2008 CVE Vulnerabilities
7,179 CVEs published in 2008.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2008-1013 | — | — | 4.1% | Apr 4, 2008 | Apple QuickTime before 7.4.5 enables deserialization of QTJava objects by untrusted Java applets, which allows remote at... |
| CVE-2008-1374 | — | — | 3.9% | Apr 4, 2008 | Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows... |
| CVE-2008-0555 | — | — | 1.9% | Apr 4, 2008 | The ExpandCert function in Apache-SSL before apache_1.3.41+ssl_1.59 does not properly handle (1) '/' and (2) '=' charact... |
| CVE-2008-0884 | — | — | 0.4% | Apr 4, 2008 | The Replace function in the capp-lspp-config script in the (1) lspp-eal4-config-ibm and (2) capp-lspp-eal4-config-hp pac... |
| CVE-2008-1373 | — | — | 2.2% | Apr 4, 2008 | Buffer overflow in the gif_read_lzw function in CUPS 1.3.6 allows remote attackers to have an unknown impact via a GIF f... |
| CVE-2008-1680 | — | — | 2.2% | Apr 4, 2008 | PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenanc... |
| CVE-2008-1331 | — | — | 8.8% | Apr 2, 2008 | cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014... |
| CVE-2008-1654 | — | — | 4.8% | Apr 2, 2008 | Interaction error between Adobe Flash and multiple Universal Plug and Play (UPnP) services allow remote attackers to per... |
| CVE-2008-1657 | — | — | 2.2% | Apr 2, 2008 | OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive... |
| CVE-2008-1644 | — | — | 1.1% | Apr 2, 2008 | SQL injection vulnerability in viewlinks.php in Sava's Link Manager 2.0 allows remote attackers to execute arbitrary SQL... |
| CVE-2008-1631 | — | — | 1.1% | Apr 2, 2008 | SQL injection vulnerability in login.php in CuteFlow 1.5.0 and 2.10.0 allows remote attackers to execute arbitrary SQL c... |
| CVE-2008-0069 | — | — | 8.4% | Apr 2, 2008 | Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi... |
| CVE-2008-1620 | — | — | 3.0% | Apr 2, 2008 | Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r349... |
| CVE-2008-1621 | — | — | 1.5% | Apr 2, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or... |
| CVE-2008-1622 | — | — | 1.0% | Apr 2, 2008 | Multiple PHP remote file inclusion vulnerabilities in GeeCarts allow remote attackers to execute arbitrary PHP code via ... |
| CVE-2008-1623 | — | — | 1.2% | Apr 2, 2008 | SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm... |
| CVE-2008-1624 | — | — | 2.7% | Apr 2, 2008 | Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include ... |
| CVE-2008-1625 | — | — | 0.7% | Apr 2, 2008 | aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which... |
| CVE-2008-1626 | — | — | 1.8% | Apr 2, 2008 | SQL injection vulnerability in eggBlog before 4.0.1 allows remote attackers to execute arbitrary SQL commands via an uns... |
| CVE-2008-1627 | — | — | 1.0% | Apr 2, 2008 | CDS Invenio 0.92.1 and earlier allows remote authenticated users to delete email notification alerts of arbitrary users ... |
| CVE-2008-1628 | — | — | 1.0% | Apr 2, 2008 | Stack-based buffer overflow in the audit_log_user_command function in lib/audit_logging.c in Linux Audit before 1.7 migh... |
| CVE-2008-1629 | — | — | 1.0% | Apr 2, 2008 | Cross-site scripting (XSS) vulnerability in PHPkrm before 1.5.0 allows remote attackers to inject arbitrary web script o... |
| CVE-2008-1630 | — | — | 1.1% | Apr 2, 2008 | Multiple cross-site scripting (XSS) vulnerabilities in CuteFlow 1.5.0 and 2.10.0 allow remote attackers to inject arbitr... |
| CVE-2008-1632 | — | — | 1.0% | Apr 2, 2008 | Multiple SQL injection vulnerabilities in CuteFlow 2.10.0 allow remote authenticated users to execute arbitrary SQL comm... |
| CVE-2008-1633 | — | — | 1.5% | Apr 2, 2008 | Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) ... |
Check if your code is affected by 2008 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now