Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2008-08-28 CVE-2008-3858 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database 9.1
The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of service (instance crash) via a crafted CONNECT data stream that simulates a V7 client connect request.
network
ibm CWE-264
4.3
2008-08-28 CVE-2008-3857 Information Exposure vulnerability in IBM DB2 Universal Database 9.1
The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the database connection that sent the password is fully established, which might allow local users to obtain sensitive information by reading a memory dump.
local
low complexity
ibm CWE-200
4.6
2008-08-28 CVE-2008-3855 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database 9.1
Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 before Fixpak 5 allows local users to gain privileges, aka a "FILE CREATION VULNERABILITY." NOTE: this may be the same as CVE-2007-5664.
local
low complexity
ibm CWE-264
4.6
2008-08-28 CVE-2008-3852 Permissions, Privileges, and Access Controls vulnerability in IBM DB2 Universal Database 9.1/9.5
Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 2 allows remote authenticated users to execute arbitrary code via unknown vectors.
network
low complexity
ibm CWE-264
6.5
2008-08-27 CVE-2008-3851 Path Traversal vulnerability in Pluck 4.5.2
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php; and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php.
network
low complexity
microsoft pluck CWE-22
5.0
2008-08-27 CVE-2008-3850 Cross-Site Scripting vulnerability in Accellion Secure File Transfer Appliance 70135
Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to courier/forgot_password.html.
network
accellion CWE-79
4.3
2008-08-27 CVE-2008-3849 Cross-Site Scripting vulnerability in Civic-Cms
Cross-site scripting (XSS) vulnerability in the calendar controller in Civic Website Manager before 1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, probably involving (1) month, (2) day, and (3) year fields.
network
civic-cms CWE-79
4.3
2008-08-27 CVE-2008-3847 Cross-Site Scripting vulnerability in Aguestbook AN Guestbook
Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
aguestbook CWE-79
4.3
2008-08-27 CVE-2008-3846 Cross-Site Scripting vulnerability in Aquagardensoft Mysql-Lists
Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2008-08-27 CVE-2008-3843 Cross-Site Scripting vulnerability in Microsoft .Net Framework 1.0/1.1/2.0
Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update does not properly detect dangerous client input, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a query string containing a "<~/" (less-than tilde slash) sequence followed by a crafted STYLE element.
network
microsoft CWE-79
4.3