|
6.1 |
MEDIUM
Network
|
tubepress
|
tubepress
|
The tubepress plugin before 1.6.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2008-7321
|
2024-11-21 09:58 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306226
|
6.8 |
MEDIUM
Physics
|
gnome
|
seahorse
|
GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is di…
|
CWE-255
Credentials Management
|
CVE-2008-7320
|
2024-11-21 09:58 |
2018-11-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306227
|
9.8 |
CRITICAL
Network
|
net-ping-external_project
|
net-ping-external
|
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing…
|
CWE-77
Command Injection
|
CVE-2008-7319
|
2024-11-21 09:58 |
2017-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306228
|
9.8 |
CRITICAL
Network
|
cpan
|
ui\
|
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2008-7315
|
2024-11-21 09:58 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306229
|
9.8 |
CRITICAL
Network
|
snoopy redhat nagios
|
snoopy openstack nagios
|
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.
|
CWE-77
Command Injection
|
CVE-2008-7313
|
2024-11-21 09:58 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306230
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers an iovec of zero length, followed by a page fault…
|
CWE-20
Improper Input Validation
|
CVE-2008-7316
|
2024-11-21 09:58 |
2016-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|