2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-3234sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac...
CVE-2008-3233Cross-site scripting (XSS) vulnerability in WordPress before 2.6, SVN development versions only, allows remote attackers...
CVE-2008-3232Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated ...
CVE-2008-3231xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via a crafted OGG file, as demonstra...
CVE-2008-3230The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GI...
CVE-2008-3229Stack-based buffer overflow in op before Changeset 563, when xauth support is enabled, allows local users to gain privil...
CVE-2008-3228Joomla! before 1.5.4 does not configure .htaccess to apply certain security checks that "block common exploits" to SEF U...
CVE-2008-3227Unspecified vulnerability in Joomla! before 1.5.4 has unknown impact and attack vectors related to a "User Redirect Spam...
CVE-2008-3226The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vecto...
CVE-2008-3225Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vector...
CVE-2008-3224Unspecified vulnerability in phpBB before 3.0.1 has unknown impact and attack vectors related to "urls gone through redi...
CVE-2008-3223SQL injection vulnerability in the Schema API in Drupal 6.x before 6.3 allows remote attackers to execute arbitrary SQL ...
CVE-2008-3222Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the curr...
CVE-2008-3220Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to p...
CVE-2008-3219The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag i...
CVE-2008-3218Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary ...
CVE-2008-3217PowerDNS Recursor before 3.1.6 does not always use the strongest random number generator for source port selection, whic...
CVE-2008-3216The save function in br/prefmanager.d in projectl 1.001 creates a projectL.prf file in the current working directory, wh...
CVE-2008-3215libclamav/petite.c in ClamAV before 0.93.3 allows remote attackers to cause a denial of service via a malformed Petite f...
CVE-2008-3214dnsmasq 2.25 allows remote attackers to cause a denial of service (daemon crash) by (1) renewing a nonexistent lease or ...
CVE-2008-3207PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl...
CVE-2008-3206SQL injection vulnerability in browse.groups.php in Yuhhu Pubs Black Cat allows remote attackers to execute arbitrary SQ...
CVE-2008-3209Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remot...
CVE-2008-3212Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute ar...
CVE-2008-3211Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now