VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 20 hours ago
Reset
More filters (2)
Columns
Published from 2008-01-01Published to 2008-12-31
Overview 121 matches, all in RASP scope · 9 protected · 0 KEV · 14 public PoC · 0 CISA SSVC · 5 EPSS ≥ 0.5 · 0 disputed
121matches, all in RASP scope 9protected7.4% 0KEV0.0% 14public PoC11.6% 0CISA SSVC0.0% 5EPSS ≥ 0.54.1% 0disputed0.0%
Critical 0 0.0% High 46 38.0% Medium 69 57.0% Low 6 5.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 7 5.8% Rule in development 0 0.0% Mitigation candidate 9 7.4% No exploit published 7 5.8% No fix identified 96 79.3% Mitigated by environment configuration 2 1.7% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 9 7.4% not blocked 112 92.6% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 13 10.7% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 108 89.3%
split by peak 34 / month
Unknown: 0None: 0Low: 6Medium: 69High: 46Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 2No fix identified: 96No exploit published: 7Mitigation candidate: 9Rule in development: 0Protected by RASP: 7 unrecorded: 0not established: 0not blocked: 112blocked by ARMR today: 9 No public exploit: 108Forecast only: 0Proof of concept only: 0Working exploit published: 13Exploited in the wild: 0 January 2008: 9 CVEs February 2008: 8 CVEs March 2008: 13 CVEs April 2008: 10 CVEs May 2008: 2 CVEs June 2008: 3 CVEs July 2008: 34 CVEs August 2008: 3 CVEs September 2008: 2 CVEs October 2008: 14 CVEs November 2008: 1 CVE December 2008: 22 CVEs
Jan 08Feb 08Mar 08Apr 08May 08Jun 08Jul 08Aug 08Sep 08Oct 08Nov 08Dec 08
121 matches CSV JSON ‹ prev page 2 of 2 next ›
CVE Severity Published Status Exploitation Description
CVE-2008-1190 High 2008-03-06 No fix identified No public exploit Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the "fourth" issue.
CVE-2008-1187 Medium 2008-03-06 No fix identified No public exploit Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.
CVE-2008-1186 High 2008-03-06 No fix identified No public exploit Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka "the second issue."
CVE-2008-1185 High 2008-03-06 No fix identified No public exploit Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka "the first issue."
CVE-2008-1045 Medium 2008-02-27 Mitigation candidate Working exploit published Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.
CVE-2008-0741 High 2008-02-13 No fix identified No public exploit Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.
CVE-2008-0740 Low 2008-02-13 No fix identified No public exploit IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.
CVE-2008-0002 Medium 2008-02-12 No exploit published No public exploit Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
CVE-2007-6286 Medium 2008-02-12 No exploit published No public exploit Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
CVE-2007-5333 Medium 2008-02-12 Mitigation candidate Working exploit published Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.
CVE-2008-0657 High 2008-02-07 No fix identified No public exploit Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.
CVE-2008-0628 High 2008-02-06 Protected by RASP No public exploit The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
CVE-2008-0389 High 2008-01-23 No fix identified No public exploit Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.
CVE-2008-0128 Medium 2008-01-23 No fix identified No public exploit The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.
CVE-2008-0349 High 2008-01-17 No fix identified No public exploit Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.
CVE-2008-0348 High 2008-01-17 No fix identified No public exploit Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.
CVE-2008-0347 High 2008-01-17 No fix identified No public exploit Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.
CVE-2008-0346 High 2008-01-17 No fix identified No public exploit Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.
CVE-2007-6679 High 2008-01-10 No fix identified No public exploit Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to "security concerns with monitor role users." NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.
CVE-2007-0012 Medium 2008-01-09 No fix identified No public exploit Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.
CVE-2007-6672 Medium 2008-01-08 Protected by RASP No public exploit Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.
‹ prev page 2 of 2 next ›