Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-3058

Published Dec 3, 2008

Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_E…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3057

Published Dec 3, 2008

Octeth Oempro 3.5.5.1, and possibly other versions before 4, does not set the secure flag for the PHPSESSID cookie in an https session, which makes it easier for remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5311

Published Dec 2, 2008

SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5310

Published Dec 2, 2008

SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5309

Published Dec 2, 2008

SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5308

Published Dec 2, 2008

The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to change the administrator passwo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5306

Published Dec 2, 2008

SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5303

Published Dec 1, 2008

Race condition in the rmtree function in File::Path 1.08 (lib/File/Path.pm) in Perl 5.8.8 allows local users to to delete arbitrary files via a symlink attack, a different vulnera…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5302

Published Dec 1, 2008

Race condition in the rmtree function in File::Path 1.08 and 2.07 (lib/File/Path.pm) in Perl 5.8.8 and 5.10.0 allows local users to create arbitrary setuid binaries via a symlink…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5301

Published Dec 1, 2008

Directory traversal vulnerability in the ManageSieve implementation in Dovecot 1.0.15, 1.1, and 1.2 allows remote attackers to read and modify arbitrary .sieve files via a ".." (d…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5300

Published Dec 1, 2008

Linux kernel 2.6.28 allows local users to cause a denial of service ("soft lockup" and process loss) via a large number of sendmsg function calls, which does not block during AF_U…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5299

Published Dec 1, 2008

chm2pdf 0.9 allows user-assisted local users to delete arbitrary files via a symlink attack on .chm files in the (1) /tmp/chm2pdf/work or (2) /tmp/chm2pdf/orig temporary directori…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5298

Published Dec 1, 2008

chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those director…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-5297

Published Dec 1, 2008

Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length che…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5296

Published Dec 1, 2008

Gallery 1.5.x before 1.5.10 and 1.6 before 1.6-RC3, when register_globals is enabled, allows remote attackers to bypass authentication and gain administrative via unspecified cook…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5295

Published Dec 1, 2008

SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL commands via the show_emp parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5292

Published Dec 1, 2008

SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL commands via the type parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5291

Published Dec 1, 2008

Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5290

Published Dec 1, 2008

Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5289

Published Dec 1, 2008

SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5288

Published Dec 1, 2008

PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals is enabled, allows remote attackers to execute arbitrary P…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5287

Published Dec 1, 2008

SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 5,632 CVEsPage 21 of 226