2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-2013 | — | — | 1.0% | Apr 30, 2008 | SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc ... |
| CVE-2008-2012 | — | — | 1.1% | Apr 30, 2008 | SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute ... |
| CVE-2008-2011 | — | — | 1.4% | Apr 30, 2008 | Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows r... |
| CVE-2008-2010 | — | — | 3.4% | Apr 30, 2008 | Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute a... |
| CVE-2008-1737 | — | — | 0.6% | Apr 30, 2008 | Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cau... |
| CVE-2008-2008 | — | — | 4.1% | Apr 29, 2008 | Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote at... |
| CVE-2008-1293 | — | — | 1.2% | Apr 29, 2008 | ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which ... |
| CVE-2008-1997 | — | — | 4.4% | Apr 28, 2008 | Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 all... |
| CVE-2008-1998 | — | — | 2.5% | Apr 28, 2008 | The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allow... |
| CVE-2008-1999 | — | — | 1.4% | Apr 28, 2008 | Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userin... |
| CVE-2008-2003 | — | — | 2.8% | Apr 28, 2008 | BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which ... |
| CVE-2008-2002 | — | — | 1.5% | Apr 28, 2008 | Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH... |
| CVE-2008-1103 | — | — | 0.3% | Apr 28, 2008 | Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issue... |
| CVE-2008-2001 | — | — | 1.9% | Apr 28, 2008 | Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that ... |
| CVE-2008-1930 | — | — | 5.0% | Apr 28, 2008 | The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPI... |
| CVE-2008-2000 | — | — | 1.3% | Apr 28, 2008 | Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash)... |
| CVE-2008-1996 | — | — | 11.2% | Apr 28, 2008 | licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash... |
| CVE-2008-1671 | — | — | 0.6% | Apr 28, 2008 | start_kdeinit in KDE 3.5.5 through 3.5.9, when installed setuid root, allows local users to cause a denial of service an... |
| CVE-2008-1670 | — | — | 4.8% | Apr 28, 2008 | Heap-based buffer overflow in the progressive PNG Image loader (decoders/pngloader.cpp) in KHTML in KDE 4.0.x up to 4.0.... |
| CVE-2008-1995 | — | — | 2.2% | Apr 28, 2008 | Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can... |
| CVE-2008-1988 | — | — | 2.6% | Apr 27, 2008 | Unrestricted file upload vulnerability in the file_upload function in core/misc.class.php in EncapsGallery 2.0.2 allows ... |
| CVE-2008-1990 | — | — | 1.2% | Apr 27, 2008 | Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via... |
| CVE-2008-1989 | — | — | 3.6% | Apr 27, 2008 | PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g... |
| CVE-2008-1993 | — | — | 2.8% | Apr 27, 2008 | Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary... |
| CVE-2008-1991 | — | — | 1.8% | Apr 27, 2008 | Cross-site scripting (XSS) vulnerability in admin_colors_swatch.asp in Acidcat CMS 3.4.1 allows remote attackers to inje... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now