2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4863——Untrusted search path vulnerability in BPY_interface in Blender 2.46 allows local users to execute arbitrary code via a ...
CVE-2008-4309HIGH7.5Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 ...
CVE-2008-4811——The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote atta...
CVE-2008-4810——The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 before r2797 allows remote attackers...
CVE-2008-4809——Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown...
CVE-2008-4808——IBM Lotus Connections 2.x before 2.0.1 allows attackers to discover passwords via unspecified vectors. NOTE: the proven...
CVE-2008-4807——IBM Lotus Connections 2.x before 2.0.1 stores the password for the administrative user in the trace.log file, which allo...
CVE-2008-4806——Multiple SQL injection vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to execute arbit...
CVE-2008-4805——Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.x before 2.0.1 allow remote attackers to ...
CVE-2008-4804——SQL injection vulnerability in the Gallery module 1.3 for PHP-Nuke allows remote attackers to execute arbitrary SQL comm...
CVE-2008-4803——Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote atta...
CVE-2008-4802——Cross-site scripting (XSS) vulnerability in complete.php in Simple PHP Scripts blog 0.3 allows remote attackers to injec...
CVE-2008-4801——Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CA...
CVE-2008-4800——The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attack...
CVE-2008-4799——pamperspective in Netpbm before 10.35.48 does not properly calculate a window height, which allows context-dependent att...
CVE-2008-4798——The loadModule function in lib/WebGUI/Asset.pm in WebGUI before 7.5.30 (stable) allows remote attackers to execute arbit...
CVE-2008-4797——Directory traversal vulnerability in Arihiro Kurata Kantan WEB Server 1.8 and earlier allows remote attackers to read ar...
CVE-2008-4796——The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-sno...
CVE-2008-4795——The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which a...
CVE-2008-4794——Opera before 9.62 allows remote attackers to execute arbitrary commands via the History Search results page, a different...
CVE-2008-2238——Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via...
CVE-2008-2237——Heap-based buffer overflow in OpenOffice.org (OOo) 2.x before 2.4.2 allows remote attackers to execute arbitrary code vi...
CVE-2008-4793——The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified oth...
CVE-2008-4792——The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fiel...
CVE-2008-4791——The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended l...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now