Skip to main content

CWE archive

CWE-20 CVEs

Programmatic archive

12,898 CVEs tagged with CWE-201,634 Critical, 5,054 High, 5,683 Medium, 521 Low, 6 Unrated.

CVE-2008-2256

Published Aug 13, 2008

Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of s…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2259

Published Aug 13, 2008

Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3657

Published Aug 13, 2008

The dl module in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not check "taintness" of inputs, which allows context-depen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3003

Published Aug 12, 2008

Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data sessio…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3005

Published Aug 12, 2008

Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file wit…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3607

Published Aug 12, 2008

The IMAP server in NoticeWare Email Server NG 4.6.3 and earlier allows remote attackers to cause a denial of service (daemon crash) via multiple long LOGIN commands.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3578

Published Aug 10, 2008

HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3571

Published Aug 10, 2008

The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3492

Published Aug 6, 2008

America's Army (aka AA or Army Game Project) 2.8.3.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted UDP packet,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3493

Published Aug 6, 2008

vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application crash) via a crafted frame buffer update packet.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3444

Published Aug 4, 2008

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted b…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3410

Published Jul 31, 2008

Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a UDP packet in which the value of a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3396

Published Jul 31, 2008

Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain sequence of malform…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3323

Published Jul 28, 2008

setup.exe before 2.573.2.3 in Cygwin does not properly verify the authenticity of packages, which allows remote Cygwin mirror servers or man-in-the-middle attackers to execute arb…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3314

Published Jul 25, 2008

ZDaemon 1.08.07 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted type 6 command, which triggers a NULL pointer dereference.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3286

Published Jul 24, 2008

SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3287

Published Jul 24, 2008

retroclient.exe in EMC Dantz Retrospect Backup Client 7.5.116 allows remote attackers to cause a denial of service (daemon crash) via malformed packets to TCP port 497, which trig…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3187

Published Jul 21, 2008

zypp-refresh-patches in zypper in SUSE openSUSE 10.2, 10.3, and 11.0 does not ask the user before accepting repository keys, which allows remote repositories to cause a denial of…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3239

Published Jul 21, 2008

Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attacker…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 12,276-12,300 of 12,898 CVEsPage 492 of 516