2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-4334 | — | — | 2.3% | Sep 30, 2008 | PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in... |
| CVE-2008-4333 | — | — | 1.4% | Sep 30, 2008 | Cross-site scripting (XSS) vulnerability in PHP infoBoard V.7 Plus allows remote attackers to inject arbitrary web scrip... |
| CVE-2008-4332 | — | — | 2.0% | Sep 30, 2008 | SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers ... |
| CVE-2008-4331 | — | — | 2.3% | Sep 30, 2008 | Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke... |
| CVE-2008-4330 | — | — | 2.3% | Sep 30, 2008 | Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrar... |
| CVE-2008-4329 | — | — | 3.5% | Sep 30, 2008 | PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote a... |
| CVE-2008-4328 | — | — | 1.0% | Sep 30, 2008 | SQL injection vulnerability in site_search.php in EasyRealtorPRO 2008 allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-4094 | — | — | 3.0% | Sep 30, 2008 | Multiple SQL injection vulnerabilities in Ruby on Rails before 2.1.1 allow remote attackers to execute arbitrary SQL com... |
| CVE-2008-4327 | — | — | 15.7% | Sep 30, 2008 | gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attacke... |
| CVE-2008-4326 | — | — | 1.9% | Sep 30, 2008 | The PMA_escapeJsString function in libraries/js_escape.lib.php in phpMyAdmin before 2.11.9.2, when Internet Explorer is ... |
| CVE-2008-4325 | — | — | 1.4% | Sep 30, 2008 | lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTT... |
| CVE-2008-4324 | — | — | 8.9% | Sep 29, 2008 | The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial... |
| CVE-2008-4323 | — | — | 8.6% | Sep 29, 2008 | Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr... |
| CVE-2008-4322 | — | — | 64.8% | Sep 29, 2008 | Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att... |
| CVE-2008-4321 | — | — | 5.7% | Sep 29, 2008 | Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res... |
| CVE-2008-3827 | — | — | 10.9% | Sep 29, 2008 | Multiple integer underflows in the Real demuxer (demux_real.c) in MPlayer 1.0_rc2 and earlier allow remote attackers to ... |
| CVE-2008-4320 | — | — | 1.9% | Sep 29, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.5.94 allow remote attackers to inject arbitrary ... |
| CVE-2008-4319 | — | — | 2.3% | Sep 29, 2008 | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth... |
| CVE-2008-4318 | — | — | 14.0% | Sep 29, 2008 | Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query... |
| CVE-2008-4302 | MEDIUM | 5.5 | 0.6% | Sep 29, 2008 | fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to... |
| CVE-2008-4301 | — | — | 16.9% | Sep 29, 2008 | A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set ... |
| CVE-2008-4300 | — | — | 13.6% | Sep 29, 2008 | A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to caus... |
| CVE-2008-4299 | — | — | 15.9% | Sep 29, 2008 | A certain ActiveX control in the Microsoft Internet Authentication Service (IAS) Helper COM Component in iashlpr.dll all... |
| CVE-2008-4210 | — | — | 2.1% | Sep 29, 2008 | fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi... |
| CVE-2008-4192 | — | — | 0.7% | Sep 29, 2008 | The pserver_shutdown function in fence_egenera in cman 2.20080629 and 2.20080801 allows local users to overwrite arbitra... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now