<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:admin="http://webns.net/mvcb/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/"><channel rdf:about="http://nvd.nist.gov/download/nvd-rss-analyzed.xml"><title>National Vulnerability Database</title><link>http://nvd.nist.gov/nvd.cfm</link><description>This feed contains the most recent fully analyzed CVE cyber vulnerabilities published within the National Vulnerability Database.</description><dc:language xmlns:dc="http://purl.org/dc/elements/1.1/">en-us</dc:language><dc:rights xmlns:dc="http://purl.org/dc/elements/1.1/">This material is not copywritten and may be freely used, however, attribution is requested.</dc:rights><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05T01:33:02-05:00</dc:date><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">nvd@nist.gov</dc:creator><items><rdf:Seq xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3664" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3531" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3530" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2436" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1197" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1144" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5474" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3945" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3944" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3943" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3942" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3941" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3940" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3939" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3938" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3937" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3936" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3935" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3934" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3933" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3932" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3903" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3931" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3930" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3929" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3928" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3927" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3926" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3925" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3924" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3923" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3922" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3921" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3920" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3919" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3918" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3917" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3916" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3911" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3910" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3909" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3908" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3907" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3906" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3905" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3904" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6716" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2736" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2735" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2734" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2733" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2732" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2441" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1389" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3902" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1739" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3901" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3900" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3899" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3898" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3897" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3896" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3895" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3894" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3893" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3892" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3891" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3792" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3791" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3698" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3697" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3696" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3695" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3694" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3693" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3692" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3691" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3537" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3536" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3525" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3101" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2101" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3888" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3887" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3886" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3885" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3884" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3883" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3882" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3881" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3880" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3879" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3878" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3877" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3876" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3875" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3538" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3146" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2728" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/><rdf:li rdf:resource="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2727" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"/></rdf:Seq></items></channel><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3664"><title>CVE-2008-3664 (xrms_crm)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3664</link><description>Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php, (5) the last_name parameter to contacts/some.php, (6) the campaign_title parameter to campaigns/some.php, (7) the opportunity_title parameter to opportunities/some.php, (8) the ca...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3531"><title>CVE-2008-3531 (FreeBSD)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3531</link><description>Stack-based buffer overflow in sys/kern/vfs_mount.c in the kernel in FreeBSD 7.0 and 7.1, when vfs.usermount is enabled, allows local users to gain privileges via a crafted (1) mount or (2) nmount system call, related to copying of &quot;user defined data&quot; in &quot;certain error conditions.&quot;</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3530"><title>CVE-2008-3530 (FreeBSD)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3530</link><description>sys/netinet6/icmp6.c in the kernel in FreeBSD 6.3 through 7.1 does not properly check the proposed new MTU in an ICMPv6 Packet Too Big Message, which allows remote attackers to cause a denial of service (panic) via a crafted Packet Too Big Message.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2436"><title>CVE-2008-2436 (iPrint Client)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2436</link><description>Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1197"><title>CVE-2008-1197 (wn802t, 88w8361w-bem1)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1197</link><description>The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse the SSID information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a &quot;Null SSID.&quot;</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1144"><title>CVE-2008-1144 (wn802t, 88w8361w-bem1)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1144</link><description>The Marvell driver for the Netgear WN802T Wi-Fi access point with firmware 1.3.16 on the Marvell 88W8361P-BEM1 chipset does not properly parse EAPoL-Key packets, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via a malformed EAPoL-Key packet with a crafted &quot;advertised length.&quot;</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5474"><title>CVE-2007-5474 (WRT350N, ar5416-ac1e_chipset)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-5474</link><description>The driver for the Linksys WRT350N Wi-Fi access point with firmware 2.00.17 on the Atheros AR5416-AC1E chipset does not properly parse the Atheros vendor-specific information element in an association request, which allows remote authenticated users to cause a denial of service (device reboot or hang) or possibly execute arbitrary code via an Atheros information element with an invalid length, as demonstrated by an element that is too long.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3945"><title>CVE-2008-3945 (words_tag_script)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3945</link><description>SQL injection vulnerability in index.php in Words tag 1.2 allows remote attackers to execute arbitrary SQL commands via the word parameter in a claim action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3944"><title>CVE-2008-3944 (acg_ptp)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3944</link><description>SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via the adid parameter in an adorder action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3943"><title>CVE-2008-3943 (living_local)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3943</link><description>SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrary SQL commands via the r parameter.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3942"><title>CVE-2008-3942 (full_php_emlak_script)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3942</link><description>SQL injection vulnerability in landsee.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL commands via the id parameter.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3941"><title>CVE-2008-3941 (bizdirectory)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3941</link><description>Cross-site scripting (XSS) vulnerability in BizDirectory 2.04 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter in a search action to the default URI.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3940"><title>CVE-2008-3940 (OpenVMS)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3940</link><description>Format string vulnerability in the finger client in HP TCP/IP Services for OpenVMS 5.x allows local users to gain privileges via format string specifiers in a (1) .plan or (2) .project file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3939"><title>CVE-2008-3939 (pager_enterprise)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3939</link><description>Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3938"><title>CVE-2008-3938 (OpenDb)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3938</link><description>Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allows remote attackers to change arbitrary passwords via an update_password action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3937"><title>CVE-2008-3937 (OpenDb)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3937</link><description>Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) user_id parameter in an edit action to user_admin.php, the (2) title parameter to listings.php, and the (3) redirect_url parameter to user_profile.php.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3936"><title>CVE-2008-3936 (DM500C)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3936</link><description>The web interface in Dreambox DM500C allows remote attackers to cause a denial of service (application hang) via a long URI.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3935"><title>CVE-2008-3935 (shop_v50, shop_v52)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3935</link><description>Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-05</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3934"><title>CVE-2008-3934 (Wireshark)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3934</link><description>Unspecified vulnerability in Wireshark (formerly Ethereal) 0.99.6 through 1.0.2 allows attackers to cause a denial of service (crash) via a crafted Tektronix .rf5 file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3933"><title>CVE-2008-3933 (Wireshark)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3933</link><description>Wireshark (formerly Ethereal) 0.10.14 through 1.0.2 allows attackers to cause a denial of service (crash) via a packet with crafted zlib-compressed data that triggers an invalid read in the tvb_uncompress function.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3932"><title>CVE-2008-3932 (Wireshark)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3932</link><description>Wireshark (formerly Ethereal) 0.9.7 through 1.0.2 allows attackers to cause a denial of service (hang) via a crafted NCP packet that triggers an infinite loop.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3903"><title>CVE-2008-3903 (p_b_x, pbx)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3903</link><description>Asterisk PBX 1.2 through 1.6 and Trixbox PBX 2.6.1, when running with Digest authentication and authalwaysreject enabled, generates different responses depending on whether or not a SIP username is valid, which allows remote attackers to enumerate valid usernames.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3931"><title>CVE-2008-3931 (r)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3931</link><description>javareconf in R 2.7.2 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3930"><title>CVE-2008-3930 (citadel_server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3930</link><description>migrate_aliases.sh in Citadel Server 7.37 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3929"><title>CVE-2008-3929 (Ampache)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3929</link><description>gather-messages.sh in Ampache 3.4.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3928"><title>CVE-2008-3928 (honeyd_common)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3928</link><description>test.sh in Honeyd 1.5c might allow local users to overwrite arbitrary files via a symlink attack on temporary files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3927"><title>CVE-2008-3927 (tiger)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3927</link><description>genmsgidx in Tiger 3.2.2 allows local users to overwrite or delete arbitrary files via a symlink attack on temporary files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3926"><title>CVE-2008-3926 (cmme)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3926</link><description>Multiple directory traversal vulnerabilities in Content Management Made Easy (CMME) 1.12 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the env parameter in a weblog action to index.php, or (2) create arbitrary directories via a .. (dot dot) in the env parameter in a login action to admin.php.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3925"><title>CVE-2008-3925 (cmme)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3925</link><description>Cross-site request forgery (CSRF) vulnerability in admin.php in Content Management Made Easy (CMME) 1.12 allows remote attackers to trigger the logout of an administrative user via a logout action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3924"><title>CVE-2008-3924 (cmme)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3924</link><description>The &quot;Make a backup&quot; functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3923"><title>CVE-2008-3923 (cmme)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3923</link><description>Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow remote attackers to inject arbitrary web script or HTML via the (1) page and (2) year parameters in an hstat_year action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3922"><title>CVE-2008-3922 (awstats_totals)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3922</link><description>awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences in the sort parameter, which is used by the multisort function when dynamically creating an anonymous PHP function.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3921"><title>CVE-2008-3921 (awstats_totals)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3921</link><description>Multiple cross-site scripting (XSS) vulnerabilities in AWStats Totals 1.0 through 1.14 allow remote attackers to inject arbitrary web script or HTML via the (1) month and (2) year parameter.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3920"><title>CVE-2008-3920 (bitlbee)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3920</link><description>Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to &quot;recreate&quot; and &quot;hijack&quot; existing accounts via unspecified vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3919"><title>CVE-2008-3919 (ichitaro)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3919</link><description>Unspecified vulnerability in multiple JustSystems Ichitaro products allows remote attackers to execute arbitrary code via a crafted JTD document, as exploited in the wild in August 2008.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3918"><title>CVE-2008-3918 (ovidentia)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3918</link><description>SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3917"><title>CVE-2008-3917 (ovidentia)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3917</link><description>Cross-site scripting (XSS) vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to inject arbitrary web script or HTML via the field parameter in a search action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3916"><title>CVE-2008-3916 (Ed)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3916</link><description>Heap-based buffer overflow in the strip_escapes function in signal.c in GNU ed before 1.0 allows context-dependent or user-assisted attackers to execute arbitrary code via a long filename.  NOTE: since ed itself does not typically run with special privileges, this issue only crosses privilege boundaries when ed is invoked as a third-party component.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3911"><title>CVE-2008-3911 (Kernel)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3911</link><description>The proc_do_xprt function in net/sunrpc/sysctl.c in the Linux kernel 2.6.26.3 does not check the length of a certain buffer obtained from userspace, which allows local users to overflow a stack-based buffer and have unspecified other impact via a crafted read system call for the /proc/sys/sunrpc/transports file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3910"><title>CVE-2008-3910 (dns2tcp)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3910</link><description>dns2tcp before 0.4.1 does not properly handle negative values in a certain length field in the input argument to the (1) dns_simple_decode or (2) dns_decode function, which allows remote attackers to overwrite a buffer and have unspecified other impact.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3909"><title>CVE-2008-3909 (Django)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3909</link><description>The administration application in Django 0.91, 0.95, and 0.96 stores unauthenticated HTTP POST requests and processes them after successful authentication occurs, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks and delete or modify data via unspecified requests.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3908"><title>CVE-2008-3908 (wordnet)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3908</link><description>Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-supplied dictionary (aka data file).  NOTE: since WordNet itself does not run with special privileges, this issue only crosses privilege boundaries when WordNet is invoked as a third party component.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3907"><title>CVE-2008-3907 (newsbeuter)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3907</link><description>The open-in-browser command in newsbeuter before 1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in a feed URL.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3906"><title>CVE-2008-3906 (Mono)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3906</link><description>CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3905"><title>CVE-2008-3905 (Ruby)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3905</link><description>resolv.rb in Ruby 1.8.5 and earlier, 1.8.6 before 1.8.6-p287, 1.8.7 before 1.8.7-p72, and 1.9 r18423 and earlier uses sequential transaction IDs and constant source ports for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3904"><title>CVE-2008-3904 (gpicview)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3904</link><description>src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6716"><title>CVE-2007-6716 (Kernel)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6716</link><description>fs/direct-io.c in the dio subsystem in the Linux kernel before 2.6.23 does not properly zero out the dio struct, which allows local users to cause a denial of service (OOPS), as demonstrated by a certain fio test.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2736"><title>CVE-2008-2736 (adaptive_security_appliance_5500)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2736</link><description>Unspecified vulnerability in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0(3)15, 8.0(3)16, 8.1(1)4, and 8.1(1)5, when configured as a clientless SSL VPN endpoint, allows remote attackers to obtain usernames and passwords via unknown vectors, aka Bug ID CSCsq45636.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2735"><title>CVE-2008-2735 (adaptive_security_appliance_5500)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2735</link><description>The HTTP server in Cisco Adaptive Security Appliance (ASA) 5500 devices 8.0 before 8.0(3)15 and 8.1 before 8.1(1)5, when configured as a clientless SSL VPN endpoint, does not properly process URIs, which allows remote attackers to cause a denial of service (device reload) via a URI in a crafted SSL or HTTP packet, aka Bug ID CSCsq19369.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2734"><title>CVE-2008-2734 (adaptive_security_appliance_5500)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2734</link><description>Memory leak in the crypto functionality in Cisco Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a clientless SSL VPN endpoint, allows remote attackers to cause a denial of service (memory consumption and VPN hang) via a crafted SSL or HTTP packet, aka Bug ID CSCso66472.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2733"><title>CVE-2008-2733 (adaptive_security_appliance_5500, PIX)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2733</link><description>Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.2 before 7.2(4)2, 8.0 before 8.0(3)14, and 8.1 before 8.1(1)4, when configured as a client VPN endpoint, do not properly process IPSec client authentication, which allows remote attackers to cause a denial of service (device reload) via a crafted authentication attempt, aka Bug ID CSCso69942.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2732"><title>CVE-2008-2732 (adaptive_security_appliance_5500, PIX)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2732</link><description>Multiple unspecified vulnerabilities in the SIP inspection functionality in Cisco PIX and Adaptive Security Appliance (ASA) 5500 devices 7.0 before 7.0(7)16, 7.1 before 7.1(2)71, 7.2 before 7.2(4)7, 8.0 before 8.0(3)20, and 8.1 before 8.1(1)8 allow remote attackers to cause a denial of service (device reload) via unknown vectors, aka Bug IDs CSCsq07867, CSCsq57091, CSCsk60581, and CSCsq39315.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2441"><title>CVE-2008-2441 (Cisco Secure Access Control Server, Secure ACS)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2441</link><description>CSRadius.exe in Cisco Secure ACS does not properly handle an EAP Response packet in which the value of the length field exceeds the actual packet length, which allows remote attackers to cause a denial of service (service crash) or possibly execute arbitrary code via a crafted (1) EAP-Response/Identity, (2) EAP-Response/MD5, or (3) EAP-Response/TLS packet.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1389"><title>CVE-2008-1389 (ClamAV)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1389</link><description>libclamav/chmunpack.c in the chm-parser in ClamAV before 0.94 allows remote attackers to cause a denial of service (application crash) via a malformed CHM file, related to an &quot;invalid memory access.&quot;</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-04</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3902"><title>CVE-2008-3902 (68dtt)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3902</link><description>HP firmware 68DTT F.0D stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer, aka SSRT080104.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1739"><title>CVE-2008-1739 (Quicktime)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1739</link><description>Apple QuickTime before 7.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted ftyp atoms in a movie file, which triggers memory corruption.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3901"><title>CVE-2008-3901 (software_suspend_2)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3901</link><description>Software suspend 2 2-2.2.1, when used with the Linux kernel 2.6.16, stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3900"><title>CVE-2008-3900 (bios)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3900</link><description>Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3899"><title>CVE-2008-3899 (TrueCrypt)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3899</link><description>TrueCrypt 5.0 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.  NOTE: the researcher mentions a response from the vendor denying the vulnerability.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3898"><title>CVE-2008-3898 (drivecrypt_plus_pack)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3898</link><description>Secu Star DriveCrypt Plus Pack 3.9 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3897"><title>CVE-2008-3897 (disckcryptor)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3897</link><description>DiskCryptor 0.2.6 on Windows stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3896"><title>CVE-2008-3896 (grub_legacy)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3896</link><description>Grub Legacy 0.97 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3895"><title>CVE-2008-3895 (lilo)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3895</link><description>LILO 22.6.1 and earlier stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer before and after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3894"><title>CVE-2008-3894 (lenovo_7cetb5ww)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3894</link><description>IBM Lenovo firmware 7CETB5WW 2.05 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3893"><title>CVE-2008-3893 (windows-nt)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3893</link><description>Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer during boot, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3892"><title>CVE-2008-3892 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3892</link><description>Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a ca...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3891"><title>CVE-2008-3891 (google_apps)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3891</link><description>The SAML Single Sign-On (SSO) Service for Google Apps allows remote service providers to impersonate users at arbitrary service providers via vectors related to authentication responses that lack a request identifier and recipient field.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3792"><title>CVE-2008-3792 (Kernel)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3792</link><description>net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel 2.6.26.3 does not verify that the SCTP-AUTH extension is enabled before proceeding with SCTP-AUTH API functions, which allows attackers to cause a denial of service (panic) via vectors that result in calls to (1) sctp_setsockopt_auth_chunk, (2) sctp_setsockopt_hmac_ident, (3) sctp_setsockopt_auth_key, (4) sctp_setsockopt_active_key, (5) sctp_setsockopt_del_key, (6) sctp_getsockopt_maxburst,...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3791"><title>CVE-2008-3791 (lightweight_x11_desktop_environment)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3791</link><description>src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3698"><title>CVE-2008-3698 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3698</link><description>Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 on Windows allows local host OS users to gain privileges on the host OS via unknown vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3697"><title>CVE-2008-3697 (VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3697</link><description>An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3696"><title>CVE-2008-3696 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3696</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3695"><title>CVE-2008-3695 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3695</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3694"><title>CVE-2008-3694 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3694</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3693"><title>CVE-2008-3693 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3693</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3692, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3692"><title>CVE-2008-3692 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3692</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3691, CVE-2008-3693, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3691"><title>CVE-2008-3691 (VMWare Workstation, VMWare Player, ACE, VMware Server)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3691</link><description>Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-3692, CVE-2008-3693, CVE-2008-3...</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3537"><title>CVE-2008-3537 (OpenView Network Node Manager)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3537</link><description>Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3536.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3536"><title>CVE-2008-3536 (OpenView Network Node Manager)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3536</link><description>Unspecified vulnerability in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2008-3537.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3525"><title>CVE-2008-3525 (Kernel)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3525</link><description>The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability before processing a (1) SIOCDEVRESINSTATS, (2) SIOCDEVSHWSTATE, (3) SIOCDEVENSLAVE, or (4) SIOCDEVEMANSIPATE ioctl request, which allows local users to bypass intended capability restrictions.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3101"><title>CVE-2008-3101 (vtiger_crm)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3101</link><description>Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the parenttab parameter in an index action to the Products module, as reachable through index.php; (2) the user_password parameter in an Authenticate action to the Users module, as reachable through index.php; or (3) the query_string parameter in a UnifiedSearch action to the Home module, as reachable through index.php.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2101"><title>CVE-2008-2101 (esx)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2101</link><description>The VMware Consolidated Backup (VCB) command-line utilities in VMware ESX 3.0.1 through 3.0.3 and ESX 3.5 place a password on the command line, which allows local users to obtain sensitive information by listing the process.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-03</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3888"><title>CVE-2008-3888 (mini_nuke_freehost)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3888</link><description>SQL injection vulnerability in members.asp in Mini-NUKE Freehost 2.3 allows remote attackers to execute arbitrary SQL commands via the uid parameter in a member_details action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3887"><title>CVE-2008-3887 (dotProject)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3887</link><description>Multiple SQL injection vulnerabilities in index.php in dotProject 2.1.2 allow (1) remote authenticated users to execute arbitrary SQL commands via the tab parameter in a projects action, and (2) remote authenticated administrators to execute arbitrary SQL commands via the user_id parameter in a viewuser action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3886"><title>CVE-2008-3886 (dotProject)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3886</link><description>Multiple cross-site scripting (XSS) vulnerabilities in index.php in dotProject 2.1.2 allow remote attackers to inject arbitrary web script or HTML via (1) the inactive parameter in a tasks action, (2) the date parameter in a calendar day_view action, (3) the callback parameter in a public calendar action, or (4) the type parameter in a ticketsmith action.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3885"><title>CVE-2008-3885 (Blogn)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3885</link><description>Cross-site request forgery (CSRF) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to make content modifications as arbitrary users via unspecified vectors.  NOTE: some of these details are obtained from third party information.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3884"><title>CVE-2008-3884 (Blogn)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3884</link><description>Cross-site scripting (XSS) vulnerability in Blogn (BURO GUN) 1.9.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different issue than CVE-2006-6176.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3883"><title>CVE-2008-3883 (caudium)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3883</link><description>configvar in Caudium 1.4.12 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/roken#####.pike temporary file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3882"><title>CVE-2008-3882 (zoneminder)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3882</link><description>ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary commands (aka &quot;Command Injection&quot;) via (1) the executeFilter function in zm_html_view_events.php and (2) the run_state parameter to zm_html_view_state.php.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3881"><title>CVE-2008-3881 (zoneminder)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3881</link><description>Multiple cross-site scripting (XSS) vulnerabilities in ZoneMinder 1.23.3 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to unspecified &quot;zm_html_view_*.php&quot; files.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3880"><title>CVE-2008-3880 (zoneminder)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3880</link><description>SQL injection vulnerability in zm_html_view_event.php in ZoneMinder 1.23.3 and earlier allows remote attackers to execute arbitrary SQL commands via the filter array parameter.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3879"><title>CVE-2008-3879 (ultra_office_control)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3879</link><description>The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3878"><title>CVE-2008-3878 (ultra_office_control)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3878</link><description>Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3877"><title>CVE-2008-3877 (mixcraft)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3877</link><description>Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execute arbitrary code via a crafted .mx4 file.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3876"><title>CVE-2008-3876 (iPhone)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3876</link><description>Apple iPhone 2.0.2, in some configurations, allows physically proximate attackers to bypass intended access restrictions, and obtain sensitive information or make arbitrary use of the device, via an Emergency Call tap and a Home double-tap, followed by a tap of any contact&apos;s blue arrow.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3875"><title>CVE-2008-3875 (Solaris, opensolaris)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3875</link><description>The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions multi-level security policy, and establish a covert communication channel, via unspecified vectors involving system calls.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3538"><title>CVE-2008-3538 (Libxml2)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3538</link><description>libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, aka the &quot;billion laughs attack.&quot;</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3146"><title>CVE-2008-3146 (Wireshark, Ethereal)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3146</link><description>Unspecified vulnerability in Wireshark and Ethereal on SUSE Linux allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2728"><title>CVE-2008-2728 (Ruby)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2728</link><description>Integer overflow in the rb_ary_splice function in Ruby 1.6.x allows context-dependent attackers to trigger memory corruption, aka the &quot;1.6.x variant&quot; of the &quot;beg + rlen&quot; issue.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item><item rdf:about="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2727"><title>CVE-2008-2727 (Ruby)</title><link>http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2727</link><description>Integer overflow in the rb_ary_splice function in Ruby 1.6.x allows context-dependent attackers to trigger memory corruption via unspecified vectors, aka the &quot;1.6.x variant&quot; of the &quot;REALLOC_N&quot; variant.</description><dc:date xmlns:dc="http://purl.org/dc/elements/1.1/">2008-09-02</dc:date></item></rdf:RDF>

