Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2007-6690

Published Jan 17, 2008

The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6691

Published Jan 17, 2008

Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the W…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-6692

Published Jan 17, 2008

Open redirect vulnerability in Menalto Gallery before 2.2.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) Core…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6693

Published Jan 17, 2008

Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0302

Published Jan 17, 2008

Untrusted search path vulnerability in apt-listchanges.py in apt-listchanges before 2.82 allows local users to execute arbitrary code via a malicious apt-listchanges program in th…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6681

Published Jan 17, 2008

Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via a long subtitle in a (1) MicroDvd, (2) SSA, an…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6682

Published Jan 17, 2008

Format string vulnerability in the httpd_FileCallBack function (network/httpd.c) in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitrary code via format string specifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2007-6683

Published Jan 17, 2008

The browser plugin in VideoLAN VLC 0.8.6d allows remote attackers to overwrite arbitrary files via (1) the :demuxdump-file option in a filename in a playlist, or (2) a EXTVLCOPT s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6684

Published Jan 17, 2008

The RTSP module in VideoLAN VLC 0.8.6d allows remote attackers to cause a denial of service (crash) via a request without a Transport parameter, which triggers a NULL pointer dere…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0297

Published Jan 16, 2008

PhotoKorn allows remote attackers to obtain database credentials via a direct request to update/update3.php, which includes the credentials in its output.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0298

Published Jan 16, 2008

KHTML WebKit as used in Apple Safari 2.x allows remote attackers to cause a denial of service (browser crash) via a crafted web page, possibly involving a STYLE attribute of a DIV…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0299

Published Jan 16, 2008

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from an…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0291

Published Jan 16, 2008

SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL commands via the cat parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0292

Published Jan 16, 2008

Cross-site scripting (XSS) vulnerability in photo_album.pl in Dansie Photo Album 1.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0293

Published Jan 16, 2008

Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0294

Published Jan 16, 2008

Unspecified vulnerability in the seat-locking implementation in FreeSeat before 1.1.5d allows attackers to book a seat more than once via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0295

Published Jan 16, 2008

Heap-based buffer overflow in modules/access/rtsp/real_sdpplin.c in the Xine library, as used in VideoLAN VLC Media Player 0.8.6d and earlier, allows user-assisted remote attacker…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0032

Published Jan 16, 2008

Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a movie file containing a Macintosh Resource record with a modified length value in the resource h…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0033

Published Jan 16, 2008

Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a movie file…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 5,351-5,375 of 5,632 CVEsPage 215 of 226