2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-3480 | — | — | 11.2% | Aug 29, 2008 | Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Pri... |
| CVE-2008-3873 | — | — | 3.7% | Aug 29, 2008 | The System.setClipboard method in ActionScript in Adobe Flash Player 9.0.124.0 and earlier allows remote attackers to po... |
| CVE-2008-3874 | — | — | 1.1% | Aug 29, 2008 | Cross-site scripting (XSS) vulnerability in account.php in Lussumo Vanilla 1.1.5-rc1, 1.1.4, and earlier allows remote a... |
| CVE-2008-3860 | — | — | 1.3% | Aug 29, 2008 | Multiple cross-site scripting (XSS) vulnerabilities (1) in the WYSIWYG editors, (2) during local group creation, (3) dur... |
| CVE-2008-3859 | — | — | 2.6% | Aug 29, 2008 | Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire... |
| CVE-2008-3861 | — | — | 1.0% | Aug 29, 2008 | Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrar... |
| CVE-2008-3855 | — | — | 0.4% | Aug 28, 2008 | Unspecified vulnerability in the DB2 Administration Server (DAS) in the Core DAS function component in IBM DB2 9.1 befor... |
| CVE-2008-3852 | — | — | 3.4% | Aug 28, 2008 | Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visu... |
| CVE-2008-3858 | — | — | 1.9% | Aug 28, 2008 | The Downlevel DB2RA Support component in IBM DB2 9.1 before Fixpak 4a allows remote attackers to cause a denial of servi... |
| CVE-2008-3856 | — | — | 2.4% | Aug 28, 2008 | The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does... |
| CVE-2008-3854 | — | — | 3.7% | Aug 28, 2008 | Multiple stack-based buffer overflows in IBM DB2 9.1 before Fixpak 5 and 9.5 before Fixpak 1 allow remote attackers to c... |
| CVE-2008-3857 | — | — | 0.3% | Aug 28, 2008 | The Base Service Utilities component in IBM DB2 9.1 before Fixpak 5 retains a cleartext password in memory after the dat... |
| CVE-2008-3853 | — | — | 5.8% | Aug 28, 2008 | Buffer overflow in the DAS server program in the Core DAS function component in IBM DB2 9.1 before FP4a and 9.5 before F... |
| CVE-2008-3850 | — | — | 1.5% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in Accellion File Transfer FTA_7_0_135 allows remote attackers to inject arbitr... |
| CVE-2008-3848 | — | — | 1.0% | Aug 27, 2008 | SQL injection vulnerability in single.php in Z-Breaknews 2.0 allows remote attackers to execute arbitrary SQL commands v... |
| CVE-2008-3847 | — | — | 1.0% | Aug 27, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in AN Guestbook (ANG) before 0.7.6 allow remote attackers to inject ... |
| CVE-2008-3845 | — | — | 1.8% | Aug 27, 2008 | Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to ex... |
| CVE-2008-3846 | — | — | 1.1% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in mysql-lists 1.2 and earlier allows remote attackers to inject arbitrary web ... |
| CVE-2008-3851 | — | — | 7.9% | Aug 27, 2008 | Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute... |
| CVE-2008-3849 | — | — | 1.1% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in the calendar controller in Civic Website Manager before 1.0.1 allows remote ... |
| CVE-2008-3739 | — | — | 1.5% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag Lacoo... |
| CVE-2008-2433 | CRITICAL | 9.8 | 10.9% | Aug 27, 2008 | The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Serve... |
| CVE-2008-3738 | CRITICAL | 9.1 | 1.3% | Aug 27, 2008 | Session fixation vulnerability in SpaceTag LacoodaST 2.1.3 and earlier allows remote attackers to hijack web sessions vi... |
| CVE-2008-3526 | — | — | 3.5% | Aug 27, 2008 | Integer overflow in the sctp_setsockopt_auth_key function in net/sctp/socket.c in the Stream Control Transmission Protoc... |
| CVE-2008-3281 | MEDIUM | 6.5 | 2.5% | Aug 27, 2008 | libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allow... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now