2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-4126——PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not...
CVE-2008-4125——The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote atta...
CVE-2008-4108——Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrit...
CVE-2008-4107——The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows...
CVE-2008-4106——WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maxim...
CVE-2008-4105——JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remot...
CVE-2008-4104——Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary...
CVE-2008-4103——The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, whic...
CVE-2008-4102——Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseud...
CVE-2008-4101——Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) exec...
CVE-2008-4100——GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier...
CVE-2008-4099——PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS re...
CVE-2008-4118——Cross-site scripting (XSS) vulnerability in High Norm Sound Master 2nd 1.0 allows remote attackers to inject arbitrary w...
CVE-2008-4117——Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote a...
CVE-2008-4116——Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr...
CVE-2008-4109——A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributi...
CVE-2008-4098——MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with...
CVE-2008-4097——MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modif...
CVE-2008-4096——libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrar...
CVE-2008-3961——Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbi...
CVE-2008-3195——Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide ...
CVE-2008-2468——Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and S...
CVE-2008-1093——Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp ...
CVE-2008-4115——TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi...
CVE-2008-4114——srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now