2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-3844 | — | — | 2.7% | Aug 27, 2008 | Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Ha... |
| CVE-2008-3843 | — | — | 22.0% | Aug 27, 2008 | Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework with the MS07-040 update doe... |
| CVE-2008-3842 | — | — | 20.4% | Aug 27, 2008 | Request Validation (aka the ValidateRequest filters) in ASP.NET in Microsoft .NET Framework without the MS07-040 update ... |
| CVE-2008-3841 | — | — | 1.7% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in admin/search_links.php in Freeway eCommerce 1.4.1.171 allows remote attacker... |
| CVE-2008-3840 | — | — | 1.2% | Aug 27, 2008 | Crafty Syntax Live Help (CSLH) 2.14.6 and earlier stores passwords in cleartext in a MySQL database, which allows contex... |
| CVE-2008-3839 | — | — | 0.3% | Aug 27, 2008 | Unspecified vulnerability in the NFS module in the kernel in Sun Solaris 10 and OpenSolaris snv_59 through snv_87, when ... |
| CVE-2008-3838 | — | — | 0.4% | Aug 27, 2008 | Unspecified vulnerability in the NFS Remote Procedure Calls (RPC) zones implementation in Sun Solaris 10 and OpenSolaris... |
| CVE-2008-3790 | — | — | 15.2% | Aug 27, 2008 | The REXML module in Ruby 1.8.6 through 1.8.6-p287, 1.8.7 through 1.8.7-p72, and 1.9 allows context-dependent attackers t... |
| CVE-2008-3789 | — | — | 0.5% | Aug 27, 2008 | Samba 3.2.0 uses weak permissions (0666) for the (1) group_mapping.tdb and (2) group_mapping.ldb files, which allows loc... |
| CVE-2008-3736 | — | — | 0.6% | Aug 27, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and ... |
| CVE-2008-3737 | — | — | 2.7% | Aug 27, 2008 | Unspecified vulnerability in (1) System Consultants La!Cooda WIZ 1.4.0 and earlier and (2) SpaceTag LacoodaST 2.1.3 and ... |
| CVE-2008-2327 | — | — | 4.1% | Aug 27, 2008 | Multiple buffer underflows in the (1) LZWDecode, (2) LZWDecodeCompat, and (3) LZWDecodeVector functions in tif_lzw.c in ... |
| CVE-2008-3740 | — | — | 1.6% | Aug 27, 2008 | Cross-site scripting (XSS) vulnerability in the output filter in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote... |
| CVE-2008-3746 | — | — | 2.3% | Aug 27, 2008 | neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via v... |
| CVE-2008-3795 | — | — | 15.1% | Aug 27, 2008 | Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message r... |
| CVE-2008-3796 | — | — | 2.2% | Aug 27, 2008 | Swfdec 0.6 before 0.6.8 allows remote attackers to cause a denial of service (application crash) via a 1x1 JPEG image. |
| CVE-2008-3747 | — | — | 2.5% | Aug 27, 2008 | The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before ... |
| CVE-2008-3745 | — | — | 1.4% | Aug 27, 2008 | The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download u... |
| CVE-2008-3744 | — | — | 0.9% | Aug 27, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities in Drupal 5.x before 5.10 and 6.x before 6.4 allow remote att... |
| CVE-2008-3743 | — | — | 0.8% | Aug 27, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities in forms in Drupal 6.x before 6.4 allow remote attackers to p... |
| CVE-2008-3742 | — | — | 2.5% | Aug 27, 2008 | Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote ... |
| CVE-2008-3741 | — | — | 1.2% | Aug 27, 2008 | The private filesystem in Drupal 5.x before 5.10 and 6.x before 6.4 trusts the MIME type sent by a web browser, which al... |
| CVE-2008-3794 | — | — | 11.0% | Aug 26, 2008 | Integer signedness error in the mms_ReceiveCommand function in modules/access/mms/mmstu.c in VLC Media Player 0.8.6i all... |
| CVE-2008-3781 | — | — | 1.1% | Aug 26, 2008 | Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web scr... |
| CVE-2008-3780 | — | — | 1.0% | Aug 26, 2008 | SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now