CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2010-4722

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

    Published: 3 Feb 2011
    4.3
    Medium

    CVE-2011-0451

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Feb 2011
    10
    Critical

    CVE-2011-0354

    Last Modified: 11 Apr 2025

    The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecified login method.

    Published: 3 Feb 2011
    7.5
    High

    CVE-2011-0720

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.

    Published: 3 Feb 2011
    6.8
    Medium

    CVE-2011-0538

    Last Modified: 11 Apr 2025

    Wireshark 1.2.0 through 1.2.14, 1.4.0 through 1.4.3, and 1.5.0 frees an uninitialized pointer during processing of a .pcap file in the pcap-ng format, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed file.

    Published: 3 Feb 2011
    7.5
    High

    CVE-2011-0778

    Last Modified: 11 Apr 2025

    Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 3 Feb 2011
    9.3
    Critical

    CVE-2010-3041

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3042, CVE-2010-3043, and CVE-2010-3044.

    Published: 2 Feb 2011
    9.3
    Critical

    CVE-2010-3269

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to use of a function pointer in a callback mechanism.

    Published: 2 Feb 2011
    6.8
    Medium

    CVE-2010-3270

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted .atp file and then disconnecting from a meeting. NOTE: since this is a site-specific issue with no expected action for consumers, it might be REJECTed.

    Published: 2 Feb 2011
    6.5
    Medium

    CVE-2011-0757

    Last Modified: 11 Apr 2025

    IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows remote authenticated users to execute non-DDL statements by leveraging previous possession of this authority.

    Published: 2 Feb 2011
    9.3
    Critical

    CVE-2010-3043

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3044.

    Published: 2 Feb 2011
    9.3
    Critical

    CVE-2010-3042

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, a different vulnerability than CVE-2010-3041, CVE-2010-3043, and CVE-2010-3044.

    Published: 2 Feb 2011
    9.3
    Critical

    CVE-2010-3044

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .wrf or (2) .arf file, related to atas32.dll, a different vulnerability than CVE-2010-3041, CVE-2010-3042, and CVE-2010-3043.

    Published: 2 Feb 2011
    4.4
    Medium

    CVE-2011-0754

    Last Modified: 11 Apr 2025

    The SplFileInfo::getType function in the Standard PHP Library (SPL) extension in PHP before 5.3.4 on Windows does not properly detect symbolic links, which might make it easier for local users to conduct symlink attacks by leveraging cross-platform differences in the stat structure, related to lack of a FILE_ATTRIBUTE_REPARSE_POINT check.

    Published: 2 Feb 2011
    4.3
    Medium

    CVE-2010-3854

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Feb 2011
    5
    Medium

    CVE-2010-3930

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE-2010-1427.

    Published: 2 Feb 2011
    6.8
    Medium

    CVE-2010-4652

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the sql_prepare_where function (contrib/mod_sql.c) in ProFTPD before 1.3.3d, when mod_sql is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted username containing substitution tags, which are not properly handled during construction of an SQL query.

    Published: 2 Feb 2011
    10
    Critical

    CVE-2011-0276

    Last Modified: 11 Apr 2025

    HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servlet.HelpManagerServlet class.

    Published: 2 Feb 2011
    4.3
    Medium

    CVE-2011-0738

    Last Modified: 11 Apr 2025

    MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.

    Published: 2 Feb 2011
    6.8
    Medium

    CVE-2011-0739

    Last Modified: 11 Apr 2025

    The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address.

    Published: 2 Feb 2011
    10
    Critical

    CVE-2011-0742

    Last Modified: 11 Apr 2025

    Buffer overflow in ZfHIPCND.exe in Novell ZENworks Handheld Management 7.0 allows remote attackers to execute arbitrary code via a crafted IP Conduit packet to TCP port 2400.

    Published: 2 Feb 2011
    6.8
    Medium

    CVE-2011-0900

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a .RDP file with a long hostname argument.

    Published: 2 Feb 2011
    4.3
    Medium

    CVE-2011-0741

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ModX Evolution before 1.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) installer or (2) image editor.

    Published: 2 Feb 2011
    6.8
    Medium

    CVE-2011-0901

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the tsc_launch_remote function (src/support.c) in Terminal Server Client (tsclient) 0.150, and possibly other versions, allow user-assisted remote attackers to execute arbitrary code via a .RDP file with a long (1) username, (2) password, or (3) domain argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Feb 2011
    8.5
    High

    CVE-2010-3719

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified parameters to the ScheduleTask method.

    Published: 2 Feb 2011
    7.5
    High

    CVE-2010-3929

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.

    Published: 2 Feb 2011
    4.3
    Medium

    CVE-2011-0740

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.

    Published: 2 Feb 2011
    5.7
    Medium

    CVE-2011-1478

    Last Modified: 11 Apr 2025

    The napi_reuse_skb function in net/core/dev.c in the Generic Receive Offload (GRO) implementation in the Linux kernel before 2.6.38 does not reset the values of certain structure members, which might allow remote attackers to cause a denial of service (NULL pointer dereference) via a malformed VLAN frame.

    Published: 2 Feb 2011
    7.5
    High

    CVE-2010-4719

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Published: 1 Feb 2011
    7.5
    High

    CVE-2010-4721

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Feb 2011
    7.5
    High

    CVE-2010-4720

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component before 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the view item page.

    Published: 1 Feb 2011
    4.3
    Medium

    CVE-2010-4718

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Lyftenbloggie (com_lyftenbloggie) component 1.1.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) tag and (2) category parameters to index.php.

    Published: 1 Feb 2011
    Unknown

    CVE-2009-0189

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1012. Reason: This candidate is a reservation duplicate of CVE-2009-1012. Notes: All CVE users should reference CVE-2009-1012 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Feb 2011
    Unknown

    CVE-2009-0190

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2009-1016. Reason: This candidate is a reservation duplicate of CVE-2009-1016. Notes: All CVE users should reference CVE-2009-1016 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Feb 2011
    7.5
    High

    CVE-2011-0731

    Last Modified: 11 Apr 2025

    Buffer overflow in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP7, and 9.7 before FP3 on Linux, UNIX, and Windows allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 1 Feb 2011
    10
    Critical

    CVE-2011-0732

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim Fix 9, have unknown impact and attack vectors, related to "security vulnerabilities of Websphere Application Server bundled within" and "many internal defects and APARs."

    Published: 1 Feb 2011
    5.3
    Medium

    CVE-2011-0737

    Last Modified: 11 Apr 2025

    Adobe ColdFusion 9.0.1 CHF1 and earlier allows remote attackers to obtain sensitive information via an id=- query to a .cfm file, which reveals the installation path in an error message. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure

    Published: 1 Feb 2011
    6.4
    Medium

    CVE-2011-0321

    Last Modified: 11 Apr 2025

    librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility of a spoofed localhost source IP address, which allows remote attackers to (1) register or (2) unregister RPC services, and consequently cause a denial of service or obtain sensitive information from interprocess communication, via crafted UDP packets containing service commands.

    Published: 1 Feb 2011
    4.3
    Medium

    CVE-2011-0735

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via vectors involving a "tag script."

    Published: 1 Feb 2011
    5.3
    Medium

    CVE-2011-0736

    Last Modified: 11 Apr 2025

    Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure

    Published: 1 Feb 2011
    4.3
    Medium

    CVE-2011-0733

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.

    Published: 1 Feb 2011
    4.3
    Medium

    CVE-2011-0734

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.

    Published: 1 Feb 2011
    6.5
    Medium

    CVE-2010-4015

    Last Modified: 11 Apr 2025

    Buffer overflow in the gettoken function in contrib/intarray/_int_bool.c in the intarray array module in PostgreSQL 9.0.x before 9.0.3, 8.4.x before 8.4.7, 8.3.x before 8.3.14, and 8.2.x before 8.2.20 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via integers with a large number of digits to unspecified functions.

    Published: 1 Feb 2011
    6.8
    Medium

    CVE-2011-0025

    Last Modified: 11 Apr 2025

    IcedTea 1.7 before 1.7.8, 1.8 before 1.8.5, and 1.9 before 1.9.5 does not properly verify signatures for JAR files that (1) are "partially signed" or (2) signed by multiple entities, which allows remote attackers to trick users into executing code that appears to come from a trusted source.

    Published: 1 Feb 2011
    5
    Medium

    CVE-2010-4476

    Last Modified: 11 Apr 2025

    The Double.parseDouble method in Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier, as used in OpenJDK, Apache, JBossweb, and other products, allows remote attackers to cause a denial of service via a crafted string that triggers an infinite loop of estimations during conversion to a double-precision binary floating-point number, as demonstrated using 2.2250738585072012e-308.

    Published: 1 Feb 2011
    4.3
    Medium

    CVE-2011-0681

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) Extensions for XML implementation in Opera before 11.01 recognizes links to javascript: URLs in the -o-link property, which makes it easier for remote attackers to bypass CSS filtering via a crafted URL.

    Published: 31 Jan 2011
    9.3
    Critical

    CVE-2011-0682

    Last Modified: 11 Apr 2025

    Integer truncation error in opera.dll in Opera before 11.01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML form with a select element that contains a large number of children.

    Published: 31 Jan 2011
    4.3
    Medium

    CVE-2011-0683

    Last Modified: 11 Apr 2025

    Opera before 11.01 does not properly restrict the use of opera: URLs, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site.

    Published: 31 Jan 2011
    5
    Medium

    CVE-2011-0686

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 11.01 allows remote attackers to cause a denial of service (application crash) via unknown content on a web page, as demonstrated by vkontakte.ru.

    Published: 31 Jan 2011
    4.3
    Medium

    CVE-2011-0687

    Last Modified: 11 Apr 2025

    Opera before 11.01 does not properly implement Wireless Application Protocol (WAP) dropdown lists, which allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted WAP document.

    Published: 31 Jan 2011