2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-3178 | — | — | 5.1% | Jul 15, 2008 | Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute... |
| CVE-2008-3181 | — | — | 3.1% | Jul 15, 2008 | Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execut... |
| CVE-2008-3184 | — | — | 1.5% | Jul 15, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in vBulletin 3.6.10 PL2 and earlier, and 3.7.2 and earlier 3.7.x ver... |
| CVE-2008-3167 | — | — | 6.5% | Jul 14, 2008 | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo... |
| CVE-2008-3163 | — | — | 1.9% | Jul 14, 2008 | Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbit... |
| CVE-2008-3169 | — | — | 4.8% | Jul 14, 2008 | Multiple heap-based buffer overflows in Empire Server before 4.3.15 allow remote attackers to cause a denial of service ... |
| CVE-2008-3165 | — | — | 2.3% | Jul 14, 2008 | Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al... |
| CVE-2008-3173 | — | — | 11.3% | Jul 14, 2008 | Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot... |
| CVE-2008-3172 | — | — | 1.2% | Jul 14, 2008 | Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, whi... |
| CVE-2008-3164 | — | — | 3.8% | Jul 14, 2008 | Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote ... |
| CVE-2008-3166 | — | — | 6.2% | Jul 14, 2008 | PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals i... |
| CVE-2008-3168 | — | — | 1.0% | Jul 14, 2008 | The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers ... |
| CVE-2008-3162 | — | — | 9.3% | Jul 14, 2008 | Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remot... |
| CVE-2008-3171 | — | — | 1.2% | Jul 14, 2008 | Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to ... |
| CVE-2008-3170 | — | — | 2.1% | Jul 14, 2008 | Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which cou... |
| CVE-2008-3160 | — | — | 2.1% | Jul 14, 2008 | Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer an... |
| CVE-2008-1589 | — | — | 1.2% | Jul 14, 2008 | Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for v... |
| CVE-2008-1590 | — | — | 2.8% | Jul 14, 2008 | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage ... |
| CVE-2008-2303 | — | — | 13.0% | Jul 14, 2008 | Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execu... |
| CVE-2008-2304 | — | — | 5.7% | Jul 14, 2008 | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use... |
| CVE-2008-2317 | — | — | 7.7% | Jul 14, 2008 | WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remot... |
| CVE-2008-2318 | — | — | 1.5% | Jul 14, 2008 | The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-... |
| CVE-2008-3159 | — | — | 8.7% | Jul 14, 2008 | Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ... |
| CVE-2008-3161 | — | — | 1.2% | Jul 14, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remot... |
| CVE-2008-1588 | — | — | 2.3% | Jul 14, 2008 | Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now