Weekly Vulnerabilities Reports > December 1 to 7, 2008

Overview

84 new vulnerabilities reported during this period, including 16 critical vulnerabilities and 33 high severity vulnerabilities. This weekly summary report vulnerabilities in 52 products from 39 vendors including SUN, IBM, Scripts4You, Octeth, and Netart Media. Vulnerabilities are notably categorized as "SQL Injection", "Cross-site Scripting", "Information Exposure", "Improper Restriction of Operations within the Bounds of a Memory Buffer", and "Numeric Errors".

  • 75 reported vulnerabilities are remotely exploitables.
  • 30 reported vulnerabilities have public exploit available.
  • 32 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 79 reported vulnerabilities are exploitable by an anonymous user.
  • SUN has the most reported vulnerabilities, with 23 reported vulnerabilities.
  • SUN has the most reported critical vulnerabilities, with 11 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

16 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2008-12-05 CVE-2008-5355 SUN Improper Authentication vulnerability in SUN Jdk, JRE and SDK

The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.

10.0
2008-12-05 CVE-2008-5353 SUN Multiple Security vulnerability in SUN Jdk, JRE and SDK

The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".

10.0
2008-12-05 CVE-2008-5340 SUN Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.

10.0
2008-12-05 CVE-2008-5334 Nitrotech Code Injection vulnerability in Nitrotech 0.0.3A

PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

10.0
2008-12-05 CVE-2008-5332 PIE Code Injection vulnerability in PIE 0.5.3

Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e) delete.php, and others; and the (2) GLOBALS[pie][library_path] parameter to files in lib/share/ including (f) diff.php, (g) file.php, (h) locale.php, (i) mapfile.php, (j) page.php, and others.

10.0
2008-12-03 CVE-2008-5317 Littlecms Numeric Errors vulnerability in Littlecms Lcms and Little CMS Color Engine

Integer signedness error in the cmsAllocGamma function in src/cmsgamma.c in Little cms color engine (aka lcms) before 1.17 allows attackers to have an unknown impact via a file containing a certain "number of entries" value, which is interpreted improperly, leading to an allocation of insufficient memory.

10.0
2008-12-03 CVE-2008-5316 Littlecms Buffer Errors vulnerability in Littlecms Lcms and Little CMS Color Engine

Buffer overflow in the ReadEmbeddedTextTag function in src/cmsio1.c in Little cms color engine (aka lcms) before 1.16 allows attackers to have an unknown impact via vectors related to a length parameter inconsistency involving the contents of "the input file," a different vulnerability than CVE-2007-2741.

10.0
2008-12-05 CVE-2008-5359 SUN Buffer Errors vulnerability in SUN Jdk, JRE and SDK

Buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code, related to a ConvolveOp operation in the Java AWT library.

9.3
2008-12-05 CVE-2008-5358 SUN Buffer Errors vulnerability in SUN JDK and JRE

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier might allow remote attackers to execute arbitrary code via a crafted GIF file that triggers memory corruption during display of the splash screen, possibly related to splashscreen.dll.

9.3
2008-12-05 CVE-2008-5357 SUN Numeric Errors vulnerability in SUN Jdk, JRE and SDK

Integer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file, which triggers a heap-based buffer overflow.

9.3
2008-12-05 CVE-2008-5356 SUN Buffer Errors vulnerability in SUN Jdk, JRE and SDK

Heap-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier might allow remote attackers to execute arbitrary code via a crafted TrueType font file.

9.3
2008-12-05 CVE-2008-5354 SUN Buffer Errors vulnerability in SUN Jdk, JRE and SDK

Stack-based buffer overflow in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows locally-launched and possibly remote untrusted Java applications to execute arbitrary code via a JAR file with a long Main-Class manifest entry.

9.3
2008-12-05 CVE-2008-5352 SUN Numeric Errors vulnerability in SUN JDK and JRE

Integer overflow in the JAR unpacking utility (unpack200) in the unpack library (unpack.dll) in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted applications and applets to gain privileges via a Pack200 compressed JAR file that triggers a heap-based buffer overflow.

9.3
2008-12-05 CVE-2008-2086 SUN Code Injection vulnerability in SUN Jdk, JRE and SDK

Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka "Java Web Start File Inclusion" and CR 6694892.

9.3
2008-12-03 CVE-2008-5276 Videolan Numeric Errors vulnerability in Videolan VLC Media Player

Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary code via a malformed RealMedia (.rm) file that triggers a heap-based buffer overflow.

9.3
2008-12-05 CVE-2008-5343 SUN Privilege Escalation vulnerability in SUN Jdk, JRE and SDK

Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR" and CR 6707535.

9.0

33 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2008-12-01 CVE-2008-4314 Samba Information Exposure vulnerability in Samba

smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests, related to a "cut&paste error" that causes an improper bounds check to be performed.

8.5
2008-12-03 CVE-2008-5322 Easy Script Information Exposure vulnerability in Easy-Script Wysi Wiki WYG 1.0

Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.

7.8
2008-12-03 CVE-2008-5315 Apple
Microsoft
Path Traversal vulnerability in Apple Iphone Configuration web Utility 1.0

Directory traversal vulnerability in the web interface in Apple iPhone Configuration Web Utility 1.0 on Windows allows remote attackers to read arbitrary files via unspecified vectors.

7.8
2008-12-01 CVE-2008-5297 Vitalwerks Buffer Errors vulnerability in Vitalwerks No-Ip DUC 2.0.3/2.1/2.1.5

Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.

7.6
2008-12-05 CVE-2008-5351 SUN Permissions, Privileges, and Access Controls vulnerability in SUN Jdk, JRE and SDK

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the "shortest" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.

7.5
2008-12-05 CVE-2008-5347 SUN Permissions, Privileges, and Access Controls vulnerability in SUN JDK and JRE

Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.

7.5
2008-12-05 CVE-2008-5345 SUN Unspecified vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.

7.5
2008-12-05 CVE-2008-5344 SUN Unspecified vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.

7.5
2008-12-05 CVE-2008-5337 Multimania SQL Injection vulnerability in Multimania Bandsite Portal System and Bandwebsite

SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2008-12-05 CVE-2008-5336 Bdigital WEB Solutions SQL Injection vulnerability in Bdigital web Solutions Webstudio CMS NIL

SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

7.5
2008-12-05 CVE-2008-5333 Nitrotech SQL Injection vulnerability in Nitrotech 0.0.3A

SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2008-12-05 CVE-2007-6719 Inspector IT SQL Injection vulnerability in Inspector IT Wiz-Ad 1.3

SQL injection vulnerability in Wiz-Ad 1.3 allows remote attackers to execute arbitrary SQL commands via unknown vectors.

7.5
2008-12-05 CVE-2008-5331 Adobe Cryptographic Issues vulnerability in Adobe Acrobat 9/9.0

Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.

7.5
2008-12-05 CVE-2008-5329 IBM Denial-Of-Service vulnerability in Rational ClearQuest

ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple comma-separated server identifiers on the JTLRMIREGISTRYSERVERS line in a jtl.properties file.

7.5
2008-12-03 CVE-2008-5321 Xoops Hocasi
Xoops
SQL Injection vulnerability in Xoops Hocasi Gesgaleri NIL

SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

7.5
2008-12-03 CVE-2008-3058 Octeth SQL Injection vulnerability in Octeth Oempro 3.5.5.1

Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_Email parameter (aka Email field) to index.php in (1) member/, (2) client/, or (3) admin/; or (4) the FormValue_SearchKeywords parameter to client/campaign_track.php.

7.5
2008-12-02 CVE-2008-5311 Netart Media SQL Injection vulnerability in Netart Media Blog System 1.5

SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2008-12-02 CVE-2008-5310 Netart Media SQL Injection vulnerability in Netart Media CAR Portal 2.0

SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2008-12-02 CVE-2008-5309 Netart Media SQL Injection vulnerability in Netart Media Real Estate Portal 1.2

SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.

7.5
2008-12-02 CVE-2008-5308 Lovecms Permissions, Privileges, and Access Controls vulnerability in Lovecms the Simple Forum 3.1D

The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator password via a direct request to modules/simpleforum/admin/index.php.

7.5
2008-12-02 CVE-2008-5307 Pilot Group SQL Injection vulnerability in Pilot Group PG Real Roommate Finder Solution NIL

SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter.

7.5
2008-12-02 CVE-2008-5306 Pilot Group SQL Injection vulnerability in Pilot Group PG Real Estate Solution NIL

SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username).

7.5
2008-12-01 CVE-2008-5295 Jamit Software SQL Injection vulnerability in Jamit Software Jamit JOB Board 3.4.10

SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.

7.5
2008-12-01 CVE-2008-5294 Bdigital WEB Solutions SQL Injection vulnerability in Bdigital web Solutions Webstudio Ecatalogue NIL

SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

7.5
2008-12-01 CVE-2008-5293 Bdigital WEB Solutions SQL Injection vulnerability in Bdigital web Solutions Webstudio Ehotel NIL

SQL injection vulnerability in index.php in WebStudio eHotel allows remote attackers to execute arbitrary SQL commands via the pageid parameter.

7.5
2008-12-01 CVE-2008-5292 Videogirls SQL Injection vulnerability in Videogirls BIZ NIL

SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.

7.5
2008-12-01 CVE-2008-5291 Fuzzylime Path Traversal vulnerability in Fuzzylime CMS 3.03

Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter, a different vector than CVE-2007-4805 and CVE-2008-3165.

7.5
2008-12-01 CVE-2008-5289 Scripts4You SQL Injection vulnerability in Scripts4You Clean CMS 1.5

SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

7.5
2008-12-01 CVE-2008-5287 Scripts4You SQL Injection vulnerability in Scripts4You FAQ Manager 1.2

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

7.5
2008-12-01 CVE-2008-5286 Apple Numeric Errors vulnerability in Apple Cups

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which bypasses a validation check and triggers a buffer overflow.

7.5
2008-12-05 CVE-2008-5349 SUN Multiple Security vulnerability in SUN JDK and JRE

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.

7.1
2008-12-05 CVE-2008-5348 SUN Multiple Security vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.

7.1
2008-12-05 CVE-2008-5346 SUN Information Exposure vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.

7.1

34 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2008-12-03 CVE-2008-5313 Mailscanner Link Following vulnerability in Mailscanner

mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot-6-autoupdate scripts in /etc/MailScanner/autoupdate/; the (5) bitdefender-wrapper, (6) kaspersky-wrapper, (7) clamav-wrapper, and (8) rav-wrapper scripts in /etc/MailScanner/wrapper/; the (9) Quarantine.pm, (10) TNEF.pm, (11) MessageBatch.pm, (12) WorkArea.pm, and (13) SA.pm scripts in /usr/share/MailScanner/MailScanner/; (14) /usr/sbin/MailScanner; and (15) scripts that load the /etc/MailScanner/mailscanner.conf.with.mcp configuration file.

6.9
2008-12-03 CVE-2008-5312 Mailscanner Link Following vulnerability in Mailscanner

mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend-autoupdate.new, and (5) rav-autoupdate.new scripts in /etc/MailScanner/autoupdate/, a different vulnerability than CVE-2008-5140.

6.9
2008-12-01 CVE-2008-5303 Perl Race Condition vulnerability in Perl File::Path 1.08

Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827.

6.9
2008-12-01 CVE-2008-5302 Perl Race Condition vulnerability in Perl File::Path 1.08/2.07

Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink attack, a different vulnerability than CVE-2005-0448, CVE-2004-0452, and CVE-2008-2827.

6.9
2008-12-01 CVE-2008-5299 Karakas Online Link Following vulnerability in Karakas-Online Chm2Pdf 0.9

chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directories.

6.9
2008-12-05 CVE-2008-5335 PHP Fusion SQL Injection vulnerability in PHP-Fusion 6.01.15/7.00.1

SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the subject and msg_send parameters, a different vector than CVE-2005-3157, CVE-2005-3158, CVE-2005-3159, CVE-2005-4005, and CVE-2006-2459.

6.8
2008-12-01 CVE-2008-5296 Gallery Improper Authentication vulnerability in Gallery

Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cookies.

6.8
2008-12-01 CVE-2008-5288 Scripts4You Code Injection vulnerability in Scripts4You FAQ Manager 1.2

PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config_path parameter.

6.8
2008-12-05 CVE-2008-5327 IBM Credentials Management vulnerability in IBM Rational Clearquest

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree.

6.5
2008-12-03 CVE-2008-5320 E107 SQL Injection vulnerability in E107

SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.

6.5
2008-12-05 CVE-2008-5360 SUN Multiple Security vulnerability in SUN Jdk, JRE and SDK

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.

6.4
2008-12-01 CVE-2008-5301 Dovecot Path Traversal vulnerability in Dovecot

Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (dot dot) in a script name.

6.4
2008-12-05 CVE-2008-5350 SUN Information Exposure vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.

5.0
2008-12-05 CVE-2008-5342 SUN Information Exposure vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.

5.0
2008-12-05 CVE-2008-5341 SUN Information Exposure vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.

5.0
2008-12-05 CVE-2008-5339 SUN Unspecified vulnerability in SUN Jdk, JRE and SDK

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.

5.0
2008-12-03 CVE-2008-5319 Tiki Multiple Unspecified vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.

5.0
2008-12-03 CVE-2008-5318 Tiki Multiple Unspecified vulnerability in Tiki Tikiwiki Cms/Groupware 1.6.1

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.

5.0
2008-12-03 CVE-2008-3057 Octeth Cryptographic Issues vulnerability in Octeth Oempro 3.5.5.1

Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

5.0
2008-12-01 CVE-2008-5285 Wireshark Resource Management Errors vulnerability in Wireshark

Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.

5.0
2008-12-01 CVE-2008-5300 Linux Resource Management Errors vulnerability in Linux Kernel 2.6.28

Linux kernel 2.6.28 allows local users to cause a denial of service ("soft lockup" and process loss) via a large number of sendmsg function calls, which does not block during AF_UNIX garbage collection and triggers an OOM condition, a different vulnerability than CVE-2008-5029.

4.9
2008-12-05 CVE-2008-5328 IBM Cryptographic Issues vulnerability in IBM Rational Clearquest

The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which allows remote authenticated users to obtain sensitive information by locating the password object within the object tree during an import process.

4.6
2008-12-05 CVE-2008-4416 HP Local Denial Of Service vulnerability in HP Hp-Ux B.11.31

Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

4.6
2008-12-05 CVE-2008-5326 Microsoft
IBM
Credentials Management vulnerability in IBM Rational Clearquest

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database passwords by using a password revealer utility on a field containing a series of asterisks.

4.4
2008-12-05 CVE-2008-5338 Multimania Cross-Site Scripting vulnerability in Multimania Bandsite Portal System and Bandwebsite

Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

4.3
2008-12-05 CVE-2008-5330 IBM Cross-Site Scripting vulnerability in IBM Rational Clearquest

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and possibly other 7.0.1 versions before 7.0.1.3, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO of a URI associated with a VOB page.

4.3
2008-12-05 CVE-2008-5325 IBM Cross-Site Scripting vulnerability in IBM Rational Clearquest

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3
2008-12-05 CVE-2008-5324 IBM Cross-Site Scripting vulnerability in IBM Rational Clearquest 2007/2008

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3
2008-12-05 CVE-2008-2379 Squirrelmail Cross-Site Scripting vulnerability in Squirrelmail

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an e-mail message.

4.3
2008-12-03 CVE-2008-5323 Easy Script Cross-Site Scripting vulnerability in Easy-Script Wysi Wiki WYG 1.0

Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

4.3
2008-12-03 CVE-2008-5080 Awstats Cross-Site Scripting vulnerability in Awstats

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string parameter.

4.3
2008-12-03 CVE-2008-5314 Clam Anti Virus Resource Management Errors vulnerability in Clam Anti-Virus Clamav

Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.

4.3
2008-12-01 CVE-2008-5290 Scripts4You Cross-Site Scripting vulnerability in Scripts4You Clean CMS 1.5

Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

4.3
2008-12-03 CVE-2008-3059 Octeth Credentials Management vulnerability in Octeth Oempro 3.5.5.1

member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to the "Settings - Account Information" tab.

4.0

1 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2008-12-01 CVE-2008-5298 Karakas Online Unspecified vulnerability in Karakas-Online Chm2Pdf 0.9

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.

2.1