Skip to main content

CWE archive

CWE-16 CVEs

Programmatic archive

318 CVEs tagged with CWE-1647 Critical, 77 High, 163 Medium, 31 Low, 0 Unrated.

CVE-2008-3228

Published Jul 18, 2008

Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF URLs, which has unknown impact and remote attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3115

Published Jul 9, 2008

Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2060

Published Jun 18, 2008

Unspecified vulnerability in Cisco Intrusion Prevention System (IPS) 5.x before 5.1(8)E2 and 6.x before 6.0(5)E2, when inline mode and jumbo Ethernet support are enabled, allows r…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2359

Published Jun 2, 2008

The default configuration of consolehelper in system-config-network before 1.5.10-1 on Fedora 8 lacks the USER=root directive, which allows local users of the workstation console…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2121

Published May 9, 2008

The TCP implementation in Sun Solaris 8, 9, and 10 allows remote attackers to cause a denial of service (CPU consumption and new connection timeouts) via a TCP SYN flood attack.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-2089

Published May 6, 2008

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1671

Published Apr 28, 2008

start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service and possibly execute arbitrary code via "user-influenceable i…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1778

Published Apr 14, 2008

Unspecified vulnerability in the floating point context switch implementation in Sun Solaris 9 and 10 on x86 platforms might allow local users to cause a denial of service (applic…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1156

Published Mar 27, 2008

Unspecified vulnerability in the Multicast Virtual Private Network (MVPN) implementation in Cisco IOS 12.0, 12.2, 12.3, and 12.4 allows remote attackers to create "extra multicast…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1287

Published Mar 11, 2008

IBM Rational ClearQuest 7.0.1.1 and 7.0.0.2 generates different error messages depending on whether the username is valid or invalid, which allows remote attackers to enumerate us…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1199

Published Mar 6, 2008

Dovecot before 1.0.11, when configured to use mail_extra_groups to allow Dovecot to create dotlocks in /var/mail, might allow local users to read sensitive mail files for other us…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0128

Published Jan 23, 2008

The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https sessio…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2007-6676

Published Jan 8, 2008

The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attac…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6505

Published Dec 20, 2007

Solaris 9, with Solaris Auditing enabled and certain patches for sshd installed, can generate audit records with an audit-ID of 0 even when the user logging into ssh is not root,…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-6285

Published Dec 20, 2007

The default configuration for autofs 5 (autofs5) in some Linux distributions, such as Red Hat Enterprise Linux (RHEL) 4 and 5, does not specify the nodev mount option for the -hos…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5856

Published Dec 19, 2007

Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote attackers to obtain sensitive info…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort
Showing 226-250 of 318 CVEsPage 10 of 13