Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-4031

Published Dec 10, 2008

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and…

CVSS 9.3 · Critical

CVE-2008-4030

Published Dec 10, 2008

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; and Office Compatibility Pack for Word, Excel,…

CVSS 9.3 · Critical

CVE-2008-4028

Published Dec 10, 2008

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and…

CVSS 9.3 · Critical

CVE-2008-4027

Published Dec 10, 2008

Double free vulnerability in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibil…

CVSS 9.3 · Critical

CVE-2008-4026

Published Dec 10, 2008

Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Forma…

CVSS 9.3 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2008-4025

Published Dec 10, 2008

Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack…

CVSS 9.3 · Critical

CVE-2008-4024

Published Dec 10, 2008

Microsoft Office Word 2000 SP3 and 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a Word document with a crafted lcbPlcfBkfSdt field in the…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2008-3009

Published Dec 10, 2008

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) i…

CVSS 10.0 · Critical

CVE-2008-5408

Published Dec 10, 2008

Buffer overflow in the data management protocol in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364, and 12.5 build 2213 allows remote…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5407

Published Dec 10, 2008

Multiple unspecified vulnerabilities in the Backup Exec remote-agent logon process in Symantec Backup Exec for Windows Servers 11.0 (aka 11d) builds 6235 and 7170, 12.0 build 1364…

CVSS 9.4 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5406

Published Dec 10, 2008

Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5405

Published Dec 10, 2008

Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an R…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5404

Published Dec 10, 2008

Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbit…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5400

Published Dec 10, 2008

Multiple cross-site request forgery (CSRF) vulnerabilities in mvnForum before 1.2.1 GA allow remote attackers to (1) create forums, (2) change account privileges, (3) enable accou…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5399

Published Dec 10, 2008

Cross-site scripting (XSS) vulnerability in the listonlineusers (aka "Who's online") component in mvnForum before 1.2.1 GA allows remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5414

Published Dec 10, 2008

Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5413

Published Dec 10, 2008

PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 376-400 of 5,632 CVEsPage 16 of 226