2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-4126 | — | — | 2.2% | Sep 18, 2008 | PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not... |
| CVE-2008-4125 | — | — | 1.6% | Sep 18, 2008 | The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote atta... |
| CVE-2008-4108 | — | — | 0.4% | Sep 18, 2008 | Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrit... |
| CVE-2008-4107 | — | — | 3.0% | Sep 18, 2008 | The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows... |
| CVE-2008-4106 | — | — | 5.5% | Sep 18, 2008 | WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maxim... |
| CVE-2008-4105 | — | — | 1.7% | Sep 18, 2008 | JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remot... |
| CVE-2008-4104 | — | — | 1.4% | Sep 18, 2008 | Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary... |
| CVE-2008-4103 | — | — | 1.5% | Sep 18, 2008 | The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, whic... |
| CVE-2008-4102 | — | — | 2.4% | Sep 18, 2008 | Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseud... |
| CVE-2008-4101 | — | — | 9.2% | Sep 18, 2008 | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) exec... |
| CVE-2008-4100 | — | — | 1.5% | Sep 18, 2008 | GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier... |
| CVE-2008-4099 | — | — | 2.3% | Sep 18, 2008 | PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS re... |
| CVE-2008-4118 | — | — | 1.1% | Sep 18, 2008 | Cross-site scripting (XSS) vulnerability in High Norm Sound Master 2nd 1.0 allows remote attackers to inject arbitrary w... |
| CVE-2008-4117 | — | — | 1.9% | Sep 18, 2008 | Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote a... |
| CVE-2008-4116 | — | — | 11.6% | Sep 18, 2008 | Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr... |
| CVE-2008-4109 | — | — | 28.6% | Sep 18, 2008 | A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributi... |
| CVE-2008-4098 | — | — | 1.6% | Sep 18, 2008 | MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with... |
| CVE-2008-4097 | — | — | 1.9% | Sep 18, 2008 | MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modif... |
| CVE-2008-4096 | — | — | 11.2% | Sep 18, 2008 | libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrar... |
| CVE-2008-3961 | — | — | 5.2% | Sep 18, 2008 | Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbi... |
| CVE-2008-3195 | — | — | 8.3% | Sep 18, 2008 | Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide ... |
| CVE-2008-2468 | — | — | 9.9% | Sep 18, 2008 | Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and S... |
| CVE-2008-1093 | — | — | 1.6% | Sep 18, 2008 | Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp ... |
| CVE-2008-4115 | — | — | 2.6% | Sep 16, 2008 | TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi... |
| CVE-2008-4114 | — | — | 49.3% | Sep 16, 2008 | srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now