NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6558  CVE-2008-6827  The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allows local users to gain SYSTEM privileges and execute arbitrary commands via a "Shatter" style attack on the "command prompt" hidden GUI button to (1) overwrite the CommandLine parameter to cmd.exe to use SYSTEM privileges and (2) modify the DLL that is loaded using the LoadLibrary API function.    6.8  Medium  2017-01-03  2009-06-09  View
48542  CVE-2009-1255  The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the locations of memory regions, and defeat ASLR protection, by sending a command to the daemon"s TCP port.    Medium  2017-01-07  2009-06-09  View
6559  CVE-2008-6828  Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory in cleartext, which allows local users to gain privileges and modify clients of the Deployment Solution Server.    4.3  Medium  2017-01-03  2009-06-09  View
6560  CVE-2008-6829  VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "//" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.    Medium  2017-01-03  2009-06-09  View
49056  CVE-2009-1787  Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.    7.5  High  2017-01-07  2009-06-09  View

Page 3123 of 17672, showing 5 records out of 88360 total, starting on record 15611, ending on 15615

Actions