LiveActive security incident?Get immediate response
CVE archive

November 2008

Browse CVE records published in November 2008, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 438 matching CVEs · Page 4 of 9.

Unknown · CVSS Not scored

CVE-2008-5026: Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and in...

Microsoft SharePoint uses URLs with the same hostname and port number for a web site's primary files and individual users' uploaded files (aka attachments), which allows remote authenticated users to leverage same-origin relationships and conduct cross-site scripting (XSS) attacks by uploading HTML documents.

Published Nov 10, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5133: ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Netwo...

ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, improperly changes the source port of a packet when the destination port is the DNS port, which allows remote attackers to bypass an intended CVE-2008-1447 protection mechanism and spoof the responses to DNS queries sent by named.

Published Nov 18, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5021: nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, a...

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

Published Nov 13, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5090: Electron Inc.

Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code embedded in bbcode in the email parameter, which is processed by the preg_replace function with the eval switch.

Published Nov 14, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5099: Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot...

Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992.

Published Nov 17, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5177: Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (...

Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute arbitrary code on a Linux platform, related to libytlindtb.so; or (2) cause a denial of service (application crash) and possibly execute arbitrary code on a Windows platform, related to ytwindtb.dll; via a long username field during authentication.

Published Nov 20, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5187: The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to caus...

The load function in the XPM loader for imlib2 1.4.2, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted XPM file that triggers a "pointer arithmetic error" and a heap-based buffer overflow, a different vulnerability than CVE-2008-2426.

Published Nov 21, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5162: The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for...

The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function's return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator.

Published Nov 26, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5121: dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1)...

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, and (3) SafeNet SoftRemote and HighAssurance Remote, allows local users to gain privileges via a crafted DNE_IOCTL DeviceIoControl request to the \\.\DNE device interface.

Published Nov 18, 2008 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2008-5172: Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to in...

Multiple cross-site scripting (XSS) vulnerabilities in Yazd Forum Software 3.x allow remote attackers to inject arbitrary web script or HTML via the (1) q parameter to (a) search.jsp, and the (2) msg parameter to (b) error.jsp and (c) userAccount.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 19, 2008 · Updated Aug 7, 2024