VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 19 hours ago
Reset
More filters (2)
Columns
Published from 2008-01-01Published to 2008-12-31
Overview 7 matches, all in RASP scope, all protected · 0 KEV · 4 public PoC · 0 CISA SSVC · 3 EPSS ≥ 0.5 · 0 disputed
7matches, all in RASP scope, all protected 0KEV0.0% 4public PoC57.1% 0CISA SSVC0.0% 3EPSS ≥ 0.542.9% 0disputed0.0%
Critical 0 0.0% High 3 42.9% Medium 4 57.1% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 7 100.0% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 0 0.0% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 7 100.0% not blocked 0 0.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 4 57.1% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 3 42.9%
split by peak 2 / month
Unknown: 0None: 0Low: 0Medium: 4High: 3Critical: 0 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 0No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 7 unrecorded: 0not established: 0not blocked: 0blocked by ARMR today: 7 No public exploit: 3Forecast only: 0Proof of concept only: 0Working exploit published: 4Exploited in the wild: 0 January 2008: 1 CVE February 2008: 1 CVE March 2008: 1 CVE April 2008: 0 CVEs May 2008: 0 CVEs June 2008: 0 CVEs July 2008: 1 CVE August 2008: 2 CVEs September 2008: 0 CVEs October 2008: 0 CVEs November 2008: 0 CVEs December 2008: 1 CVE
Jan 08Feb 08Mar 08Apr 08May 08Jun 08Jul 08Aug 08Sep 08Oct 08Nov 08Dec 08
7 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2008-5353 High 2008-12-05 Protected by RASP Working exploit published The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by "deserializing Calendar objects".
CVE-2008-2938 Medium 2008-08-13 Protected by RASP Working exploit published Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370. NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.
CVE-2008-2370 Medium 2008-08-04 Protected by RASP Working exploit published Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
CVE-2008-3112 High 2008-07-09 Protected by RASP No public exploit Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.
CVE-2008-1301 Medium 2008-03-12 Protected by RASP Working exploit published Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.
CVE-2008-0628 High 2008-02-06 Protected by RASP No public exploit The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the "external general entities" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.
CVE-2007-6672 Medium 2008-01-08 Protected by RASP No public exploit Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.