CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-4399

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the CHG_DYNPG_SET_LANGUAGE parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 4 Dec 2010
    7.5
    High

    CVE-2010-4400

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter.

    Published: 4 Dec 2010
    5
    Medium

    CVE-2010-4401

    Last Modified: 11 Apr 2025

    languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

    Published: 4 Dec 2010
    5
    Medium

    CVE-2010-4403

    Last Modified: 11 Apr 2025

    The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

    Published: 4 Dec 2010
    7.5
    High

    CVE-2010-4404

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 4 Dec 2010
    7.8
    High

    CVE-2010-4398

    Last Modified: 21 Apr 2026

    Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."

    Published: 3 Dec 2010
    7.5
    High

    CVE-2010-4254

    Last Modified: 11 Apr 2025

    Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possibly execute arbitrary code, via a crafted method call.

    Published: 3 Dec 2010
    6.2
    Medium

    CVE-2010-4258

    Last Modified: 11 Apr 2025

    The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.

    Published: 3 Dec 2010
    9
    Critical

    CVE-2010-4278

    Last Modified: 11 Apr 2025

    operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an operation/agentes/networkmap action to index.php.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4282

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php or (2) the id parameter to general/pandora_help.php, and allow remote attackers to include and execute, create, modify, or delete arbitrary local files via (3) the layout parameter to operation/agentes/networkmap.php.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4283

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] parameter.

    Published: 2 Dec 2010
    10
    Critical

    CVE-2010-4279

    Last Modified: 11 Apr 2025

    The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4280

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operation/agentes/ver_agente action to ajax.php or (2) the group_id parameter in an operation/agentes/estado_agente action to index.php, related to operation/agentes/estado_agente.php.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4281

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a page parameter containing a UNC share pathname, which bypasses the check for the : (colon) character.

    Published: 2 Dec 2010
    6
    Medium

    CVE-2010-4313

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then accessing it via a direct request to the file in uploads/.

    Published: 2 Dec 2010
    5.8
    Medium

    CVE-2009-5020

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 2 Dec 2010
    9.3
    Critical

    CVE-2010-2586

    Last Modified: 11 Apr 2025

    Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Table of Contents (TOC) in a (1) NSV stream or (2) NSV file that triggers a heap-based buffer overflow.

    Published: 2 Dec 2010
    3.5
    Low

    CVE-2010-3266

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd parameter to edit_bug.aspx, (2) the bug_id parameter to edit_comment.aspx, (3) the id parameter to edit_user_permissions2.aspx, or (4) the default_name parameter to edit_customfield.aspx. NOTE: some of these details are obtained from third party information.

    Published: 2 Dec 2010
    6.5
    Medium

    CVE-2010-3267

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx, (2) the row_id parameter to delete_query.aspx, the (3) new_project or (4) us_id parameter to edit_bug.aspx, or (5) the bug_list parameter to massedit.aspx. NOTE: some of these details are obtained from third party information.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4367

    Last Modified: 11 Apr 2025

    awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server or (2) NFS server.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4368

    Last Modified: 11 Apr 2025

    awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC share pathname.

    Published: 2 Dec 2010
    6.4
    Medium

    CVE-2010-4369

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2010-4373

    Last Modified: 11 Apr 2025

    The in_mp4 plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via crafted (1) metadata or (2) albumart in an invalid MP4 file.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2010-4374

    Last Modified: 11 Apr 2025

    The in_mkv plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via a Matroska Video (MKV) file containing a string with a crafted length.

    Published: 2 Dec 2010
    9.3
    Critical

    CVE-2010-4371

    Last Modified: 11 Apr 2025

    Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box.

    Published: 2 Dec 2010
    9.3
    Critical

    CVE-2010-4372

    Last Modified: 11 Apr 2025

    Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vulnerability than CVE-2010-2586.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2010-4329

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 allows remote attackers to inject arbitrary web script or HTML via a crafted request.

    Published: 2 Dec 2010
    9.3
    Critical

    CVE-2010-4370

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI file that triggers a buffer overflow.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2008-7270

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.

    Published: 2 Dec 2010
    4.7
    Medium

    CVE-2011-0716

    Last Modified: 11 Apr 2025

    The br_multicast_add_group function in net/bridge/br_multicast.c in the Linux kernel before 2.6.38, when a certain Ethernet bridge configuration is used, allows local users to cause a denial of service (memory corruption and system crash) by sending IGMP packets to a local interface.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2010-4180

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2010-4492

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG animations.

    Published: 2 Dec 2010
    4.3
    Medium

    CVE-2010-4493

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.

    Published: 2 Dec 2010
    7.5
    High

    CVE-2008-7267

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Dec 2010
    5
    Medium

    CVE-2009-5019

    Last Modified: 11 Apr 2025

    Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/NewsPad.mdb.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4356

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in news_default.asp in Site2Nite Big Truck Broker allows remote attackers to execute arbitrary SQL commands via the txtSiteId parameter.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4357

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter.

    Published: 1 Dec 2010
    4.3
    Medium

    CVE-2010-4358

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in gb.cgi in MRCGIGUY (MCG) Guestbook 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, (3) website, and (4) message parameters.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4359

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Jurpopage 0.2.0 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4360

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in Jurpopage 0.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) note and (2) pg parameters, different vectors than CVE-2010-4359. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Dec 2010
    4.3
    Medium

    CVE-2010-4361

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in url-gateway.php in Jurpopage 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 1 Dec 2010
    6.8
    Medium

    CVE-2010-4363

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) email parameters in a showtickets action.

    Published: 1 Dec 2010
    4.3
    Medium

    CVE-2010-4364

    Last Modified: 11 Apr 2025

    DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does not include the htmLawed library, which allows remote attackers to bypass the protection mechanism for CVE-2010-4355 and conduct cross-site scripting (XSS) attacks via the (1) html content and (2) rich_editor fields. NOTE: some of these details are obtained from third party information.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4365

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in JE Ajax Event Calendar (com_jeajaxeventcalendar) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the event_id parameter in an alleventlist_more action to index.php.

    Published: 1 Dec 2010
    4.3
    Medium

    CVE-2010-4366

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2) thread_description parameters in a message.

    Published: 1 Dec 2010
    5.8
    Medium

    CVE-2008-7269

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the forward parameter in a logout action.

    Published: 1 Dec 2010
    3.5
    Low

    CVE-2010-4355

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in DaDaBIK before 4.3 beta2, when the insert or edit feature is enabled, allows remote authenticated users to inject arbitrary web script or HTML via the select_single parameter.

    Published: 1 Dec 2010
    5
    Medium

    CVE-2008-7268

    Last Modified: 11 Apr 2025

    The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in misc.php.

    Published: 1 Dec 2010
    7.5
    High

    CVE-2010-4362

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and the (2) orderBy parameter to showAlllistings.asp.

    Published: 1 Dec 2010
    6.4
    Medium

    CVE-2010-3614

    Last Modified: 11 Apr 2025

    named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY algorithm rollover, which might allow remote attackers to cause a denial of service (DNSSEC validation error) by triggering a rollover.

    Published: 1 Dec 2010