CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-3593

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Health Sciences - Oracle Argus Safety component in Oracle Industry Applications 5.0, 5.0.1, 5.0.2, and 5.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Login and LDAP.

    Published: 19 Jan 2011
    6.4
    Medium

    CVE-2010-3596

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the mod_ssl component in Oracle Secure Backup 10.3.0.2 allows remote attackers to affect integrity and availability via unknown vectors.

    Published: 19 Jan 2011
    1.9
    Low

    CVE-2010-3597

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.0 allows local users to affect availability, related to Outside In Viewer SDK.

    Published: 19 Jan 2011
    7.1
    High

    CVE-2010-3598

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Import Export Utility.

    Published: 19 Jan 2011
    4.1
    Medium

    CVE-2010-4415

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to libc.

    Published: 19 Jan 2011
    5.5
    Medium

    CVE-2010-4419

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise CRM component in Oracle PeopleSoft and JDEdwards Suite 9.0 Bundle #31 and 9.1 Bundle #6 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Order Capture.

    Published: 19 Jan 2011
    3.6
    Low

    CVE-2010-4420

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 19 Jan 2011
    3.5
    Low

    CVE-2010-4425

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.3.2, 10.1.3.4.0, and 10.1.3.4.1 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2010-4426

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.0 through 8.49.29, 8.50.0 through 8.50.14, and 8.51.0 through 8.51.04 allows remote attackers to affect integrity, related to PIA Core Technology.

    Published: 19 Jan 2011
    3.5
    Low

    CVE-2010-4427

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 10.1.3.4.0, 10.1.3.4.1, and 11.1.1.3 allows remote authenticated users to affect integrity via unknown vectors related to Web Server.

    Published: 19 Jan 2011
    4.3
    Medium

    CVE-2010-3587

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Common Applications component in Oracle Applications 11.5.10.2, 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to User Management.

    Published: 19 Jan 2011
    7.8
    High

    CVE-2010-3595

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can read arbitrary files via a full pathname in the first argument to the ImportBodyText method in the EasyMail ActiveX control (emsmtp.dll).

    Published: 19 Jan 2011
    7.5
    High

    CVE-2010-3600

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and Enterprise Manager Grid Control 10.2.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this issue involves an exposed JSP script that accepts XML uploads in conjunction with NULL bytes in an unspecified parameter that allow execution of arbitrary code.

    Published: 19 Jan 2011
    6.8
    Medium

    CVE-2010-4414

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle VM VirtualBox 4.0 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Extensions.

    Published: 19 Jan 2011
    7.5
    High

    CVE-2010-4417

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Services for Beehive component in Oracle Fusion Middleware 2.0.1.0, 2.0.1.1, 2.0.1.2, 2.0.1.2.1, and 2.0.1.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that voice-servlet/prompt-qa/Index.jspf does not properly handle null (%00) bytes in the evaluation parameter that is used in a filename, which allows attackers to create a file with an executable extension and execute arbitrary JSP code.

    Published: 19 Jan 2011
    6.9
    Medium

    CVE-2010-4423

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Cluster Verify Utility component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2010-4424

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.49.0 through 8.49.29, 8.50.0 through 8.50.14, and 8.51.0 through 8.51.04 allows remote attackers to affect availability via unknown vectors related to the Security sub-component.

    Published: 19 Jan 2011
    7.8
    High

    CVE-2010-2632

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect availability. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable researcher that this is an issue in the glob implementation in libc that allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames.

    Published: 19 Jan 2011
    10
    Critical

    CVE-2010-3510

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Node Manager.

    Published: 19 Jan 2011
    9.3
    Critical

    CVE-2010-3591

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Internal Operations. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite or delete arbitrary files via a full pathname in the second argument to the DownloadSingleMessageToFile method in the EMPOP3Lib ActiveX component (empop3.dll).

    Published: 19 Jan 2011
    6.4
    Medium

    CVE-2010-3594

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Real User Experience Insight component in Oracle Enterprise Manager Grid Control 6.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Processing. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that this is SQL injection in rsynclogdird involving improper escaping of UTF-8 characters while processing log files.

    Published: 19 Jan 2011
    9.4
    Critical

    CVE-2010-3599

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can overwrite arbitrary files and execute arbitrary code via a full pathname in the first argument to the WriteJPG method in the NCSECWLib ActiveX control.

    Published: 19 Jan 2011
    4.3
    Medium

    CVE-2010-4413

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Scheduler Agent component in Oracle Database Server 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2010-4416

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle GoldenGate Veridata component in Oracle Fusion Middleware 3.0.0.4 allows remote attackers to affect availability via unknown vectors related to Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party researcher that this is a buffer overflow via a crafted XML soap request and a value that does not contain the expected 0x20 terminator character.

    Published: 19 Jan 2011
    7.5
    High

    CVE-2010-4418

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft and JDEdwards Suite 8.50.11 through 8.50.15 and 8.51GA through 8.51.05 allows remote attackers to affect confidentiality, integrity, and availability, related to PIA Core Technology.

    Published: 19 Jan 2011
    6.8
    Medium

    CVE-2010-4421

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 19 Jan 2011
    4
    Medium

    CVE-2010-4428

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft and JDEdwards Suite 9.0 Update 2010-F allows remote authenticated users to affect confidentiality via unknown vectors related to Absence Management.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0015

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly check the amount of compression in zlib-compressed data, which allows remote attackers to cause a denial of service via a large compression factor.

    Published: 19 Jan 2011
    2.1
    Low

    CVE-2011-0016

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not properly manage key data in memory, which might allow local users to obtain sensitive information by leveraging the ability to read memory that was previously used by a different process.

    Published: 19 Jan 2011
    6.8
    Medium

    CVE-2011-0427

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0490

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha makes calls to Libevent within Libevent log handlers, which might allow remote attackers to cause a denial of service (daemon crash) via vectors that trigger certain log messages.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0491

    Last Modified: 11 Apr 2025

    The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not validate a certain size value during memory allocation, which might allow remote attackers to cause a denial of service (daemon crash) via unspecified vectors, related to "underflow errors."

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0493

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha might allow remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors related to malformed router caches and improper handling of integer values.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0494

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in WebSEAL in IBM Tivoli Access Manager for e-business 5.1 before 5.1.0.39-TIV-AWS-IF0040, 6.0 before 6.0.0.25-TIV-AWS-IF0026, 6.1.0 before 6.1.0.5-TIV-AWS-IF0006, and 6.1.1 before 6.1.1-TIV-AWS-FP0001 has unspecified impact and attack vectors. NOTE: this might overlap CVE-2010-4622.

    Published: 19 Jan 2011
    5
    Medium

    CVE-2011-0492

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that trigger a certain file size, as demonstrated by the cached-descriptors.new file.

    Published: 19 Jan 2011
    7.2
    High

    CVE-2011-0521

    Last Modified: 11 Apr 2025

    The dvb_ca_ioctl function in drivers/media/dvb/ttpci/av7110_ca.c in the Linux kernel before 2.6.38-rc2 does not check the sign of a certain integer field, which allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a negative value.

    Published: 19 Jan 2011
    2.1
    Low

    CVE-2011-1159

    Last Modified: 11 Apr 2025

    acpid.c in acpid before 2.0.9 does not properly handle a situation in which a process has connected to acpid.socket but is not reading any data, which allows local users to cause a denial of service (daemon hang) via a crafted application that performs a connect system call but no read system calls.

    Published: 19 Jan 2011
    6.9
    Medium

    CVE-2011-0640

    Last Modified: 11 Apr 2025

    The default configuration of udev on Linux does not warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.

    Published: 19 Jan 2011
    7.5
    High

    CVE-2010-4166

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via (1) the filter_order parameter in a com_weblinks category action to index.php, (2) the filter_order_Dir parameter in a com_weblinks category action to index.php, or (3) the filter_order_Dir parameter in a com_messages action to administrator/index.php.

    Published: 18 Jan 2011
    4.3
    Medium

    CVE-2010-4646

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hastymail2 before 1.01 allows remote attackers to inject arbitrary web script or HTML via a crafted background attribute within a cell in a TABLE element, related to improper use of the htmLawed filter.

    Published: 18 Jan 2011
    10
    Critical

    CVE-2011-0272

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.

    Published: 18 Jan 2011
    4.3
    Medium

    CVE-2011-0486

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cognos.cgi in IBM Cognos 8 Business Intelligence (BI) 8.4.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via the pathinfo parameter.

    Published: 18 Jan 2011
    7.5
    High

    CVE-2010-4696

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Joomla! 1.5.x before 1.5.22 allow remote attackers to execute arbitrary SQL commands via the (1) filter_order or (2) filter_order_Dir parameter in a com_contact action to index.php, a different vulnerability than CVE-2010-4166. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 18 Jan 2011
    7.5
    High

    CVE-2011-0489

    Last Modified: 11 Apr 2025

    The server components in Objectivity/DB 10.0 do not require authentication for administrative commands, which allows remote attackers to modify data, obtain sensitive information, or cause a denial of service by sending requests over TCP to (1) the Lock Server or (2) the Advanced Multithreaded Server, as demonstrated by commands that are ordinarily sent by the (a) ookillls and (b) oostopams applications. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2011
    5
    Medium

    CVE-2009-5051

    Last Modified: 11 Apr 2025

    Hastymail2 before RC 8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 18 Jan 2011
    9.3
    Critical

    CVE-2011-0487

    Last Modified: 11 Apr 2025

    ICQ 7 does not verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a crafted file that is fetched through an automatic-update mechanism.

    Published: 18 Jan 2011
    10
    Critical

    CVE-2011-0488

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long request to TCP port 80.

    Published: 18 Jan 2011
    6.8
    Medium

    CVE-2010-4351

    Last Modified: 11 Apr 2025

    The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPermission method instead of throwing an exception in certain circumstances, which might allow context-dependent attackers to bypass the intended security policy by creating instances of ClassLoader.

    Published: 18 Jan 2011
    5
    Medium

    CVE-2012-0050

    Last Modified: 11 Apr 2025

    OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.

    Published: 18 Jan 2011
    7.6
    High

    CVE-2011-0020

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the pango_ft2_font_render_box_glyph function in pango/pangoft2-render.c in libpango in Pango 1.28.3 and earlier, when the FreeType2 backend is enabled, allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file, related to the glyph box for an FT_Bitmap object.

    Published: 18 Jan 2011