CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-4109

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file.

    Published: 8 Dec 2010
    6.8
    Medium

    CVE-2010-4108

    Last Modified: 11 Apr 2025

    HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows remote authenticated users to cause a denial of service via unspecified vectors.

    Published: 8 Dec 2010
    6.8
    Medium

    CVE-2010-4500

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) subject, and (4) message parameters in a sendmess action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Dec 2010
    4.3
    Medium

    CVE-2010-4480

    Last Modified: 11 Apr 2025

    error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "@" characters, as demonstrated using "[a@url@page]".

    Published: 8 Dec 2010
    3.3
    Low

    CVE-2010-4648

    Last Modified: 11 Apr 2025

    The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.

    Published: 8 Dec 2010
    6.9
    Medium

    CVE-2010-4649

    Last Modified: 11 Apr 2025

    Integer overflow in the ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large value of a certain structure member.

    Published: 8 Dec 2010
    5
    Medium

    CVE-2011-0752

    Last Modified: 11 Apr 2025

    The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.

    Published: 8 Dec 2010
    7.8
    High

    CVE-2010-4661

    Last Modified: 21 Nov 2024

    udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.

    Published: 8 Dec 2010
    2.1
    Low

    CVE-2011-1044

    Last Modified: 11 Apr 2025

    The ib_uverbs_poll_cq function in drivers/infiniband/core/uverbs_cmd.c in the Linux kernel before 2.6.37 does not initialize a certain response buffer, which allows local users to obtain potentially sensitive information from kernel memory via vectors that cause this buffer to be only partially filled, a different vulnerability than CVE-2010-4649.

    Published: 8 Dec 2010
    2.6
    Low

    CVE-2010-4265

    Last Modified: 11 Apr 2025

    The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch. NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier.

    Published: 8 Dec 2010
    5
    Medium

    CVE-2010-4698

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the GD extension in PHP before 5.2.15 and 5.3.x before 5.3.4 allows context-dependent attackers to cause a denial of service (application crash) via a large number of anti-aliasing steps in an argument to the imagepstext function.

    Published: 8 Dec 2010
    4.3
    Medium

    CVE-2010-4491

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.

    Published: 7 Dec 2010
    4.3
    Medium

    CVE-2010-4485

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which allows remote attackers to cause a denial of service (reduced usability and possible application crash) via a crafted web site.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4484

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4482

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the pop-up blocker via unknown vectors.

    Published: 7 Dec 2010
    4.3
    Medium

    CVE-2010-4483

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive video data via a crafted web site.

    Published: 7 Dec 2010
    9.3
    Critical

    CVE-2010-4486

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to history handling.

    Published: 7 Dec 2010
    7.5
    High

    CVE-2010-4487

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows remote attackers to have an unspecified impact via a "dangerous file."

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4488

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 7 Dec 2010
    4.3
    Medium

    CVE-2010-4489

    Last Modified: 11 Apr 2025

    libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video. NOTE: this vulnerability exists because of a regression.

    Published: 7 Dec 2010
    9.3
    Critical

    CVE-2010-4490

    Last Modified: 11 Apr 2025

    Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via malformed video content that triggers an indexing error.

    Published: 7 Dec 2010
    6
    Medium

    CVE-2010-4257

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4260

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka (1) "bb #2358" and (2) "bb #2396."

    Published: 7 Dec 2010
    7.5
    High

    CVE-2010-4261

    Last Modified: 11 Apr 2025

    Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 7 Dec 2010
    4.3
    Medium

    CVE-2010-4412

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.

    Published: 7 Dec 2010
    6.8
    Medium

    CVE-2010-4330

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter to index.php.

    Published: 7 Dec 2010
    4.3
    Medium

    CVE-2010-4246

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182.

    Published: 7 Dec 2010
    7.5
    High

    CVE-2010-4479

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document, aka "bb #2380," a different vulnerability than CVE-2010-4260.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4051

    Last Modified: 11 Apr 2025

    The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."

    Published: 7 Dec 2010
    7.8
    High

    CVE-2010-4345

    Last Modified: 21 Apr 2026

    Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

    Published: 7 Dec 2010
    9.8
    Critical

    CVE-2010-4344

    Last Modified: 21 Apr 2026

    Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-3616

    Last Modified: 11 Apr 2025

    ISC DHCP server 4.2 before 4.2.0-P2, when configured to use failover partnerships, allows remote attackers to cause a denial of service (communications-interrupted state and DHCP client service loss) by connecting to a port that is only intended for a failover peer, as demonstrated by a Nagios check_tcp process check to TCP port 520.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2011-1467

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument, a related issue to CVE-2010-4409.

    Published: 7 Dec 2010
    5
    Medium

    CVE-2010-4052

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

    Published: 7 Dec 2010
    Unknown

    CVE-2010-4510

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-4150. Reason: This candidate is a duplicate of CVE-2010-4150. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2010-4150 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Dec 2010
    7.2
    High

    CVE-2010-4296

    Last Modified: 11 Apr 2025

    vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 does not properly load libraries, which allows host OS users to gain privileges via vectors involving shared object files.

    Published: 6 Dec 2010
    9.3
    Critical

    CVE-2010-4294

    Last Modified: 11 Apr 2025

    The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548 on Windows, VMware Player 2.5.x before 2.5.5 build 246459 and 3.x before 3.1.2 build 301548 on Windows, and VMware Server 2.x on Windows does not properly validate an unspecified size field, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted video file.

    Published: 6 Dec 2010
    6.9
    Medium

    CVE-2010-4295

    Last Modified: 11 Apr 2025

    Race condition in the mounting process in vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.2 on Linux, and VMware Fusion 3.1.x before 3.1.2 build 332101 allows host OS users to gain privileges via vectors involving temporary files.

    Published: 6 Dec 2010
    7.2
    High

    CVE-2010-4297

    Last Modified: 11 Apr 2025

    The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548; VMware Player 2.5.x before 2.5.5 build 328052 and 3.1.x before 3.1.2 build 301548; VMware Server 2.0.2; VMware Fusion 2.x before 2.0.8 build 328035 and 3.1.x before 3.1.2 build 332101; VMware ESXi 3.5, 4.0, and 4.1; and VMware ESX 3.0.3, 3.5, 4.0, and 4.1 allows host OS users to gain privileges on the guest OS via unspecified vectors, related to a "command injection" issue.

    Published: 6 Dec 2010
    4.3
    Medium

    CVE-2010-4411

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists because of an incomplete fix for CVE-2010-2761.

    Published: 6 Dec 2010
    6.8
    Medium

    CVE-2010-3449

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1; and Apache Continuum 1.3.6, 1.4.0, and 1.1 through 1.2.3.1; allows remote attackers to hijack the authentication of administrators for requests that modify credentials.

    Published: 6 Dec 2010
    6.8
    Medium

    CVE-2010-4408

    Last Modified: 11 Apr 2025

    Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

    Published: 6 Dec 2010
    5
    Medium

    CVE-2010-2639

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and "concurrency issues."

    Published: 6 Dec 2010
    4
    Medium

    CVE-2010-4334

    Last Modified: 11 Apr 2025

    The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, which allows remote attackers to bypass intended certificate restrictions.

    Published: 6 Dec 2010
    6.8
    Medium

    CVE-2010-2793

    Last Modified: 11 Apr 2025

    Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of the ImpersonateNamedPipeClient function.

    Published: 6 Dec 2010
    5
    Medium

    CVE-2013-4350

    Last Modified: 11 Apr 2025

    The IPv6 SCTP implementation in net/sctp/ipv6.c in the Linux kernel through 3.11.1 uses data structures and function calls that do not trigger an intended configuration of IPsec encryption, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 6 Dec 2010
    4.3
    Medium

    CVE-2010-4402

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) firstname, (2) lastname, (3) website, (4) aim, (5) yahoo, (6) jabber, (7) about, (8) pass1, and (9) pass2 parameters in a register action.

    Published: 4 Dec 2010
    4.3
    Medium

    CVE-2010-4405

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Dec 2010
    6.8
    Medium

    CVE-2010-4406

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in gallery.php in Brunetton LittlePhpGallery 1.0.2, when magic_quotes_gpc is disabled, allows remote attackers to list, include, and execute arbitrary local files via a ..// (dot dot slash slash) in the repertoire parameter.

    Published: 4 Dec 2010
    4.3
    Medium

    CVE-2010-4407

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlGuest 1.1c-patched allow remote attackers to inject arbitrary web script or HTML via the (1) nome (nickname), (2) messaggio (message), and (3) link (homepage) parameters.

    Published: 4 Dec 2010