LiveActive security incident?Get immediate response
CVE archive

September 2008

Browse CVE records published in September 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 561 matching CVEs · Page 5 of 12.

Unknown · CVSS Not scored

CVE-2008-4210: fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a...

fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.

Published Sep 29, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4190: The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to ove...

The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack on the (1) ipseclive.conn and (2) ipsec.olts.remote.log temporary files. NOTE: in many distributions and the upstream version, this tool has been disabled.

Published Sep 24, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4155: Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files...

Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list directories via a .. (dot dot) in the (1) module or (2) action parameter in (a) www/index.php; the (3) module, (4) ss_module, or (5) ss_action parameter in (b) modules/Module/index.php or (c) modules/Themes/index.php; or the (6) module parameter in (d) inc/vmenu.php.

Published Sep 19, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4181: Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.1...

Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for cPanel, when cPanel PHP Register Globals is enabled, allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) or absolute pathname in the fantasticopath parameter. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.

Published Sep 23, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4197: Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu command...

Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or conduct other attacks via vectors related to activation of a shortcut.

Published Sep 27, 2008 · Updated Aug 7, 2024