2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-2475——eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbi...
CVE-2008-6832——Cross-site request forgery (CSRF) vulnerability in Atlassian JIRA Enterprise Edition 3.13 allows remote attackers to hij...
CVE-2008-6831——Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA Enterprise Edition 3.13 allow remote attackers to ...
CVE-2008-6830——The disconnection feature in Citrix Web Interface 5.0 and 5.0.1 for Java Application Servers does not properly terminate...
CVE-2008-6829——VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo...
CVE-2008-6828HIGH7.8Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory i...
CVE-2008-6827HIGH7.8The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allo...
CVE-2008-6826——dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par...
CVE-2008-6825——Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to ...
CVE-2008-6824——The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco...
CVE-2008-6823——Multiple cross-site request forgery (CSRF) vulnerabilities in the management interface on the A-LINK WL54AP3 and WL54AP2...
CVE-2008-6822——Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader...
CVE-2008-6821——Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to ...
CVE-2008-6820——The db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," whi...
CVE-2008-2154——IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 provides an INSTALL_JAR (aka sqlj.install_jar) procedure, whic...
CVE-2008-6819——win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via...
CVE-2008-6818——Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to...
CVE-2008-6817——Mole Group Lastminute Script 4.0 and earlier stores passwords in cleartext, which allows context-dependent attackers to ...
CVE-2008-6816——Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a ...
CVE-2008-6815——mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a ...
CVE-2008-6814——Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl...
CVE-2008-3870——Integer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted RPC r...
CVE-2008-3869——Heap-based buffer overflow in sadmind in Sun Solaris 8 and 9 allows remote attackers to execute arbitrary code via a cra...
CVE-2008-6813——SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ...
CVE-2008-6812——SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now