Skip to main content

Year archive

CVEs published in 2008

Archive summary

5,632 CVEs published in 2008 — 1,005 Critical, 1,859 High, 2,583 Medium, 185 Low, 0 Unrated.

CVE-2008-5286

Published Dec 1, 2008

Integer overflow in the _cupsImageReadPNG function in CUPS 1.1.17 through 1.3.9 allows remote attackers to execute arbitrary code via a PNG image with a large height value, which…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5285

Published Dec 1, 2008

Wireshark 1.0.4 and earlier allows remote attackers to cause a denial of service via a long SMTP request, which triggers an infinite loop.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4314

Published Dec 1, 2008

smbd in Samba 3.0.29 through 3.2.4 might allow remote attackers to read arbitrary memory and cause a denial of service via crafted (1) trans, (2) trans2, and (3) nttrans requests,…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5282

Published Nov 29, 2008

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5280

Published Nov 29, 2008

The Local ZIM Server in Zilab Chat and Instant Messaging (ZIM) Server 2.0 and 2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via crafted reque…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5279

Published Nov 29, 2008

The Local ZIM Server (zcs.exe) in Zilab Chat and Instant Messaging (ZIM) Server 2.1 and earlier allow remote attackers to execute arbitrary code via (1) heap-based buffer overflow…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5278

Published Nov 28, 2008

Cross-site scripting (XSS) vulnerability in the self_link function in in the RSS Feed Generator (wp-includes/feed.php) for WordPress before 2.6.5 allows remote attackers to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5275

Published Nov 28, 2008

Multiple directory traversal vulnerabilities in the (a) "Unzip archive" and (b) "Upload files and archives" functionality in net2ftp 0.96 stable and 0.97 beta allow remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5272

Published Nov 28, 2008

Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the template parameter…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5271

Published Nov 28, 2008

Cross-site scripting (XSS) vulnerability in index.php in Fred Stuurman SyndeoCMS 2.6.0 allows remote attackers to inject arbitrary web script or HTML via the section parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5270

Published Nov 28, 2008

SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL commands via the board parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5269

Published Nov 28, 2008

SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands via the shownews parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5268

Published Nov 28, 2008

SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL commands via the Topic_Id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5267

Published Nov 28, 2008

SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parame…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5265

Published Nov 28, 2008

Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via dire…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5264

Published Nov 28, 2008

Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5257

Published Nov 27, 2008

webseald in WebSEAL 6.0.0.17 in IBM Tivoli Access Manager for e-business allows remote attackers to cause a denial of service (crash or hang) via HTTP requests, as demonstrated by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5256

Published Nov 27, 2008

The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ip…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 526-550 of 5,632 CVEsPage 22 of 226