Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-5495

Published Dec 12, 2008

Unspecified vulnerability in the GungHo LoadPrgAx ActiveX control 1.0.0.6 and earlier allows remote attackers to execute arbitrary Java applications via unknown vectors.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5494

Published Dec 12, 2008

SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5492

Published Dec 12, 2008

Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5491

Published Dec 12, 2008

SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pageID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5490

Published Dec 12, 2008

SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5489

Published Dec 12, 2008

SQL injection vulnerability in channel_detail.php in ClipShare Pro 4, and 2006 through 2007, allows remote attackers to execute arbitrary SQL commands via the chid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5488

Published Dec 12, 2008

SQL injection vulnerability in admin.php in E-topbiz Domain Shop 2 allows remote attackers to execute arbitrary SQL commands via the passfromform parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5487

Published Dec 12, 2008

Cross-site scripting (XSS) vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5486

Published Dec 12, 2008

SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5435

Published Dec 11, 2008

Cross-site scripting (XSS) vulnerability in moderate.php in PunBB before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via a topic subject.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5434

Published Dec 11, 2008

Multiple SQL injection vulnerabilities in PunBB 1.3 and 1.3.1 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) order_by or (2) direction par…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5433

Published Dec 11, 2008

Cross-site scripting (XSS) vulnerability in login.php in PunBB 1.3 and 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the password field.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5432

Published Dec 11, 2008

Cross-site scripting (XSS) vulnerability in Moodle before 1.6.8, 1.7 before 1.7.6, 1.8 before 1.8.7, and 1.9 before 1.9.3 allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5431

Published Dec 11, 2008

Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3) a certain PORT command.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5429

Published Dec 11, 2008

Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc82…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5428

Published Dec 11, 2008

Opera 9.51 on Windows XP does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5427

Published Dec 11, 2008

Norton Antivirus in Norton Internet Security 15.5.0.23 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5425

Published Dec 11, 2008

ESet NOD32 2.70.0039.0000 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc82…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5424

Published Dec 11, 2008

The MimeOleClearDirtyTree function in InetComm.dll in Microsoft Outlook Express 6.00.2900.5512 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5421

Published Dec 11, 2008

The SSL web administration service in NetWin SmsGate 1.1n and earlier allows remote attackers to cause a denial of service (hang) via (1) a large integer in the Content-Length HTT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 5,632 CVEsPage 14 of 226