Vulnerabilities > Ubuntu > Ubuntu Linux > 8.10

DATE CVE VULNERABILITY TITLE RISK
2009-03-05 CVE-2009-0578 Permissions, Privileges, and Access Controls vulnerability in Ubuntu Linux 8.10
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to change or remove the network connections of arbitrary users via unspecified vectors related to org.freedesktop.NetworkManagerUserSettings and at_console.
local
low complexity
ubuntu CWE-264
6.2
2009-03-05 CVE-2009-0365 Permissions, Privileges, and Access Controls vulnerability in Ubuntu Linux
nm-applet.conf in GNOME NetworkManager before 0.7.0.99 contains an incorrect deny setting, which allows local users to discover (1) network connection passwords and (2) pre-shared keys via calls to the GetSecrets method in the dbus request handler.
local
low complexity
ubuntu CWE-264
4.6
2008-11-17 CVE-2008-5104 Credentials Management vulnerability in Dcgrendel Vmbuilder 0.9
Ubuntu 6.06 LTS, 7.10, 8.04 LTS, and 8.10, when installed as a virtual machine by (1) python-vm-builder or (2) ubuntu-vm-builder in VMBuilder 0.9 in Ubuntu 8.10, have ! (exclamation point) as the default root password, which allows attackers to bypass intended login restrictions.
local
low complexity
dcgrendel ubuntu CWE-255
7.2
2008-11-17 CVE-2008-5103 Credentials Management vulnerability in Dcgrendel Vmbuilder 0.9
The (1) python-vm-builder and (2) ubuntu-vm-builder implementations in VMBuilder 0.9 in Ubuntu 8.10 omit the -e option when invoking chpasswd with a root:! argument, which configures the root account with a cleartext password of ! (exclamation point) and allows attackers to bypass intended login restrictions.
local
low complexity
dcgrendel ubuntu CWE-255
7.2