Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-5331

Published Dec 5, 2008

Adobe Acrobat 9 uses more efficient encryption than previous versions, which makes it easier for attackers to guess a document's password via a brute-force attack.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5330

Published Dec 5, 2008

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in ClearCase RWP server in IBM Rational ClearCase 7.0.0 before 7.0.0.4, and 7.0.1.1-RATL-RCC-IFIX02 and po…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5329

Published Dec 5, 2008

ClearQuest Web in IBM Rational ClearQuest MultiSite before 7.1 allows remote servers to direct a client's submissions and changes to an arbitrary database by specifying multiple c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5328

Published Dec 5, 2008

The ClearQuest Maintenance Tool in IBM Rational ClearQuest before 7 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, which…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5327

Published Dec 5, 2008

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7 before 7.1 stores the database password in cleartext in an object in a ClearQuest connection profile or export file, w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5326

Published Dec 5, 2008

The ClearQuest Maintenance Tool in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 on Windows allows local users to obtain (1) user and (2) database password…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5325

Published Dec 5, 2008

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 7.0.0 before 7.0.0.4 and 7.0.1 before 7.0.1.3 allow remote attackers to inject arbitrary w…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5324

Published Dec 5, 2008

Multiple cross-site scripting (XSS) vulnerabilities in CQ Web in IBM Rational ClearQuest 2007 before 2007D and 2008 before 2008B allow remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4416

Published Dec 5, 2008

Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2379

Published Dec 5, 2008

Cross-site scripting (XSS) vulnerability in SquirrelMail before 1.4.17 allows remote attackers to inject arbitrary web script or HTML via a crafted hyperlink in an HTML part of an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5323

Published Dec 3, 2008

Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5322

Published Dec 3, 2008

Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, which calls the phpinfo function.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5321

Published Dec 3, 2008

SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary SQL commands via the no parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5320

Published Dec 3, 2008

SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5319

Published Dec 3, 2008

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to tiki-error.php, a different issue than CVE-2008-3653.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5318

Published Dec 3, 2008

Unspecified vulnerability in Tikiwiki before 2.2 has unknown impact and attack vectors related to "size of user-provided input," a different issue than CVE-2008-3653.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5080

Published Dec 3, 2008

awstats.pl in AWStats 6.8 and earlier does not properly remove quote characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the query_string p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5314

Published Dec 3, 2008

Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5313

Published Dec 3, 2008

mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5312

Published Dec 3, 2008

mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5276

Published Dec 3, 2008

Integer overflow in the ReadRealIndex function in real.c in the Real demuxer plugin in VideoLAN VLC media player 0.9.0 through 0.9.7 allows remote attackers to execute arbitrary c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3059

Published Dec 3, 2008

member/settings_account.php in Octeth Oempro 3.5.5.1, and possibly other versions before 4, uses cleartext to transmit a password entered in the FormValue_Password field, which ma…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 476-500 of 5,632 CVEsPage 20 of 226