Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2008-10-22 CVE-2008-4687 Code Injection vulnerability in Mantis
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP sequences, which are processed by create_function within the multi_sort function in core/utility_api.php.
network
low complexity
mantis CWE-94
critical
9.0
2008-10-22 CVE-2008-4685 Resource Management Errors vulnerability in Wireshark
Use-after-free vulnerability in the dissect_q931_cause_ie function in packet-q931.c in the Q.931 dissector in Wireshark 0.10.3 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via certain packets that trigger an exception.
network
low complexity
wireshark CWE-399
5.0
2008-10-22 CVE-2008-4684 Resource Management Errors vulnerability in Wireshark
packet-frame in Wireshark 0.99.2 through 1.0.3 does not properly handle exceptions thrown by post dissectors, which allows remote attackers to cause a denial of service (application crash) via a certain series of packets, as demonstrated by enabling the (1) PRP or (2) MATE post dissector.
network
wireshark CWE-399
4.3
2008-10-22 CVE-2008-4683 Resource Management Errors vulnerability in Wireshark
The dissect_btacl function in packet-bthci_acl.c in the Bluetooth ACL dissector in Wireshark 0.99.2 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a packet with an invalid length, related to an erroneous tvb_memcpy call.
network
low complexity
wireshark CWE-399
5.0
2008-10-22 CVE-2008-4682 Improper Input Validation vulnerability in Wireshark
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a malformed Tamos CommView capture file (aka .ncf file) with an "unknown/unexpected packet type" that triggers a failed assertion.
network
low complexity
wireshark CWE-20
5.0
2008-10-22 CVE-2008-4681 Improper Input Validation vulnerability in Wireshark
Unspecified vulnerability in the Bluetooth RFCOMM dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via unknown packets.
network
wireshark CWE-20
4.3
2008-10-22 CVE-2008-4680 Resource Management Errors vulnerability in Wireshark
packet-usb.c in the USB dissector in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application crash or abort) via a malformed USB Request Block (URB).
network
wireshark CWE-399
4.3
2008-10-22 CVE-2008-4679 Improper Authentication vulnerability in IBM Websphere Application Server
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the "Java security method" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.
network
ibm CWE-287
6.8
2008-10-22 CVE-2008-4678 Resource Management Errors vulnerability in IBM Websphere Application Server
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
network
low complexity
ibm CWE-399
7.8
2008-10-22 CVE-2008-4677 Credentials Management vulnerability in VIM Netrw
autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords.
network
vim CWE-255
4.3