2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-6079imlib2 before 1.4.2 allows context-dependent attackers to have an unspecified impact via a crafted (1) ARGB, (2) BMP, (3...
CVE-2008-6078SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote att...
CVE-2008-6077SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to exe...
CVE-2008-6076SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers ...
CVE-2008-6075SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL ...
CVE-2008-6074Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows rem...
CVE-2008-6067Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-5838. Reason: This candidate is a duplicate of...
CVE-2008-6066Multiple PHP remote file inclusion vulnerabilities in Meet#Web 0.8 allow remote attackers to execute arbitrary PHP code ...
CVE-2008-6065Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased i...
CVE-2008-6064Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c...
CVE-2008-6063Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during a...
CVE-2008-6062Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dream...
CVE-2008-6061Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by ...
CVE-2008-6060Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft Fu...
CVE-2008-6059xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Se...
CVE-2008-6058Syslserve 1.058 and earlier, and probably 1.059, allows remote attackers to cause a denial of service (hang) via a craft...
CVE-2008-4419Directory traversal vulnerability in the HP JetDirect web administration interface in the HP-ChaiSOE 1.0 embedded web se...
CVE-2008-6057Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic...
CVE-2008-6056Multiple cross-site scripting (XSS) vulnerabilities in World Recipe 2.11 allow remote attackers to inject arbitrary web ...
CVE-2008-6055PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows ...
CVE-2008-6054PreProjects Pre Courier and Cargo Business stores dbcourior.mdb under the web root with insufficient access control, whi...
CVE-2008-6053PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allo...
CVE-2008-6052PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which all...
CVE-2008-6051MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to ...
CVE-2008-6050SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now