2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4428Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier ...
CVE-2008-4427changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au...
CVE-2008-4426Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem...
CVE-2008-4425Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att...
CVE-2008-4424Cross-site scripting (XSS) vulnerability in index.php in Domain Group Network GooCMS 1.02 allows remote attackers to inj...
CVE-2008-4423SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands vi...
CVE-2008-4383Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS...
CVE-2008-4410The vmi_write_ldt_entry function in arch/x86/kernel/vmi_32.c in the Virtual Machine Interface (VMI) in the Linux kernel ...
CVE-2008-4409libxml2 2.7.0 and 2.7.1 does not properly handle "predefined entities definitions" in entities, which allows context-dep...
CVE-2008-4408Cross-site scripting (XSS) vulnerability in MediaWiki 1.13.1, 1.12.0, and possibly other versions before 1.13.2 allows r...
CVE-2008-4407XRunSabre in sabre (aka xsabre) 0.2.4b relies on the ability to create /tmp/sabre.log, which allows local users to cause...
CVE-2008-4406A certain Debian patch to the run scripts for sabre (aka xsabre) 0.2.4b allows local users to delete or overwrite arbitr...
CVE-2008-4405xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not proper...
CVE-2008-4360mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sen...
CVE-2008-4359lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings befo...
CVE-2008-3833The generic_file_splice_write function in fs/splice.c in the Linux kernel before 2.6.19 does not properly strip setuid a...
CVE-2008-3832A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-...
CVE-2008-4404The IPv6 Neighbor Discovery Protocol (NDP) implementation on IBM zSeries servers does not validate the origin of Neighbo...
CVE-2008-4403The CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 Patch 1 before build 3087 ...
CVE-2008-4402Multiple buffer overflows in CGI modules in the server in Trend Micro OfficeScan 8.0 SP1 before build 2439 and 8.0 SP1 P...
CVE-2008-3825pam_krb5 2.2.14 in Red Hat Enterprise Linux (RHEL) 5 and earlier, when the existing_ticket option is enabled, uses incor...
CVE-2008-2476The IPv6 Neighbor Discovery Protocol (NDP) implementation in (1) FreeBSD 6.3 through 7.1, (2) OpenBSD 4.2 and 4.3, (3) N...
CVE-2008-2439Directory traversal vulnerability in the UpdateAgent function in TmListen.exe in the OfficeScanNT Listener service in th...
CVE-2008-2236Cross-site scripting (XSS) vulnerability in blosxom.cgi in Blosxom before 2.1.2 allows remote attackers to inject arbitr...
CVE-2008-4396Stack-based buffer overflow in Safer Networking FileAlyzer 1.6.0.0 and 1.6.0.4 beta, and possibly other versions, allows...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now