2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-3168The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers ...
CVE-2008-3173Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot...
CVE-2008-3172Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, whi...
CVE-2008-3162Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remot...
CVE-2008-3163Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbit...
CVE-2008-3164Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote ...
CVE-2008-3171Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to ...
CVE-2008-3170Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which cou...
CVE-2008-2303Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execu...
CVE-2008-1809Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attacke...
CVE-2008-2318The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-...
CVE-2008-1590JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage ...
CVE-2008-1589Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for v...
CVE-2008-2317WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remot...
CVE-2008-2304Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use...
CVE-2008-3159Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ...
CVE-2008-3160Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer an...
CVE-2008-3161Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remot...
CVE-2008-1588Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode...
CVE-2008-3157Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows a...
CVE-2008-3156The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and...
CVE-2008-3155Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac...
CVE-2008-3154SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi...
CVE-2008-3153SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwar...
CVE-2008-3152SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now