Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,897 CVEs tagged with CWE-201,634 Critical, 5,054 High, 5,684 Medium, 521 Low, 4 Unrated.

CVE-2008-3230

Published Jul 18, 2008

The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by l…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3231

Published Jul 18, 2008

xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstrated by playing lol-ffplay.ogg with xine.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3208

Published Jul 18, 2008

Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of service via multiple DNS reply packets.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3210

Published Jul 18, 2008

rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daemon crash) via a SIP (1) INVITE or (2) OPTIONS message with…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2933

Published Jul 17, 2008

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to a…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-3199

Published Jul 17, 2008

Multiple unspecified vulnerabilities in ReSIProcate before 1.3.4 allow remote attackers to cause a denial of service (stack consumption) via unknown network traffic with a large "…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3145

Published Jul 16, 2008

The fragment_add_work function in epan/reassemble.c in Wireshark 0.8.19 through 1.0.1 allows remote attackers to cause a denial of service (crash) via a series of fragmented packe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3178

Published Jul 15, 2008

Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute arbitrary code by uploading a .php file with a jpeg conten…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3181

Published Jul 15, 2008

Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable ext…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3127

Published Jul 10, 2008

PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals is enabled, allows remote attackers to execute arbitrary PH…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3137

Published Jul 10, 2008

The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.2 through 1.0.0 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3117

Published Jul 10, 2008

Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated users to execute arbitrary code by uploading a .php file with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3111

Published Jul 9, 2008

Multiple buffer overflows in Sun Java Web Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allow context-dependent a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3081

Published Jul 9, 2008

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Storage Server (MSS) 3.x and 4.0,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2805

Published Jul 7, 2008

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to force the upload of arbitrary local files from a client computer via vectors involving origin…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2970

Published Jul 2, 2008

Multiple session fixation vulnerabilities in Academic Web Tools (AWT YEKTA) 1.4.3.1, and 1.4.2.8 and earlier, allow remote attackers to hijack web sessions by setting the PHPSESSI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2988

Published Jul 2, 2008

Unrestricted file upload vulnerability in admin/upload.php in Benja CMS 0.1 allows remote attackers to upload and execute arbitrary PHP files via unspecified vectors, followed by…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2372

Published Jul 2, 2008

The Linux kernel 2.6.24 and 2.6.25 before 2.6.25.9 allows local users to cause a denial of service (memory consumption) via a large number of calls to the get_user_pages function,…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2953

Published Jul 1, 2008

Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via "partial file list requests" that trigger a NULL pointer dereference.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2954

Published Jul 1, 2008

client/NmdcHub.cpp in Linux DC++ (linuxdcpp) before 0.707 allows remote attackers to cause a denial of service (crash) via an empty private message, which triggers an out-of-bound…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2955

Published Jul 1, 2008

Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 12,301-12,325 of 12,897 CVEsPage 493 of 516