2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-2020HIGH7.5The CAPTCHA implementation as used in (1) Francisco Burzi PHP-Nuke 7.0 and 8.1, (2) my123tkShop e-Commerce-Suite (aka 12...
CVE-2008-2014Mozilla Firefox 3.0 beta 5 allows remote attackers to cause a denial of service (application crash) via JavaScript code ...
CVE-2008-2015Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac...
CVE-2008-2019Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the ...
CVE-2008-2018The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings del...
CVE-2008-2013SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc ...
CVE-2008-1738Rising Antivirus 2008 before 20.38.20 allows local users to cause a denial of service (system crash) via an invalid poin...
CVE-2008-1737Sophos Anti-Virus 7.0.5, and other 7.x versions, when Runtime Behavioural Analysis is enabled, allows local users to cau...
CVE-2008-1736Comodo Firewall Pro before 3.0 does not properly validate certain parameters to hooked System Service Descriptor Table (...
CVE-2008-2012SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute ...
CVE-2008-2011Cross-site scripting (XSS) vulnerability in the National Rail Enquiries Live Departure Boards gadget before 1.1 allows r...
CVE-2008-2010Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute a...
CVE-2008-1735BitDefender Antivirus 2008 20080118 and earlier allows local users to cause a denial of service (system crash) via an in...
CVE-2008-1293ldm in Linux Terminal Server Project (LTSP) 0.99 and 2 passes the -ac option to the X server on each LTSP client, which ...
CVE-2008-2008Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote at...
CVE-2008-2001Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash) via a file:///%E2 link that ...
CVE-2008-2000Unspecified vulnerability in Apple Safari 3.1.1 allows remote attackers to cause a denial of service (application crash)...
CVE-2008-1999Apple Safari 3.1.1 allows remote attackers to spoof the address bar by placing many "invisible" characters in the userin...
CVE-2008-1998The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allow...
CVE-2008-1930The cookie authentication method in WordPress 2.5 relies on a hash of a concatenated string containing USERNAME and EXPI...
CVE-2008-1997Unspecified vulnerability in the ADMIN_SP_C2 procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 all...
CVE-2008-1996licq before 1.3.6 allows remote attackers to cause a denial of service (file-descriptor exhaustion and application crash...
CVE-2008-1103Multiple unspecified vulnerabilities in Blender have unknown impact and attack vectors, related to "temporary file issue...
CVE-2008-2002Multiple cross-site request forgery (CSRF) vulnerabilities on Motorola Surfboard with software SB5100-2.3.3.0-SCM00-NOSH...
CVE-2008-2003BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which ...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now