2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-4126PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not...
CVE-2008-4125The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote atta...
CVE-2008-4108Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrit...
CVE-2008-4107The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows...
CVE-2008-4106WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maxim...
CVE-2008-4105JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remot...
CVE-2008-4104Multiple open redirect vulnerabilities in Joomla! 1.5 before 1.5.7 allow remote attackers to redirect users to arbitrary...
CVE-2008-4103The mailto (aka com_mailto) component in Joomla! 1.5 before 1.5.7 sends e-mail messages without validating the URL, whic...
CVE-2008-4102Joomla! 1.5 before 1.5.7 initializes PHP's PRNG with a weak seed, which makes it easier for attackers to guess the pseud...
CVE-2008-4101Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) exec...
CVE-2008-4100GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier...
CVE-2008-4099PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS re...
CVE-2008-4118Cross-site scripting (XSS) vulnerability in High Norm Sound Master 2nd 1.0 allows remote attackers to inject arbitrary w...
CVE-2008-4117Unspecified vulnerability in a web page in the PRM module in Sun Management Center (SunMC) 3.6.1 and 4.0 allows remote a...
CVE-2008-4116Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr...
CVE-2008-4109A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributi...
CVE-2008-4098MySQL before 5.0.67 allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with...
CVE-2008-4097MySQL 5.0.51a allows local users to bypass certain privilege checks by calling CREATE TABLE on a MyISAM table with modif...
CVE-2008-4096libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrar...
CVE-2008-3961Multiple unspecified vulnerabilities in Adobe Illustrator CS2 on Macintosh allow user-assisted attackers to execute arbi...
CVE-2008-3195Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide ...
CVE-2008-2468Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and S...
CVE-2008-1093Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp ...
CVE-2008-4115TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi...
CVE-2008-4114srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now