2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-2475eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbi...
CVE-2008-6832Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hij...
CVE-2008-6831Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to ...
CVE-2008-6830The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate...
CVE-2008-6829VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo...
CVE-2008-6828HIGH7.8Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory i...
CVE-2008-6827HIGH7.8The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allo...
CVE-2008-6826dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par...
CVE-2008-6825Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to ...
CVE-2008-6824The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco...
CVE-2008-6823Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2...
CVE-2008-6822Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader...
CVE-2008-6821Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to ...
CVE-2008-6820The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," whi...
CVE-2008-2154IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, whic...
CVE-2008-6819win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via...
CVE-2008-6818Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to...
CVE-2008-6817Mole Group Lastminute Script 4.0 and earlier stores passwords in cleartext, which allows context-dependent attackers to ...
CVE-2008-6816Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a ...
CVE-2008-6815mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a ...
CVE-2008-6814Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl...
CVE-2008-3870Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC r...
CVE-2008-3869Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a cra...
CVE-2008-6813SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ...
CVE-2008-6812SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now