Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0365

Published Jan 18, 2008

Multiple buffer overflows in CORE FORCE before 0.95.172 allow local users to cause a denial of service (system crash) and possibly execute arbitrary code in the kernel context via…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0366

Published Jan 18, 2008

CORE FORCE before 0.95.172 does not properly validate arguments to SSDT hook handler functions in the Registry module, which allows local users to cause a denial of service (syste…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0353

Published Jan 18, 2008

SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute arbitrary SQL commands via the cognome_cerca parameter. NO…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0354

Published Jan 18, 2008

Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0355

Published Jan 18, 2008

SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id par…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0357

Published Jan 18, 2008

Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via di…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0358

Published Jan 18, 2008

SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0359

Published Jan 18, 2008

Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin.php or (2) inde…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0360

Published Jan 18, 2008

Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (1) the blogid parameter to index.php, (2) the user paramete…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0361

Published Jan 18, 2008

Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0362

Published Jan 18, 2008

Cross-site scripting (XSS) vulnerability in gallery.php in Clever Copy 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the album parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0363

Published Jan 18, 2008

Multiple SQL injection vulnerabilities in Clever Copy 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to postcomment.php and the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0350

Published Jan 18, 2008

admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0351

Published Jan 18, 2008

admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es_security_captcha parameter and not invoking captcha.php.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0352

Published Jan 18, 2008

The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop op…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0171

Published Jan 17, 2008

regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0172

Published Jan 17, 2008

The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0339

Published Jan 17, 2008

Unspecified vulnerability in the XML DB component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB01.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0341

Published Jan 17, 2008

Unspecified vulnerability in the Advanced Queuing component in Oracle Database 9.0.1.5 FIPS+ and 10.1.0.5 has unknown impact and remote attack vectors, aka DB03.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0342

Published Jan 17, 2008

Unspecified vulnerability in the Upgrade/Downgrade component in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3 has unknown impact and remote attack vectors, aka DB05.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,301-5,325 of 5,632 CVEsPage 213 of 226