2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2008-2013SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc ...
CVE-2008-2012SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute ...
CVE-2008-2011Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows r...
CVE-2008-2010Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute a...
CVE-2008-1737Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cau...
CVE-2008-2008Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote at...
CVE-2008-1293ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which ...
CVE-2008-1997Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 all...
CVE-2008-1998The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allow...
CVE-2008-1999Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userin...
CVE-2008-2003BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which ...
CVE-2008-2002Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH...
CVE-2008-1103Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issue...
CVE-2008-2001Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that ...
CVE-2008-1930The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPI...
CVE-2008-2000Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash)...
CVE-2008-1996licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash...
CVE-2008-1671start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service an...
CVE-2008-1670Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0....
CVE-2008-1995Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can...
CVE-2008-1988Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows ...
CVE-2008-1990Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via...
CVE-2008-1989PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g...
CVE-2008-1993Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary...
CVE-2008-1991Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inje...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now