2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-4120 | — | — | 1.8% | Sep 29, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in FlatPress 0.804 allow remote attackers to inject arbitrary web sc... |
| CVE-2008-3524 | — | — | 0.3% | Sep 29, 2008 | rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary f... |
| CVE-2008-2474 | — | — | 7.8% | Sep 29, 2008 | Buffer overflow in x87 before 3.5.5 in ABB Process Communication Unit 400 (PCU400) 4.4 through 4.6 allows remote attacke... |
| CVE-2008-4298 | — | — | 3.5% | Sep 27, 2008 | Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a... |
| CVE-2008-4297 | — | — | 2.7% | Sep 27, 2008 | Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows r... |
| CVE-2008-4296 | — | — | 2.1% | Sep 27, 2008 | The Cisco Linksys WRT350N with firmware 1.0.3.7 has "admin" as its default password for the "admin" account, which makes... |
| CVE-2008-4295 | — | — | 30.1% | Sep 27, 2008 | Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta... |
| CVE-2008-4294 | — | — | 0.4% | Sep 27, 2008 | IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically prox... |
| CVE-2008-4293 | — | — | 4.5% | Sep 27, 2008 | Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attacker... |
| CVE-2008-4292 | — | — | 1.9% | Sep 27, 2008 | Opera before 9.52 does not check the CRL override upon encountering a certificate that lacks a CRL, which has unknown im... |
| CVE-2008-4200 | — | — | 3.2% | Sep 27, 2008 | Opera before 9.52 does not ensure that the address field of a news feed represents the feed's actual URL, which allows r... |
| CVE-2008-4199 | — | — | 2.9% | Sep 27, 2008 | Opera before 9.52 does not prevent use of links from web pages to feed source files on the local disk, which might allow... |
| CVE-2008-4198 | — | — | 2.8% | Sep 27, 2008 | Opera before 9.52, when rendering an http page that has loaded an https page into a frame, displays a padlock icon and o... |
| CVE-2008-4197 | HIGH | 8.8 | 6.3% | Sep 27, 2008 | Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produc... |
| CVE-2008-4196 | — | — | 1.7% | Sep 27, 2008 | Cross-site scripting (XSS) vulnerability in Opera before 9.52 allows remote attackers to inject arbitrary web script or ... |
| CVE-2008-4195 | — | — | 2.0% | Sep 27, 2008 | Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a di... |
| CVE-2008-4119 | — | — | 1.9% | Sep 27, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in CA Service Desk 11.2 and CMDB 11.0 through 11.2 allow remote atta... |
| CVE-2008-4070 | — | — | 7.4% | Sep 27, 2008 | Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to... |
| CVE-2008-3528 | — | — | 0.5% | Sep 27, 2008 | The error-reporting functionality in (1) fs/ext2/dir.c, (2) fs/ext3/dir.c, and possibly (3) fs/ext4/dir.c in the Linux k... |
| CVE-2008-3813 | — | — | 3.1% | Sep 26, 2008 | Unspecified vulnerability in Cisco IOS 12.2 and 12.4, when the L2TP mgmt daemon process is enabled, allows remote attack... |
| CVE-2008-3812 | — | — | 2.8% | Sep 26, 2008 | Cisco IOS 12.4, when IOS firewall Application Inspection Control (AIC) with HTTP Deep Packet Inspection is enabled, allo... |
| CVE-2008-3811 | — | — | 2.0% | Sep 26, 2008 | Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote at... |
| CVE-2008-3810 | — | — | 1.9% | Sep 26, 2008 | Cisco IOS 12.2 and 12.4, when NAT Skinny Call Control Protocol (SCCP) Fragmentation Support is enabled, allows remote at... |
| CVE-2008-3809 | — | — | 2.8% | Sep 26, 2008 | Cisco IOS 12.0 through 12.4 on Gigabit Switch Router (GSR) devices (aka 12000 Series routers) allows remote attackers to... |
| CVE-2008-3808 | — | — | 3.4% | Sep 26, 2008 | Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows remote attackers to cause a denial of service (device re... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now