Monthly Archives: May 2008



CVE-2008-2092 (SPA-2102 Phone Adapter)

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet (“ping of death”). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2080 (Common Data Format)

Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

Posted in Badware | Leave a comment

CVE-2008-2092 (SPA-2102 Phone Adapter)

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet (“ping of death”). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

Posted in Badware | Leave a comment

CVE-2008-2092 (SPA-2102 Phone Adapter)

Linksys SPA-2102 Phone Adapter 3.3.6 allows remote attackers to cause a denial of service (crash) via a long ping packet (“ping of death”). NOTE: the severity of this issue has been disputed since there are limited attack scenarios.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment

CVE-2008-2091 (kubelance)

Directory traversal vulnerability in ipn.php in KubeLabs Kubelance 1.6.4 allows remote attackers to include and execute arbitrary local files via the i parameter.

Posted in Badware | Leave a comment

CVE-2008-2087 (Web Hosting Directory Script)

SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.

Posted in Badware | Leave a comment

CVE-2008-2080 (Common Data Format)

Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.

Posted in Badware | Leave a comment

CVE-2008-2089 (Solaris)

Unspecified vulnerability in the SCTP protocol implementation in Sun Solaris 10 allows remote attackers to cause a denial of service (panic) via a crafted SCTP packet.

Posted in Badware | Leave a comment