2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2008-20001HIGH7.5activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of t...
CVE-2008-7314HIGH7.5mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
CVE-2008-7273HIGH7.8A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
CVE-2008-7272HIGH7.5FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and th...
CVE-2008-3278HIGH7.8frysk packages through 2008-08-05 as shipped in Red Hat Enterprise Linux 5 are built with an insecure RPATH set in the E...
CVE-2008-0015HIGH8.8Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in...
CVE-2008-6828HIGH7.8Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 stores the Application Identity Account password in memory i...
CVE-2008-6827HIGH7.8The ListView control in the Client GUI (AClient.exe) in Symantec Altiris Deployment Solution 6.x before 6.9.355 SP1 allo...
CVE-2008-6157HIGH7.5SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent at...
CVE-2008-5748HIGH8.1Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to rea...
CVE-2008-4122HIGH7.5Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote ...
CVE-2008-4390HIGH7.5The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a...
CVE-2008-5162HIGH7The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time ...
CVE-2008-5183HIGH7.5cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon ...
CVE-2008-4929HIGH7.5MyBB (aka MyBulletinBoard) 1.4.2 uses insufficient randomness to compose filenames of uploaded files used as attachments...
CVE-2008-2992HIGH7.8Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c...
CVE-2008-4905HIGH7.5Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to gu...
CVE-2008-4309HIGH7.5Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 ...
CVE-2008-4577HIGH7.5The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows...
CVE-2008-4036HIGH8.4Integer overflow in Memory Manager in Microsoft Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and...
CVE-2008-3475HIGH8.8Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml obje...
CVE-2008-4197HIGH8.8Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produc...
CVE-2008-3637HIGH8.8The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an...
CVE-2008-3938HIGH8.8Cross-site request forgery (CSRF) vulnerability in user_admin.php in Open Media Collectors Database (OpenDb) 1.0.6 allow...
CVE-2008-3939HIGH7.5Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers t...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now