2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

CVE IDSeverityCVSSDescription
CVE-2008-5257webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of se...
CVE-2008-5256The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite ar...
CVE-2008-4636yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell Linux allows local users to gain privileges via shell metach...
CVE-2008-4315tog-pegasus in OpenGroup Pegasus 2.7.0 on Red Hat Enterprise Linux (RHEL) 5, Fedora 9, and Fedora 10 does not log failed...
CVE-2008-4313A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which a...
CVE-2008-5162HIGH7The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time ...
CVE-2008-2378Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan h...
CVE-2008-5248xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consist...
CVE-2008-5247The real_parse_audio_specific_data function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, u...
CVE-2008-5246Multiple heap-based buffer overflows in xine-lib before 1.1.15 allow remote attackers to execute arbitrary code via vect...
CVE-2008-5245xine-lib before 1.1.15 performs V4L video frame preallocation before ascertaining the required length, which has unknown...
CVE-2008-5244Unspecified vulnerability in xine-lib before 1.1.15 has unknown impact and attack vectors related to libfaad. NOTE: due...
CVE-2008-5243The real_parse_headers function in demux_real.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an ...
CVE-2008-5242demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not validate the count field before calling c...
CVE-2008-5241Integer underflow in demux_qt.c in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allows remote attackers to ca...
CVE-2008-5240xine-lib 1.1.12, and other 1.1.15 and earlier versions, relies on an untrusted input value to determine the memory alloc...
CVE-2008-5239xine-lib 1.1.12, and other 1.1.15 and earlier versions, does not properly handle (a) negative and (b) zero values during...
CVE-2008-5238Integer overflow in the real_parse_mdpr function in demux_real.c in xine-lib 1.1.12, and other versions before 1.1.15, a...
CVE-2008-5237Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a ...
CVE-2008-5236Multiple heap-based buffer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers t...
CVE-2008-5235Heap-based buffer overflow in the demux_real_send_chunk function in src/demuxers/demux_real.c in xine-lib before 1.1.15 ...
CVE-2008-5234Multiple heap-based buffer overflows in xine-lib 1.1.12, and other versions before 1.1.15, allow remote attackers to exe...
CVE-2008-5233xine-lib 1.1.12, and other versions before 1.1.15, does not check for failure of malloc in circumstances including (1) t...
CVE-2008-5232Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3...
CVE-2008-5231Stack-based buffer overflow in the ExecuteRequest method in the Novell iPrint ActiveX control in ienipp.ocx in Novell iP...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now