CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2010-4603

    Last Modified: 11 Apr 2025

    IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 does not prevent modification of back-reference fields, which allows remote authenticated users to interfere with intended record relationships, and possibly cause a denial of service (loop) or have unspecified other impact, by (1) adding or (2) removing a back reference.

    Published: 29 Dec 2010
    10
    Critical

    CVE-2010-4601

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.

    Published: 29 Dec 2010
    4
    Medium

    CVE-2010-4602

    Last Modified: 11 Apr 2025

    The Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1 allows remote authenticated users to bypass "restricted user" limitations, and read arbitrary records, via a modified record number in the URL for a RECORD action, as demonstrated by a modified bookmark.

    Published: 29 Dec 2010
    7.2
    High

    CVE-2010-4604

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.2.10, and 6.1.x before 6.1.3.1 on Unix and Linux allows local users to gain privileges by specifying a long LANG environment variable, and then sending a request over a pipe.

    Published: 29 Dec 2010
    7.5
    High

    CVE-2010-4606

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Space Management client in the Hierarchical Storage Management (HSM) component in IBM Tivoli Storage Manager (TSM) 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows remote attackers to execute arbitrary commands via unknown vectors, related to a "script execution vulnerability."

    Published: 29 Dec 2010
    6.9
    Medium

    CVE-2010-4527

    Last Modified: 11 Apr 2025

    The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

    Published: 29 Dec 2010
    4
    Medium

    CVE-2010-4528

    Last Modified: 11 Apr 2025

    directconn.c in the MSN protocol plugin in libpurple 2.7.6 through 2.7.8 in Pidgin before 2.7.9 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a short p2pv2 packet in a DirectConnect (aka direct connection) session.

    Published: 26 Dec 2010
    9.3
    Critical

    CVE-2010-4588

    Last Modified: 11 Apr 2025

    The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary code via a crafted argument to the ReleaseContext method, a different vector than CVE-2010-3973, possibly an untrusted pointer dereference.

    Published: 23 Dec 2010
    10
    Critical

    CVE-2010-4597

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows remote attackers to execute arbitrary code via a long string in the second argument.

    Published: 23 Dec 2010
    5
    Medium

    CVE-2010-4598

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file_name parameter in an open request.

    Published: 23 Dec 2010
    6.9
    Medium

    CVE-2010-4599

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Ecava IntegraXor 3.6.4000.0 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Dec 2010
    9.3
    Critical

    CVE-2010-3973

    Last Modified: 11 Apr 2025

    The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

    Published: 23 Dec 2010
    4.3
    Medium

    CVE-2010-4520

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Views module 6.x before 6.x-2.11 for Drupal allow remote attackers to inject arbitrary web script or HTML via (1) a URL or (2) an aggregator feed title.

    Published: 23 Dec 2010
    10
    Critical

    CVE-2010-3972

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information.

    Published: 23 Dec 2010
    6.8
    Medium

    CVE-2010-4519

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Views UI implementation in the Views module 5.x before 5.x-1.8 and 6.x before 6.x-2.11 for Drupal allow remote attackers to hijack the authentication of administrators for requests that (1) enable all Views or (2) disable all Views.

    Published: 23 Dec 2010
    4.3
    Medium

    CVE-2010-4521

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Views module 6.x before 6.x-2.12 for Drupal allows remote attackers to inject arbitrary web script or HTML via a page path.

    Published: 23 Dec 2010
    Unknown

    CVE-2011-0171

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Dec 2010
    Unknown

    CVE-2011-0236

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Dec 2010
    Unknown

    CVE-2011-0239

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Dec 2010
    Unknown

    CVE-2011-0243

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 23 Dec 2010
    5
    Medium

    CVE-2010-2644

    Last Modified: 11 Apr 2025

    IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to perform governance actions via unspecified API requests to an EJB interface.

    Published: 22 Dec 2010
    5
    Medium

    CVE-2010-3268

    Last Modified: 11 Apr 2025

    The GetStringAMSHandler function in prgxhndl.dll in hndlrsvc.exe in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (AMS), as used in Symantec Antivirus Corporate Edition 10.1.4.4010 on Windows 2000 SP4 and Symantec Endpoint Protection before 11.x, does not properly validate the CommandLine field of an AMS request, which allows remote attackers to cause a denial of service (application crash) via a crafted request.

    Published: 22 Dec 2010
    7.5
    High

    CVE-2010-3905

    Last Modified: 11 Apr 2025

    The password reset feature in the administrator interface for Eucalyptus 2.0.0 and 2.0.1 does not perform authentication, which allows remote attackers to gain privileges by sending password reset requests for other users.

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-3971

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-4113

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in HP Power Manager (HPPM) before 4.3.2 allows remote attackers to execute arbitrary code via a long Login variable to the management web server.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4114

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Discovery & Dependency Mapping Inventory (DDMI) 2.5x, 7.5x, and 7.6x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-4573

    Last Modified: 11 Apr 2025

    The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4589

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4592

    Last Modified: 11 Apr 2025

    The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows remote attackers to cause a denial of service (memory consumption and daemon crash) by making many TCP connection attempts.

    Published: 22 Dec 2010
    5
    Medium

    CVE-2010-4595

    Last Modified: 11 Apr 2025

    The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header.

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-3970

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."

    Published: 22 Dec 2010
    5.7
    Medium

    CVE-2010-4110

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or cause a denial of service via unknown vectors.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4277

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lembedded-video.php in the Embedded Video plugin 4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the content parameter to wp-admin/post.php.

    Published: 22 Dec 2010
    4.4
    Medium

    CVE-2010-4591

    Last Modified: 11 Apr 2025

    The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain mismatch.

    Published: 22 Dec 2010
    4
    Medium

    CVE-2010-4593

    Last Modified: 11 Apr 2025

    The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4594

    Last Modified: 11 Apr 2025

    The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTTP-AS hang) by making many connection requests that trigger "queue size delta errors," related to a "timing hole" issue.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4111

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Dec 2010
    5
    Medium

    CVE-2010-4112

    Last Modified: 11 Apr 2025

    HP Insight Management Agents before 8.6 allows remote attackers to obtain sensitive information via an unspecified request that triggers disclosure of the full path.

    Published: 22 Dec 2010
    4.3
    Medium

    CVE-2010-4590

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Dec 2010
    10
    Critical

    CVE-2010-4586

    Last Modified: 11 Apr 2025

    The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, possibly a related issue to CVE-2010-4508.

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-4587

    Last Modified: 11 Apr 2025

    Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assisted remote attackers to have an unspecified impact via a crafted module.

    Published: 22 Dec 2010
    6.1
    Medium

    CVE-2009-2189

    Last Modified: 11 Apr 2025

    The ICMPv6 implementation on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 does not limit the rate of (1) Router Advertisement and (2) Neighbor Discovery packets, which allows remote attackers to cause a denial of service (resource consumption and device restart) by sending many packets.

    Published: 22 Dec 2010
    2.6
    Low

    CVE-2010-0039

    Last Modified: 11 Apr 2025

    The Application-Level Gateway (ALG) on the Apple Time Capsule, AirPort Extreme Base Station, and AirPort Express Base Station with firmware before 7.5.2 modifies PORT commands in incoming FTP traffic, which allows remote attackers to use the device's IP address for arbitrary intranet TCP traffic by leveraging write access to an intranet FTP server.

    Published: 22 Dec 2010
    7.5
    High

    CVE-2010-4332

    Last Modified: 11 Apr 2025

    Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.

    Published: 22 Dec 2010
    7.5
    High

    CVE-2010-4333

    Last Modified: 11 Apr 2025

    Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrative privileges via arbitrary values of the auser and apass cookies.

    Published: 22 Dec 2010
    5
    Medium

    CVE-2010-4579

    Last Modified: 11 Apr 2025

    Opera before 11.00 does not properly constrain dialogs to appear on top of rendered documents, which makes it easier for remote attackers to trick users into interacting with a crafted web site that spoofs the (1) security information dialog or (2) download dialog.

    Published: 22 Dec 2010
    5
    Medium

    CVE-2010-4580

    Last Modified: 11 Apr 2025

    Opera before 11.00 does not clear WAP WML form fields after manual navigation to a new web site, which allows remote attackers to obtain sensitive information via an input field that has the same name as an input field on a previously visited web site.

    Published: 22 Dec 2010
    9.3
    Critical

    CVE-2010-2590

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion property value.

    Published: 22 Dec 2010
    3.5
    Low

    CVE-2010-4275

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) name or (2) descr parameter in an (a) update_usergroup or a (b) store_nas action to admin.php.

    Published: 22 Dec 2010
    2.6
    Low

    CVE-2010-4583

    Last Modified: 11 Apr 2025

    Opera before 11.00, when Opera Turbo is enabled, does not display a page's security indication, which makes it easier for remote attackers to spoof trusted content via a crafted web site.

    Published: 22 Dec 2010