Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0036

Published Jan 16, 2008

Buffer overflow in Apple QuickTime before 7.4 allows remote attackers to execute arbitrary code via a crafted compressed PICT image, which triggers the overflow during decoding.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0031

Published Jan 16, 2008

Unspecified vulnerability in Apple QuickTime before 7.4 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Sor…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0034

Published Jan 16, 2008

Unspecified vulnerability in Passcode Lock in Apple iPhone 1.0 through 1.1.2 allows users with physical access to execute applications without entering the passcode via vectors re…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0122

Published Jan 16, 2008

Off-by-one error in the inet_network function in libbind in ISC BIND 9.4.2 and earlier, as used in libc in FreeBSD 6.2 through 7.0-PRERELEASE, allows context-dependent attackers t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0216

Published Jan 16, 2008

The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the p…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0217

Published Jan 16, 2008

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0287

Published Jan 16, 2008

PHP remote file inclusion vulnerability in VisionBurst vcart 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) index.php and (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0288

Published Jan 16, 2008

Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0289

Published Jan 16, 2008

PHP remote file inclusion vulnerability in view_func.php in Member Area System (MAS) 1.7 and possibly others allows remote attackers to execute arbitrary PHP code via a URL in the…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0290

Published Jan 16, 2008

Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitrary SQL commands via the selectskin parameter to an unspecif…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0286

Published Jan 16, 2008

SQL injection vulnerability in admin/login.php in Article Dashboard allows remote attackers to execute arbitrary SQL commands via the (1) user or (2) password fields.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0285

Published Jan 16, 2008

ngIRCd 0.10.x before 0.10.4 and 0.11.0 before 0.11.0-pre2 allows remote attackers to cause a denial of service (crash) via crafted IRC PART message, which triggers an invalid dere…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0280

Published Jan 15, 2008

SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0281

Published Jan 15, 2008

SQL injection vulnerability in liste.php in ID-Commerce 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idFamille parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0282

Published Jan 15, 2008

SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary SQL commands via the mail parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0283

Published Jan 15, 2008

PHP remote file inclusion vulnerability in /aides/index.php in DomPHP 0.81 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0284

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) Itemid or (2) topi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0001

Published Jan 15, 2008

VFS in the Linux kernel before 2.6.22.16, and 2.6.23.x before 2.6.23.14, performs tests of access mode by using the flag variable instead of the acc_mode variable, which might all…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2008-0173

Published Jan 15, 2008

SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0253

Published Jan 15, 2008

SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands via the nid parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0254

Published Jan 15, 2008

SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL comm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0255

Published Jan 15, 2008

SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0256

Published Jan 15, 2008

Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) Imgbig.asp, (…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0257

Published Jan 15, 2008

Cross-site scripting (XSS) vulnerability in search.pl in Dansie Search Engine 2.7 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter. NOTE:…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,376-5,400 of 5,632 CVEsPage 216 of 226