Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-0244

Published Jan 12, 2008

SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell metacharacters in exec_sdbinfo and other unspecified commands…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0247

Published Jan 12, 2008

Heap-based buffer overflow in the Express Backup Server service (dsmsvc.exe) in IBM Tivoli Storage Manager (TSM) Express 5.3 before 5.3.7.3 allows remote attackers to execute arbi…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0249

Published Jan 12, 2008

PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebquest.php, which leaks the credentials in an error message if…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0250

Published Jan 12, 2008

Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0251

Published Jan 12, 2008

Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0252

Published Jan 12, 2008

Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0123

Published Jan 12, 2008

Cross-site scripting (XSS) vulnerability in install.php for Moodle 1.8.3, and possibly other versions before 1.8.4, allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6420

Published Jan 12, 2008

Cross-site request forgery (CSRF) vulnerability in the balancer-manager in mod_proxy_balancer for Apache HTTP Server 2.2.x allows remote attackers to gain privileges via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-6423

Published Jan 12, 2008

Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0239

Published Jan 11, 2008

Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allow remote attackers to inject arbitrary HTML or web sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0240

Published Jan 11, 2008

/idm/help/index.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to inject frames from arbitrary web sites and conduct phishing at…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0241

Published Jan 11, 2008

Open redirect vulnerability in /idm/user/login.jsp in Sun Java System Identity Manager 6.0 SP1 through SP3, 7.0, and 7.1 allows remote attackers to redirect users to arbitrary web…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0238

Published Jan 11, 2008

Multiple heap-based buffer overflows in the rmff_dump_cont function in input/libreal/rmff.c in xine-lib 1.1.9 allow remote attackers to execute arbitrary code via the SDP (1) Titl…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0233

Published Jan 11, 2008

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload and execute arbitrary files by u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-0234

Published Jan 11, 2008

Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allows remote attackers to execute arbitrary code via a long Re…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0236

Published Jan 11, 2008

An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary commands by invoking the DoCmd method.

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0237

Published Jan 11, 2008

The Microsoft Rich Textbox ActiveX Control (RICHTX32.OCX) 6.1.97.82 allows remote attackers to execute arbitrary commands by invoking the insecure SaveFile method.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0230

Published Jan 11, 2008

PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via a URL in the php121…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 5,426-5,450 of 5,632 CVEsPage 218 of 226