LiveActive security incident?Get immediate response
CVE archive

October 2008

Browse CVE records published in October 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 542 matching CVEs · Page 4 of 11.

Unknown · CVSS Not scored

CVE-2008-4626: Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generatio...

Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng) 2.3.2 and possibly other versions through 2.3.3-beta0, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the album parameter.

Published Oct 21, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4678: The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6....

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."

Published Oct 22, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4676: Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, P...

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essentials 1.0, 1.5, and 2.0 allows local users to gain privileges via unknown attack vectors related to creating an unspecified file. NOTE: this might be the same issue as CVE-2008-3485, but the vendor advisory is too vague to be certain.

Published Oct 22, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-4690: lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows...

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.

Published Oct 22, 2008 · Updated Aug 7, 2024