2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-4166Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a d...
CVE-2008-4165admin/user/create_user.php in Kolab Groupware Server 1.0.0 places a user password in an HTTP GET request, which allows l...
CVE-2008-4159SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitra...
CVE-2008-4158Multiple directory traversal vulnerabilities in index.php in Zanfi CMS lite 1.2 allow remote attackers to include and ex...
CVE-2008-4157SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL c...
CVE-2008-4156SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow...
CVE-2008-4155Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire...
CVE-2008-4154SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the...
CVE-2008-4135Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause...
CVE-2008-4134PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other ver...
CVE-2008-4133The web proxy service on the D-Link DIR-100 with firmware 1.12 and earlier does not properly filter web requests with la...
CVE-2008-4132Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.2...
CVE-2008-4131Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors relate...
CVE-2008-4130Cross-site scripting (XSS) vulnerability in Gallery 2.x before 2.2.6 allows remote attackers to inject arbitrary web scr...
CVE-2008-4129Gallery before 1.5.9, and 2.x before 2.2.6, does not properly handle ZIP archives containing symbolic links, which allow...
CVE-2008-4128MEDIUM4.3Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the...
CVE-2008-3662Gallery before 1.5.9, and 2.x before 2.2.6, does not set the secure flag for the session cookie in an https session, whi...
CVE-2008-2470The InstallShield Update Service Agent ActiveX control in isusweb.dll allows remote attackers to cause a denial of servi...
CVE-2008-4127Mshtml.dll in Microsoft Internet Explorer 7 Gold 7.0.5730 and 8 Beta 8.0.6001 on Windows XP SP2 allows remote attackers ...
CVE-2008-4126PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not...
CVE-2008-4125The search function in phpBB 2.x provides a search_id value that leaks the state of PHP's PRNG, which allows remote atta...
CVE-2008-4108Tools/faqwiz/move-faqwiz.sh (aka the generic FAQ wizard moving tool) in Python 2.4.5 might allow local users to overwrit...
CVE-2008-4107The (1) rand and (2) mt_rand functions in PHP 5.2.6 do not produce cryptographically strong random numbers, which allows...
CVE-2008-4106WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maxim...
CVE-2008-4105JRequest in Joomla! 1.5 before 1.5.7 does not sanitize variables that were set with JRequest::setVar, which allows remot...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now