2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4334PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in...
CVE-2008-4333Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web scrip...
CVE-2008-4332SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers ...
CVE-2008-4331Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke...
CVE-2008-4330Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrar...
CVE-2008-4329PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote a...
CVE-2008-4328SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL c...
CVE-2008-4094Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL com...
CVE-2008-4327gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attacke...
CVE-2008-4326The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is ...
CVE-2008-4325lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTT...
CVE-2008-4324The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial...
CVE-2008-4323Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr...
CVE-2008-4322Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att...
CVE-2008-4321Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res...
CVE-2008-3827Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to ...
CVE-2008-4320Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary ...
CVE-2008-4319fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth...
CVE-2008-4318Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query...
CVE-2008-4302MEDIUM5.5fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to...
CVE-2008-4301A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set ...
CVE-2008-4300A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to caus...
CVE-2008-4299A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll all...
CVE-2008-4210fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi...
CVE-2008-4192The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitra...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now