LiveActive security incident?Get immediate response
CVE archive

February 2008

Browse CVE records published in February 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 836 matching CVEs · Page 7 of 17.

Unknown · CVSS Not scored

CVE-2008-6107: The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in ar...

The (1) sys32_mremap function in arch/sparc64/kernel/sys_sparc32.c, the (2) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c, and the (3) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel before 2.6.25.4, omit some virtual-address range (aka span) checks when the mremap MREMAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mremap calls, a related issue to CVE-2008-2137.

Published Feb 10, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6071: Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, an...

Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party information.

Published Feb 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6062: Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created b...

Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637.

Published Feb 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6070: Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick befo...

Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information.

Published Feb 6, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6065: Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that...

Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTORY statement, which allows remote authenticated users with CREATE ANY DIRECTORY privileges to gain SYSDBA privileges by aliasing the pathname of the password directory, and then overwriting the password file through UTL_FILE operations, a related issue to CVE-2006-7141.

Published Feb 5, 2009 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-6059: xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages...

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

Published Feb 5, 2009 · Updated Aug 7, 2024