2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-3867 | — | — | 1.2% | Nov 3, 2008 | SQL injection vulnerability in spaces/emailuser.php in Interact 2.4.1 allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-4878 | — | — | 4.0% | Nov 1, 2008 | Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated admi... |
| CVE-2008-4877 | — | — | 1.0% | Nov 1, 2008 | SQL injection vulnerability in admin.php in WebCards 1.3, when magic_quotes_gpc is disabled, allows remote attackers to ... |
| CVE-2008-4876 | — | — | 1.8% | Nov 1, 2008 | Cross-site scripting (XSS) vulnerability in the web server component in Philips Electronics VOIP841 DECT Phone with firm... |
| CVE-2008-4875 | — | — | 3.1% | Nov 1, 2008 | Directory traversal vulnerability in the web server in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and... |
| CVE-2008-4874 | — | — | 3.5% | Nov 1, 2008 | The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service... |
| CVE-2008-4873 | — | — | 4.9% | Nov 1, 2008 | board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the fil... |
| CVE-2008-4872 | — | — | 0.8% | Nov 1, 2008 | Cross-site scripting (XSS) vulnerability in bidhistory.php in iTechBids Gold 5.0 allows remote attackers to inject arbit... |
| CVE-2008-4871 | — | — | 1.0% | Nov 1, 2008 | Cross-site scripting (XSS) vulnerability in My Little Forum 1.75 and 2.0 Beta 23 allows remote attackers to inject arbit... |
| CVE-2008-4870 | — | — | 0.4% | Nov 1, 2008 | dovecot 1.0.7 in Red Hat Enterprise Linux (RHEL) 5, and possibly Fedora, uses world-readable permissions for dovecot.con... |
| CVE-2008-4869 | — | — | 2.3% | Nov 1, 2008 | FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to cause a denial of service (memory consumption) v... |
| CVE-2008-4868 | — | — | 2.3% | Nov 1, 2008 | Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by ... |
| CVE-2008-4867 | — | — | 2.4% | Nov 1, 2008 | Buffer overflow in libavcodec/dca.c in FFmpeg 0.4.9 before r14917, as used by MPlayer, allows context-dependent attacker... |
| CVE-2008-4866 | — | — | 4.7% | Nov 1, 2008 | Multiple buffer overflows in libavformat/utils.c in FFmpeg 0.4.9 before r14715, as used by MPlayer, allow context-depend... |
| CVE-2008-4865 | — | — | 0.4% | Nov 1, 2008 | Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Troj... |
| CVE-2008-4864 | — | — | 21.0% | Nov 1, 2008 | Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta... |
| CVE-2008-4863 | — | — | 0.4% | Nov 1, 2008 | Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a ... |
| CVE-2008-4811 | — | — | 1.6% | Oct 31, 2008 | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote atta... |
| CVE-2008-4810 | — | — | 2.2% | Oct 31, 2008 | The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers... |
| CVE-2008-4809 | — | — | 1.5% | Oct 31, 2008 | Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown... |
| CVE-2008-4808 | — | — | 1.0% | Oct 31, 2008 | IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the proven... |
| CVE-2008-4807 | — | — | 0.3% | Oct 31, 2008 | IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allo... |
| CVE-2008-4806 | — | — | 1.1% | Oct 31, 2008 | Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbit... |
| CVE-2008-4805 | — | — | 1.2% | Oct 31, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to ... |
| CVE-2008-4804 | — | — | 1.1% | Oct 31, 2008 | SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL comm... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now