2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-3168 | — | — | 1.0% | Jul 14, 2008 | The files utility in Empire Server before 4.3.15 discloses the world creation time, which makes it easier for attackers ... |
| CVE-2008-3173 | — | — | 11.3% | Jul 14, 2008 | Microsoft Internet Explorer allows web sites to set cookies for domains that have a public suffix with more than one dot... |
| CVE-2008-3172 | — | — | 1.2% | Jul 14, 2008 | Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, whi... |
| CVE-2008-3162 | — | — | 9.3% | Jul 14, 2008 | Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remot... |
| CVE-2008-3163 | — | — | 1.9% | Jul 14, 2008 | Directory traversal vulnerability in dodosmail.php in DodosMail 2.5 allows remote attackers to include and execute arbit... |
| CVE-2008-3164 | — | — | 3.8% | Jul 14, 2008 | Directory traversal vulnerability in blog.php in fuzzylime (cms) 3.01, when magic_quotes_gpc is disabled, allows remote ... |
| CVE-2008-3171 | — | — | 1.2% | Jul 14, 2008 | Apple Safari sends Referer headers containing https URLs to different https web sites, which allows remote attackers to ... |
| CVE-2008-3170 | — | — | 2.1% | Jul 14, 2008 | Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which cou... |
| CVE-2008-2303 | — | — | 13.0% | Jul 14, 2008 | Integer signedness error in Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to execu... |
| CVE-2008-1809 | — | — | 5.7% | Jul 14, 2008 | Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attacke... |
| CVE-2008-2318 | — | — | 1.5% | Jul 14, 2008 | The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-... |
| CVE-2008-1590 | — | — | 2.8% | Jul 14, 2008 | JavaScriptCore in WebKit on Apple iPhone before 2.0 and iPod touch before 2.0 does not properly perform runtime garbage ... |
| CVE-2008-1589 | — | — | 1.2% | Jul 14, 2008 | Safari on Apple iPhone before 2.0 and iPod touch before 2.0 misinterprets a menu button press as user confirmation for v... |
| CVE-2008-2317 | — | — | 7.7% | Jul 14, 2008 | WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remot... |
| CVE-2008-2304 | — | — | 5.7% | Jul 14, 2008 | Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use... |
| CVE-2008-3159 | — | — | 8.7% | Jul 14, 2008 | Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ... |
| CVE-2008-3160 | — | — | 2.1% | Jul 14, 2008 | Multiple unspecified vulnerabilities in IBM Data ONTAP 7.1 before 7.1.3, as used by IBM System Storage N series Filer an... |
| CVE-2008-3161 | — | — | 1.2% | Jul 14, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in jsp/common/system/debug.jsp in IBM Maximo 4.1 and 5.2 allow remot... |
| CVE-2008-1588 | — | — | 2.3% | Jul 14, 2008 | Safari on Apple iPhone before 2.0 and iPod touch before 2.0 allows remote attackers to spoof the address bar via Unicode... |
| CVE-2008-3157 | — | — | 1.4% | Jul 11, 2008 | Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows a... |
| CVE-2008-3156 | — | — | 4.1% | Jul 11, 2008 | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and... |
| CVE-2008-3155 | — | — | 7.7% | Jul 11, 2008 | Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac... |
| CVE-2008-3154 | — | — | 1.0% | Jul 11, 2008 | SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi... |
| CVE-2008-3153 | — | — | 1.0% | Jul 11, 2008 | SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwar... |
| CVE-2008-3152 | — | — | 1.1% | Jul 11, 2008 | SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now