NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
3956 | CVE-2008-4098 | MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modified (1) DATA DIRECTORY or (2) INDEX DIRECTORY arguments that are originally associated with pathnames without symlinks, and that can point to tables created at a future time at which a pathname is modified to contain a symlink to a subdirectory of the MySQL home data directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4097. | 2 | 4.6 | Medium | 2017-01-03 | 2012-10-30 | View | |
3957 | CVE-2008-4099 | PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-19 | View | |
3958 | CVE-2008-4100 | GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: the vendor reports that this is intended behavior and is compatible with the product"s intended role in a trusted environment. | 2 | 6.4 | Medium | 2017-01-03 | 2008-09-19 | View | |
3959 | CVE-2008-4101 | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712. | 2 | 9.3 | High | 2017-01-03 | 2012-10-30 | View | |
3960 | CVE-2008-4102 | Joomla! 1.5 before 1.5.7 initializes PHP"s PRNG with a weak seed, which makes it easier for attackers to guess the pseudo-random values produced by PHP"s mt_rand function, as demonstrated by guessing password reset tokens, a different vulnerability than CVE-2008-3681. | 2 | 7.5 | High | 2017-01-03 | 2009-08-19 | View |
Page 792 of 17672, showing 5 records out of 88360 total, starting on record 3956, ending on 3960