Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-5411

Published Dec 10, 2008

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over "unsecured TCP," which makes it easier for remote attackers to obtain sensitive information by sniff…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5410

Published Dec 10, 2008

The PK11_SESSION cache in the OpenSSL PKCS#11 engine in Sun Solaris 10 does not maintain reference counts for operations with asymmetric keys, which allows context-dependent attac…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5305

Published Dec 10, 2008

Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5304

Published Dec 10, 2008

Cross-site scripting (XSS) vulnerability in TWiki before 4.2.4 allows remote attackers to inject arbitrary web script or HTML via the %URLPARAM{}% variable.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4311

Published Dec 10, 2008

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restri…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5398

Published Dec 9, 2008

Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a policy-based refusal of a stream…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5397

Published Dec 9, 2008

Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by leveraging unintended supplemen…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5396

Published Dec 9, 2008

Array index error in the (1) torisa.c and (2) dahdi/tor2.c drivers in Zaptel (aka DAHDI) 1.4.11 and earlier allows local users in the dialout group to overwrite an integer value i…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5395

Published Dec 9, 2008

The parisc_show_stack function in arch/parisc/kernel/traps.c in the Linux kernel before 2.6.28-rc7 on PA-RISC allows local users to cause a denial of service (system crash) via ve…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5394

Published Dec 9, 2008

/bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack o…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5393

Published Dec 9, 2008

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanism…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5387

Published Dec 9, 2008

Buffer overflow in autoconf6 in IBM AIX 6.1.0 through 6.1.2, when Role-Based Access Control is enabled, allows local users with aix.network.config.tcpip authorization to gain priv…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5386

Published Dec 9, 2008

Buffer overflow in ndp in IBM AIX 6.1.0 through 6.1.2, when the netcd daemon is running, allows local users to gain privileges via unspecified vectors.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5385

Published Dec 9, 2008

enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files via unspecified vectors.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5384

Published Dec 9, 2008

crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching an editor.

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5383

Published Dec 9, 2008

Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbi…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5381

Published Dec 9, 2008

Buffer overflow in the URL processing in ffdshow (aka ffdshow-tryout) before SVN revision 2347 allows remote attackers to execute arbitrary code via a long URL.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5277

Published Dec 9, 2008

PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5079

Published Dec 9, 2008

net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_liste…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4391

Published Dec 9, 2008

Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera befo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-4310

Published Dec 9, 2008

httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5380

Published Dec 8, 2008

gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 5,632 CVEsPage 17 of 226