Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-11-17 CVE-2008-4832 Link Following vulnerability in Rpath Initscripts 8.128.21/8.56.150.1
rc.sysinit in initscripts 8.12-8.21 and 8.56.15-0.1 on rPath allows local users to delete arbitrary files via a symlink attack on a directory under (1) /var/lock or (2) /var/run.
local
rpath CWE-59
6.9
2008-11-17 CVE-2008-5108 Code Injection vulnerability in Adobe AIR
Unspecified vulnerability in Adobe AIR 1.1 and earlier allows context-dependent attackers to execute untrusted JavaScript in an AIR application via unknown attack vectors.
network
adobe CWE-94
6.8
2008-11-17 CVE-2008-5105 Improper Input Validation vulnerability in Karjasoft Sami FTP Server 2.0.0/2.0.1/2.0.2
KarjaSoft Sami FTP Server 2.0.x allows remote attackers to cause a denial of service (daemon crash or hang) via certain (1) APPE, (2) CWD, (3) DELE, (4) MKD, (5) RMD, (6) RETR, (7) RNFR, (8) RNTO, (9) SIZE, and (10) STOR commands.
network
low complexity
karjasoft CWE-20
5.0
2008-11-17 CVE-2008-5102 Resource Management Errors vulnerability in Zope
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to cause a denial of service (resource consumption or application halt) via certain (1) raise or (2) import statements.
network
low complexity
zope CWE-399
4.0
2008-11-17 CVE-2008-5099 Information Exposure vulnerability in SUN Logical Domain Manager
Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992.
local
low complexity
sun CWE-200
4.6
2008-11-17 CVE-2008-5098 Cross-Site Scripting vulnerability in SUN Java System Messaging Server 6.2/6.3
Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904.
network
sun CWE-79
4.3
2008-11-17 CVE-2008-4216 Information Exposure vulnerability in Apple Safari
The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
network
apple CWE-200
4.3
2008-11-14 CVE-2008-5096 Information Exposure vulnerability in Typo3 File List Extension
Unspecified vulnerability in the TYPO3 File List (file_list) extension 0.2.1 and earlier allows remote attackers to obtain sensitive information via unknown attack vectors.
network
low complexity
typo3 CWE-200
5.0
2008-11-14 CVE-2008-5095 Cross-Site Scripting vulnerability in Novell products
Cross-site scripting (XSS) vulnerability in the Novell User Application 3.0.1, 3.5.0, and 3.5.1; and Identity Manager Roles Based Provisioning Module 3.6.0 and 3.6.1 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
novell CWE-79
4.3
2008-11-14 CVE-2008-5093 Cross-Site Scripting vulnerability in Novell Edirectory
Cross-site scripting (XSS) vulnerability in the HTTP Protocol Stack (HTTPSTK) in Novell eDirectory before 8.8 SP3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
network
novell CWE-79
4.3