Tools / CVE Explorer
Which vulnerabilities actually matter?
Every CVE with its CVSS severity, EPSS probability of exploitation and CISA KEV status side by side, refreshed daily from NVD, FIRST and CISA — plus a plain-English verdict on whether it needs an emergency change or the normal patch cycle.
395,947 CVEs1,717 in CISA KEV17,392 with EPSS ≥ 10%25,049 with a public exploitUpdated 21 September 2026
17,392 results · page 288 of 348
| CVE | Summary | Priority | Published |
|---|---|---|---|
| CVE-2008-1089 | Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability." | HIGH 9.3EPSS 32.1% | 8 April 2008 |
| CVE-2008-1088 | Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations." | HIGH 9.3EPSS 31.9% | 8 April 2008 |
| CVE-2008-1087 | Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow… | EXPLOIT ×2 ✓HIGH 9.3EPSS 56.6% | 8 April 2008 |
| CVE-2008-1086 | The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which… | HIGH 9.3EPSS 30.5% | 8 April 2008 |
| CVE-2008-1085 | Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does… | HIGH 9.3EPSS 31.9% | 8 April 2008 |
| CVE-2008-1083 | Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF or WMF image file with a… | EXPLOIT ×3 ✓HIGH 8.1EPSS 57.1% | 8 April 2008 |
| CVE-2008-0087 | The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses. | HIGH 7.5EPSS 32.4% | 8 April 2008 |
| CVE-2008-0083 | The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary… | HIGH 9.3EPSS 30.0% | 8 April 2008 |
| CVE-2008-1697 | Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows remote attackers to execute arbitrary code via a long URI in an HTTP request processed by ovas.exe, as demonstrated by a certain… | EXPLOIT ×2 ✓HIGH 10.0EPSS 74.3% | 8 April 2008 |
| CVE-2008-1328 | Buffer overflow in the LGServer service in CA ARCserve Backup for Laptops and Desktops r11.0 through r11.5, and Suite 11.1 and 11.2, allows remote attackers to execute arbitrary code via unspecified "command arguments." | HIGH 9.3EPSS 23.6% | 7 April 2008 |
| CVE-2007-4620 | Multiple stack-based buffer overflows in Computer Associates (CA) Alert Notification Service (Alert.exe) 8.1.586.0, 8.0.450.0, and 7.1.758.0, as used in multiple CA products including Anti-Virus for the Enterprise 7.1 through r11.1 and Threat Manager… | EXPLOIT ✓HIGH 9.0EPSS 52.3% | 7 April 2008 |
| CVE-2008-1602 | Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed. | EXPLOIT ✓HIGH 10.0EPSS 67.5% | 6 April 2008 |
| CVE-2008-0311 | Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request. | EXPLOIT ✓HIGH 9.3EPSS 31.0% | 6 April 2008 |
| CVE-2008-1682 | PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1.0.2 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 26.6% | 4 April 2008 |
| CVE-2008-1611 | Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or execute arbitrary code via a long filename in a read or write request. | EXPLOIT ×3 ✓HIGH 10.0EPSS 67.6% | 1 April 2008 |
| CVE-2008-1610 | Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long mode field in a read or write request. | EXPLOIT ×3 ✓HIGH 7.5EPSS 53.9% | 1 April 2008 |
| CVE-2008-1609 | Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) website parameter to (a) forum.php, (b) headlines.php, and (c) main.php in forum/,… | EXPLOIT ×3 ✓MEDIUM 6.8EPSS 44.3% | 1 April 2008 |
| CVE-2008-1562 | The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of service (application crash) via a malformed packet, a different vulnerability than CVE-2006-5740. | EXPLOIT ✓MEDIUM 5.0EPSS 50.7% | 31 March 2008 |
| CVE-2008-1558 | Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a large streamid SDP parameter. | EXPLOIT ✓HIGH 10.0EPSS 16.8% | 31 March 2008 |
| CVE-2008-1545 | The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 7 does not restrict the dangerous Transfer-Encoding HTTP request header, which allows remote attackers to conduct HTTP request splitting and HTTP request smuggling… | MEDIUM 4.3EPSS 11.8% | 28 March 2008 |
| CVE-2008-1544 | The setRequestHeader method of the XMLHttpRequest object in Microsoft Internet Explorer 5.01, 6, and 7 does not block dangerous HTTP request headers when certain 8-bit character sequences are appended to a header name, which allows remote attackers to… | HIGH 7.1EPSS 26.3% | 28 March 2008 |
| CVE-2008-0926 | The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on client-side authentication, which allows remote attackers to bypass authentication via requests for /SOAP URIs, and cause a denial of… | EXPLOIT ✓HIGH 7.5EPSS 58.2% | 28 March 2008 |
| CVE-2008-1391 | Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1)… | EXPLOIT ✓HIGH 7.5EPSS 18.8% | 27 March 2008 |
| CVE-2008-1505 | PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the cpage parameter to index.php. | EXPLOIT ✓HIGH 7.5EPSS 46.1% | 25 March 2008 |
| CVE-2008-1502 | The _bad_protocol_once function in phpgwapi/inc/class.kses.inc.php in KSES, as used in eGroupWare before 1.4.003, Moodle before 1.8.5, and other products, allows remote attackers to bypass HTML filtering and conduct cross-site scripting (XSS) attacks… | MEDIUM 4.3EPSS 10.5% | 25 March 2008 |
| CVE-2008-1491 | Stack-based buffer overflow in the DPC Proxy server (DpcProxy.exe) in ASUS Remote Console (aka ARC or ASMB3) 2.0.0.19 and 2.0.0.24 allows remote attackers to execute arbitrary code via a long string to TCP port 623. | EXPLOIT ×2 ✓HIGH 10.0EPSS 70.1% | 25 March 2008 |
| CVE-2008-1092 | Buffer overflow in msjet40.dll before 4.0.9505.0 in Microsoft Jet Database Engine allows remote attackers to execute arbitrary code via a crafted Word file, as exploited in the wild in March 2008. | HIGH 9.3EPSS 25.9% | 25 March 2008 |
| CVE-2008-1489 | Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted MP4 RDRF box that triggers a heap-based buffer overflow, a… | EXPLOIT ✓MEDIUM 6.8EPSS 11.8% | 25 March 2008 |
| CVE-2008-1160 | ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges. | EXPLOIT ✓CRITICAL 9.8EPSS 14.8% | 25 March 2008 |
| CVE-2008-1472 | Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows… | EXPLOIT ×2 ✓HIGH 9.3EPSS 39.0% | 24 March 2008 |
| CVE-2008-0951 | Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2)… | HIGH 9.3EPSS 30.1% | 24 March 2008 |
| CVE-2008-1461 | Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename argument on the command line. | EXPLOIT ✓HIGH 7.6EPSS 11.3% | 24 March 2008 |
| CVE-2008-1289 | Multiple buffer overflows in Asterisk Open Source 1.4.x before 1.4.18.1 and 1.4.19-rc3, Open Source 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6.1, AsteriskNOW 1.0.x before 1.0.2, Appliance Developer Kit before 1.4 revision 109386, and… | EXPLOIT ✓HIGH 7.5EPSS 11.5% | 24 March 2008 |
| CVE-2008-1201 | Multiple unspecified vulnerabilities in FLA file parsing in Adobe Flash CS3 Professional, Flash Professional 8, and Flash Basic 8 on Windows allow user-assisted remote attackers to execute arbitrary code via a crafted .FLA file. | MEDIUM 6.8EPSS 19.7% | 24 March 2008 |
| CVE-2008-1416 | Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) converter.inc.php, (2) messages.inc.php, and (3) settings.inc.php in includes/. | EXPLOIT ✓MEDIUM 6.8EPSS 37.7% | 20 March 2008 |
| CVE-2008-1405 | PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute arbitrary PHP code via a URL in the admindir parameter. | EXPLOIT ✓MEDIUM 6.8EPSS 37.7% | 20 March 2008 |
| CVE-2008-0062 | KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer… | CRITICAL 9.8EPSS 10.1% | 19 March 2008 |
| CVE-2008-1368 | CRLF injection vulnerability in Microsoft Internet Explorer 5 and 6 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded CRLF (%0D%0A) before the FTP command, which causes the commands to be inserted… | MEDIUM 4.3EPSS 11.3% | 18 March 2008 |
| CVE-2008-1365 | Stack-based buffer overflow in Trend Micro OfficeScan Corporate Edition 8.0 Patch 2 build 1189 and earlier, and 7.3 Patch 3 build 1314 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long… | EXPLOIT ×2 ✓MEDIUM 6.4EPSS 51.1% | 17 March 2008 |
| CVE-2008-1358 | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY. | EXPLOIT ×2 ✓MEDIUM 6.5EPSS 57.1% | 17 March 2008 |
| CVE-2008-1157 | Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands. | HIGH 10.0EPSS 20.7% | 14 March 2008 |
| CVE-2008-1117 | Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination… | EXPLOIT ×3 ✓HIGH 10.0EPSS 69.5% | 14 March 2008 |
| CVE-2008-0533 | Multiple cross-site scripting (XSS) vulnerabilities in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to inject arbitrary… | EXPLOIT ✓MEDIUM 4.3EPSS 28.8% | 14 March 2008 |
| CVE-2008-0532 | Multiple buffer overflows in securecgi-bin/CSuserCGI.exe in User-Changeable Password (UCP) before 4.2 in Cisco Secure Access Control Server (ACS) for Windows and ACS Solution Engine allow remote attackers to execute arbitrary code via a long argument… | EXPLOIT ✓HIGH 10.0EPSS 57.1% | 14 March 2008 |
| CVE-2008-1320 | Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary code or cause a denial of service (crash) via (1) a long request to FxIAList on TCP port 6162, or (2) an SNMP request with a long… | EXPLOIT ✓HIGH 10.0EPSS 16.3% | 13 March 2008 |
| CVE-2008-1311 | The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of service (daemon hang) by uploading a file named (1) '|' (pipe), (2) '"' (quotation mark), or (3) "<>" (less than, greater than); or… | EXPLOIT ✓MEDIUM 5.0EPSS 49.2% | 12 March 2008 |
| CVE-2008-1309 | The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, RealPlayer 10.5 before build 6.0.12.1675, and RealPlayer 11 before 11.0.3 build 6.0.14.806 does not properly manage memory for the (1)… | EXPLOIT ×2 ✓HIGH 9.3EPSS 46.0% | 12 March 2008 |
| CVE-2008-1307 | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method. | EXPLOIT ✓HIGH 10.0EPSS 15.0% | 12 March 2008 |
| CVE-2008-1203 | The administrator interface for Adobe ColdFusion 8 and ColdFusion MX7 does not log failed authentication attempts, which makes it easier for remote attackers to conduct brute force attacks without detection. | HIGH 7.5EPSS 15.5% | 12 March 2008 |
| CVE-2008-0118 | Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption… | EXPLOIT ×2 ✓HIGH 9.3EPSS 34.8% | 11 March 2008 |
How to read this
CVSS measures how bad a vulnerability could be if exploited. EPSS (from FIRST) estimates the probability it will actually be exploited in the next thirty days. KEV is CISA’s list of vulnerabilities that are being exploited right now. EXPLOIT means a working exploit is published in Exploit-DB, so the technical barrier is gone. Patch KEV entries first, then anything with a public exploit or an EPSS above 10 per cent, then work down by CVSS in your normal cycle.
Data is refreshed daily from the NVD, FIRST EPSS, the CISA KEV catalogue and the Exploit-DB repository. Every record can be downloaded as JSON from its page. Our SOC uses the same table to prioritise patching for clients; the verdict on each page is the rule of thumb our analysts apply.