Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0406

Published Jan 29, 2008

HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allows remote attackers to cause a denial of service (daemon crash) via a long account name.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0407

Published Jan 29, 2008

HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which mig…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0408

Published Jan 29, 2008

HTTP File Server (HFS) before 2.2c allows remote attackers to append arbitrary text to the log file by using the base64 representation of this text during HTTP Basic Authenticatio…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0409

Published Jan 29, 2008

Cross-site scripting (XSS) vulnerability in HTTP File Server (HFS) before 2.2c allows remote attackers to inject arbitrary web script or HTML via the userinfo subcomponent of a UR…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0410

Published Jan 29, 2008

HTTP File Server (HFS) before 2.2c allows remote attackers to obtain configuration and usage details by using an id element such as <id>%version%</id> in HTTP Basic Authentication…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0458

Published Jan 25, 2008

Directory traversal vulnerability in function/sources.php in SLAED CMS 2.5 Lite allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newl…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0459

Published Jan 25, 2008

Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0461

Published Jan 25, 2008

SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQ…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0462

Published Jan 25, 2008

Cross-site scripting (XSS) vulnerability in the Archive 5.x before 5.x-1.8 module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0463

Published Jan 25, 2008

Cross-site scripting (XSS) vulnerability in the Workflow 4.7.x before 4.7.x-1.2 and 5.x before 5.x-1.2 module for Drupal allows remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0464

Published Jan 25, 2008

Directory traversal vulnerability in archiv.cgi in absofort aconon Mail 2007 Enterprise SQL 11.7.0 and Mail 2004 Enterprise SQL 11.5.1 allows remote attackers to read arbitrary fi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0465

Published Jan 25, 2008

Directory traversal vulnerability in optimizer.php in Seagull 0.6.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the files parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4850

Published Jan 25, 2008

curl/interface.c in the cURL library (aka libcurl) in PHP 5.2.4 and 5.2.5 allows context-dependent attackers to bypass safe_mode and open_basedir restrictions and read arbitrary f…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5764

Published Jan 25, 2008

Buffer overflow in the pioout program in printers.rte in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via a long command line option.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6415

Published Jan 25, 2008

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute arbitrary code by invoking scp, as implemented by OpenSSH, with the -F and -o…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0441

Published Jan 25, 2008

IBM Tivoli Business Service Manager (TBSM) 4.1.1 stores passwords in cleartext (1) after external authentication, which triggers writing the password to SM_server.log; and (2) aft…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0442

Published Jan 25, 2008

PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the ffile parameter, a diff…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0443

Published Jan 25, 2008

Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary c…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0444

Published Jan 25, 2008

Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0445

Published Jan 25, 2008

The replace_inline_img function in elogd in Electronic Logbook (ELOG) before 2.7.1 allows remote attackers to cause a denial of service (infinite loop) via crafted logbook entries…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,201-5,225 of 5,632 CVEsPage 209 of 226