 |
|
|
|
| Microsoft Publisher memory corruption | | Published: |  | 14.05.2008 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 8990 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | .PUB files memory corruption on embedded objects parsing. |
| Microsoft Jet engine buffer overflow | | Published: |  | 14.05.2008 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 8991 | | Type: |  | library | | Level: |  | 7/10 | | Description: |  | Buffer overflow on MDB files request handling. |
| Common Data Format library buffer overflow | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8995 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | Buffer overflow in Read32s_64() function. |
| Affected: |  | NASA : CDF 3.2 | | CVE: |  | CVE-2008-2080 (Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.) |
| Cisco Building Broadband Service Manager Captive Portal crossite scripting | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8996 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | Crossite scripting with
http://host/ekgnkm/AccessCodeStart.asp?msg=%3Cscript%3Ealert(%22XSS%22);%3C/script%3E |
| CVE: |  | CVE-2008-2165 (Cross-site scripting (XSS) vulnerability in AccessCodeStart.asp in Cisco Building Broadband Service Manager (BBSM) Captive Portal 5.3 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.) |
| Microsoft Word multiple security vulnerabilities | | Published: |  | 14.05.2008 | | Source: |  | MICROSOFT | | SecurityVulns ID: |  | 8989 | | Type: |  | remote | | Level: |  | 7/10 | | Description: |  | Memory coruption on RTF parsing, memory corruption on CSS parsing. |
| Microsoft Windows I2O driver privilege escalation | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8993 | | Type: |  | local | | Level: |  | 5/10 | | Description: |  | \\.\I2OExc device weak permissions, IOCTL data insufficient validation. |
| libid3tag library endless loop | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8998 | | Type: |  | library | | Level: |  | 5/10 | | Description: |  | Endless loop on MP3 files parsing. |
| Affected: |  | LIBID3TAG : libid3tag 0.15 | | CVE: |  | CVE-2008-2109 (field.c in the libid3tag 0.15.0b library allows context-dependent attackers to cause a denial of service (CPU consumption) via an ID3_FIELD_TYPE_STRINGLIST field that ends in '\0', which triggers an infinite loop.) |
| Cisco Unified Communications Manager DoS | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8999 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | DoS against Certificate Trust List (CTL) Provider (TCP/2444), Certificate Authority Proxy Function (CAPF) (TCP/3804), SIP and SNMP TRAP. |
| Adobe Distiller buffer overflow | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8997 | | Type: |  | client | | Level: |  | 5/10 | | Description: |  | Buffer overflow on .joboptions file parsing. |
| Microsoft antiviral applications multiple security vulnerabilities | | Published: |  | 14.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8992 | | Type: |  | remote | | Level: |  | 6/10 | | Description: |  | Multiple DoS conditions on different file formats parsing. |
| CVE: |  | CVE-2008-1438 (Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large temporary files, a different vulnerability than CVE-2008-1437.) | | |  | CVE-2008-1437 (Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.) |
Linux distributives OpenSSH / OpenSSL weak random generator updated since 14.05.2008 | | Published: |  | 15.05.2008 | | Source: |  | BUGTRAQ | | SecurityVulns ID: |  | 8994 | | Type: |  | library | | Level: |  | 6/10 | | Description: |  | Weak random generation in Debian-based distributives (Debian, Ubuntu). |
|
|
|
|
|
|
|
|