2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-3827——Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to ...
CVE-2008-4320——Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary ...
CVE-2008-4319——fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth...
CVE-2008-4318——Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query...
CVE-2008-4301——A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set ...
CVE-2008-4300——A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to caus...
CVE-2008-4299——A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll all...
CVE-2008-4210——fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi...
CVE-2008-4192——The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitra...
CVE-2008-4120——Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web sc...
CVE-2008-3524——rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary f...
CVE-2008-2474——Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attacke...
CVE-2008-4298——Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a...
CVE-2008-4297——Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows r...
CVE-2008-4296——The Cisco Linksys WRT350N with firmware 1.0.3.7 has "admin" as its default password for the "admin" account, which makes...
CVE-2008-4295——Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta...
CVE-2008-4294——IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically prox...
CVE-2008-4293——Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attacker...
CVE-2008-4292——Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown im...
CVE-2008-4200——Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows r...
CVE-2008-4199——Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow...
CVE-2008-4198——Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and o...
CVE-2008-4196——Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbitrary web script or ...
CVE-2008-4195——Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a di...
CVE-2008-4119——Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk 11.2 and CMDB 11.0 through 11.2 allow remote atta...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now