NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2071  CVE-2008-2137  The (1) sparc_mmap_check function in arch/sparc/kernel/sys_sparc.c and the (2) sparc64_mmap_check function in arch/sparc64/kernel/sys_sparc.c, in the Linux kernel 2.4 before 2.4.36.5 and 2.6 before 2.6.25.3, omit some virtual-address range (aka span) checks when the mmap MAP_FIXED bit is not set, which allows local users to cause a denial of service (panic) via unspecified mmap calls.    4.4  Medium  2017-01-03  2012-03-19  View
2072  CVE-2008-2138  Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.    Medium  2017-01-03  2009-02-26  View
2073  CVE-2008-2139  The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, including requests to change the password, which makes it easier for physically proximate attackers to gain privileges and maintain control over the administrator account.    6.5  Medium  2017-01-03  2008-09-05  View
2074  CVE-2008-2140  Cross-site request forgery (CSRF) vulnerability in the rootpw plugin in rPath Appliance Platform Agent 2 and 3 allows remote attackers to reset the root password as the administrator via a crafted URL.    2.6  Low  2017-01-03  2008-09-05  View
2075  CVE-2008-2142  Emacs 21 and XEmacs automatically load and execute .flc (fast lock) files that are associated with other files that are edited within Emacs, which allows user-assisted attackers to execute arbitrary code.    6.8  Medium  2017-01-03  2011-03-07  View

Page 415 of 17672, showing 5 records out of 88360 total, starting on record 2071, ending on 2075

Actions