2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-3663——Squirrelmail 1.4.15 does not set the secure flag for the session cookie in an https session, which can cause the cookie ...
CVE-2008-3098——Cross-site scripting (XSS) vulnerability in admin/usercheck.php in fuzzylime (cms) before 3.03 allows remote attackers t...
CVE-2008-4201——Heap-based buffer overflow in the decodeMP4file function (frontend/main.c) in FAAD2 2.6.1 and earlier allows remote atta...
CVE-2008-4194——The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv...
CVE-2008-4193——Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t...
CVE-2008-4191——extract-table.pl in Emacspeak 26 and 28 allows local users to overwrite arbitrary files via a symlink attack on the extr...
CVE-2008-4190——The IPSEC livetest tool in Openswan 2.4.12 and earlier, and 2.6.x through 2.6.16, allows local users to overwrite arbitr...
CVE-2008-3102——Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https ses...
CVE-2008-4153——The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a nod...
CVE-2008-4152——Cross-site scripting (XSS) vulnerability in the Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drup...
CVE-2008-4151——Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (...
CVE-2008-4150——SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL...
CVE-2008-4149——Cross-site scripting (XSS) vulnerability in the Greg Holsclaw Link to Us module 5.x before 5.x-1.1 for Drupal allows rem...
CVE-2008-4148——SQL injection vulnerability in the Mailhandler module 5.x before 5.x-1.4 and 6.x before 6.x-1.4, a module for Drupal, al...
CVE-2008-4147——Cross-site scripting (XSS) vulnerability in the Mailsave module 5.x before 5.x-3.3 and 6.x before 6.x-1.3, a module for ...
CVE-2008-4146——Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field ...
CVE-2008-4145——SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled...
CVE-2008-4144——SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitra...
CVE-2008-4143——SQL injection vulnerability in category_search.php in RazorCommerce Shopping Cart allows remote attackers to execute arb...
CVE-2008-4142——SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th...
CVE-2008-4141——Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to ...
CVE-2008-4140——Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web ...
CVE-2008-4139——Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inje...
CVE-2008-4138——PHP remote file inclusion vulnerability in skin_shop/standard/3_plugin_twindow/twindow_notice.php in TECHNOTE 7 allows r...
CVE-2008-4137——PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now