LiveActive security incident?Get immediate response
CVE archive

2008 CVE Archive

Browse CVE records published in 2008 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 7005 matching CVEs · Page 5 of 141.

Unknown · CVSS Not scored

CVE-2008-7293: Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, w...

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

Published Aug 9, 2011 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-7282: Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2....

Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.

Published Mar 18, 2011 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-1342: Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and Collage...

Multiple cross-site scripting (XSS) vulnerabilities in the search feature in Polymita BPM-Suite and CollagePortal allow remote attackers to inject arbitrary web script or HTML via the (1) _q and (2) lucene_index_field_value parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Mar 17, 2008 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-7271: Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Serv...

Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2) the workingSet parameter in an add action to help/advanced/workingSetManager.jsp, a different issue than CVE-2010-4647.

Published Jan 13, 2011 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-5842: Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possib...

Multiple cross-site scripting (XSS) vulnerabilities in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via vectors associated with (1) a demo application shipped with WebTransactions and possibly (2) an unspecified "dynamic application."

Published Jan 5, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-6819: win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (syst...

win32k.sys in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (system crash) via vectors related to CreateWindow, TranslateMessage, and DispatchMessage, possibly a race condition between threads, a different vulnerability than CVE-2008-1084. NOTE: some of these details are obtained from third party information.

Published Jun 1, 2009 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-4126: PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests...

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099.

Published Sep 18, 2008 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-4927: Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of ser...

Microsoft Windows Media Player (WMP) 9.0 through 11 allows user-assisted attackers to cause a denial of service (application crash) via a malformed (1) MIDI or (2) DAT file, related to "MThd Header Parsing." NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Nov 4, 2008 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-7258: The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denia...

The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages with certain long lines, and has no security impact

Published Aug 20, 2010 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-7289: IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultane...

IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-LA0007 does not properly handle the simultaneous changing of multiple passwords, which makes it easier for remote authenticated users to cause a denial of service (DB2 daemon deadlock) by making password changes that trigger updates to a DB2 password-history table.

Published Apr 21, 2011 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2008-3685: Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentu...

Directory traversal vulnerability in aws_tmxn.exe in the Admin Agent service in the server in EMC Documentum ApplicationXtender Workflow, possibly 5.40 SP1 and earlier, allows remote attackers to upload arbitrary files, and execute arbitrary code, via directory traversal sequences in requests to TCP port 2606.

Published Oct 22, 2009 · Updated Sep 16, 2024