2008 CVE Vulnerabilities

7,179 CVEs published in 2008.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2008-10002MEDIUM6.1A vulnerability has been found in cfire24 ajaxlife up to 0.3.2 and classified as problematic. This vulnerability affects...
CVE-2008-10001MEDIUM6.1A vulnerability, which was classified as problematic, has been found in Pro2col Stingray FTS. The manipulation of the ar...
CVE-2008-2544MEDIUM5.5Mounting /proc filesystem via chroot command silently mounts it in read-write mode. The user could bypass the chroot env...
CVE-2008-3280MEDIUM5.9It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb...
CVE-2008-5083MEDIUM6.5In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBo...
CVE-2008-5180MEDIUM5.3Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of ser...
CVE-2008-4989MEDIUM5.9The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate...
CVE-2008-4996MEDIUM5.5init in initramfs-tools 0.92f allows local users to overwrite arbitrary files via a symlink attack on the /tmp/initramfs...
CVE-2008-3474MEDIUM6.5Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, whi...
CVE-2008-4302MEDIUM5.5fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to...
CVE-2008-4128MEDIUM4.3Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the...
CVE-2008-3937MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in Open Media Collectors Database (OpenDb) 1.0.6 allow remote attack...
CVE-2008-3935MEDIUM6.1Cross-site scripting (XSS) vulnerability in DIC shop_v50 3.0 and earlier and shop_v52 2.0 and earlier allows remote atta...
CVE-2008-3893MEDIUM5.5Microsoft Bitlocker in Windows Vista before SP1 stores pre-boot authentication passwords in the BIOS Keyboard buffer and...
CVE-2008-3281MEDIUM6.5libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allow...
CVE-2008-3775MEDIUM4.4Folder Lock 5.9.5 and earlier uses weak encryption (ROT-25) for the password, which allows local administrators to obtai...
CVE-2008-3275MEDIUM5.5The (1) real_lookup and (2) __lookup_hash functions in fs/namei.c in the vfs implementation in the Linux kernel before 2...
CVE-2008-3397MEDIUM6.1Cross-site scripting (XSS) vulnerability in Runesoft Cerberus CMS before 3_1.4_0.9 allows remote attackers to inject arb...
CVE-2008-2951MEDIUM6.1Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbi...
CVE-2008-2991MEDIUM6.1Cross-site scripting (XSS) vulnerability in Adobe RoboHelp Server 6 and 7 allows remote attackers to inject arbitrary we...
CVE-2008-1447MEDIUM6.8The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo...
CVE-2008-2052MEDIUM6.1Open redirect vulnerability in redirect.php in Bitrix Site Manager 6.5 allows remote attackers to redirect users to arbi...
CVE-2008-1567MEDIUM5.5phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext...
CVE-2008-1299MEDIUM6.1Cross-site scripting (XSS) vulnerability in SolutionSearch.do in ManageEngine ServiceDesk Plus 7.0.0 Build 7011 for Wind...
CVE-2008-0642MEDIUM6.1Cross-site scripting (XSS) vulnerability in files created by Adobe RoboHelp 6 and 7, possibly involving use of a (1) Web...

Check if your code is affected by 2008 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now