Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-11-17 | CVE-2008-4832 | Link Following vulnerability in Rpath Initscripts 8.128.21/8.56.150.1 rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run. | 6.9 |
2008-11-17 | CVE-2008-5108 | Code Injection vulnerability in Adobe AIR Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors. | 6.8 |
2008-11-17 | CVE-2008-5105 | Improper Input Validation vulnerability in Karjasoft Sami FTP Server 2.0.0/2.0.1/2.0.2 KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (4) MKD, (5) RMD, (6) RETR, (7) RNFR, (8) RNTO, (9) SIZE, and (10) STOR commands. | 5.0 |
2008-11-17 | CVE-2008-5102 | Resource Management Errors vulnerability in Zope PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements. | 4.0 |
2008-11-17 | CVE-2008-5099 | Information Exposure vulnerability in SUN Logical Domain Manager Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992. | 4.6 |
2008-11-17 | CVE-2008-5098 | Cross-Site Scripting vulnerability in SUN Java System Messaging Server 6.2/6.3 Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904. | 4.3 |
2008-11-17 | CVE-2008-4216 | Information Exposure vulnerability in Apple Safari The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files." | 4.3 |
2008-11-14 | CVE-2008-5096 | Information Exposure vulnerability in Typo3 File List Extension Unspecified vulnerability in the TYPO3 File List (file_list) extension 0.2.1 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors. | 5.0 |
2008-11-14 | CVE-2008-5095 | Cross-Site Scripting vulnerability in Novell products Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 4.3 |
2008-11-14 | CVE-2008-5093 | Cross-Site Scripting vulnerability in Novell Edirectory Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 4.3 |