2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-3827Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to ...
CVE-2008-4320Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary ...
CVE-2008-4319fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth...
CVE-2008-4318Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query...
CVE-2008-4301A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set ...
CVE-2008-4300A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to caus...
CVE-2008-4299A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll all...
CVE-2008-4210fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi...
CVE-2008-4192The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitra...
CVE-2008-4120Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web sc...
CVE-2008-3524rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary f...
CVE-2008-2474Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attacke...
CVE-2008-4298Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a...
CVE-2008-4297Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows r...
CVE-2008-4296The Cisco Linksys WRT350N with firmware 1.0.3.7 has "admin" as its default password for the "admin" account, which makes...
CVE-2008-4295Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta...
CVE-2008-4294IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically prox...
CVE-2008-4293Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attacker...
CVE-2008-4292Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown im...
CVE-2008-4200Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows r...
CVE-2008-4199Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow...
CVE-2008-4198Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and o...
CVE-2008-4196Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbitrary web script or ...
CVE-2008-4195Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a di...
CVE-2008-4119Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk 11.2 and CMDB 11.0 through 11.2 allow remote atta...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now