CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2010-3822

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer during processing of Cascading Style Sheets (CSS) counter styles, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3823

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving Geolocation objects. NOTE: this might overlap CVE-2010-3415.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3824

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving SVG use elements.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3826

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of colors in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    5
    Medium

    CVE-2010-3804

    Last Modified: 11 Apr 2025

    The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of random numbers, which makes it easier for remote attackers to track a user by predicting a value, a related issue to CVE-2008-5913 and CVE-2010-3171.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3805

    Last Modified: 11 Apr 2025

    Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving WebSockets. NOTE: this may overlap CVE-2010-3254.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3809

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of inline styling, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3817

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Cascading Style Sheets (CSS) 3D transforms, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3821

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the :first-letter pseudo-element in a Cascading Style Sheets (CSS) token sequence, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3803

    Last Modified: 11 Apr 2025

    Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3808

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of editing commands, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3816

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-3820

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses uninitialized memory during processing of editable elements, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site.

    Published: 20 Nov 2010
    7.8
    High

    CVE-2010-4210

    Last Modified: 11 Apr 2025

    The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a file system that uses pseudofs.

    Published: 20 Nov 2010
    9.3
    Critical

    CVE-2010-4299

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in ZfHIPCND.exe in Novell Zenworks 7 Handheld Management (ZHM) allows remote attackers to execute arbitrary code via a crafted request to TCP port 2400.

    Published: 20 Nov 2010
    4
    Medium

    CVE-2010-4176

    Last Modified: 11 Apr 2025

    plymouth-pretrigger.sh in dracut and udev, when running on Fedora 13 and 14, sets weak permissions for the /dev/systty device file, which allows remote authenticated users to read terminal data from tty0 for local users.

    Published: 19 Nov 2010
    5
    Medium

    CVE-2010-4409

    Last Modified: 11 Apr 2025

    Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an invalid argument.

    Published: 19 Nov 2010
    5
    Medium

    CVE-2010-4301

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted ZCL packet, related to Discover Attributes.

    Published: 18 Nov 2010
    5.8
    Medium

    CVE-2010-3813

    Last Modified: 11 Apr 2025

    The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.

    Published: 18 Nov 2010
    7.5
    High

    CVE-2010-4300

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector in Wireshark 1.2.0 through 1.2.12 and 1.4.0 through 1.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an LDSS packet with a long digest line that triggers memory corruption.

    Published: 18 Nov 2010
    7.8
    High

    CVE-2010-4107

    Last Modified: 11 Apr 2025

    The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

    Published: 17 Nov 2010
    7.5
    High

    CVE-2010-4168

    Last Modified: 11 Apr 2025

    Multiple use-after-free vulnerabilities in OpenTTD 1.0.x before 1.0.5 allow (1) remote attackers to cause a denial of service (invalid write and daemon crash) by abruptly disconnecting during transmission of the map from the server, related to network/network_server.cpp; (2) remote attackers to cause a denial of service (invalid read and daemon crash) by abruptly disconnecting, related to network/network_server.cpp; and (3) remote servers to cause a denial of service (invalid read and application crash) by forcing a disconnection during the join process, related to network/network.cpp.

    Published: 17 Nov 2010
    5
    Medium

    CVE-2010-3978

    Last Modified: 11 Apr 2025

    Spree 0.11.x before 0.11.2 and 0.30.x before 0.30.0 exchanges data using JavaScript Object Notation (JSON) without a mechanism for validating requests, which allows remote attackers to obtain sensitive information via vectors involving (1) admin/products.json, (2) admin/users.json, or (3) admin/overview/get_report_data, related to a "JSON hijacking" issue.

    Published: 17 Nov 2010
    6.9
    Medium

    CVE-2010-4159

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in metadata/loader.c in Mono 2.8 and earlier allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 17 Nov 2010
    2.1
    Low

    CVE-2010-4171

    Last Modified: 11 Apr 2025

    The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unloading of arbitrary kernel modules).

    Published: 17 Nov 2010
    7.5
    High

    CVE-2010-4494

    Last Modified: 11 Apr 2025

    Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.

    Published: 17 Nov 2010
    6.8
    Medium

    CVE-2012-0864

    Last Modified: 11 Apr 2025

    Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.

    Published: 17 Nov 2010
    7.2
    High

    CVE-2010-4170

    Last Modified: 11 Apr 2025

    The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

    Published: 17 Nov 2010
    7.8
    High

    CVE-2010-4231

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 16 Nov 2010
    10
    Critical

    CVE-2010-4232

    Last Modified: 11 Apr 2025

    The web-based administration interface on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to bypass authentication via a // (slash slash) at the beginning of a URI, as demonstrated by the //system.html URI.

    Published: 16 Nov 2010
    10
    Critical

    CVE-2010-4233

    Last Modified: 11 Apr 2025

    The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it easier for remote attackers to obtain access via the TELNET interface.

    Published: 16 Nov 2010
    7.8
    High

    CVE-2010-4234

    Last Modified: 11 Apr 2025

    The web server on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to cause a denial of service (device reboot) via a large number of requests in a short time interval.

    Published: 16 Nov 2010
    7.5
    High

    CVE-2010-4268

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Pulse Infotech Flip Wall (com_flipwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Published: 16 Nov 2010
    7.5
    High

    CVE-2010-4269

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action.

    Published: 16 Nov 2010
    7.5
    High

    CVE-2010-4271

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Nov 2010
    4.4
    Medium

    CVE-2010-4274

    Last Modified: 11 Apr 2025

    reset_diragent_keys in the Common agent in IBM Systems Director 6.2.0 has 754 permissions, which allows local users to gain privileges by leveraging system group membership.

    Published: 16 Nov 2010
    9.3
    Critical

    CVE-2010-4230

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in a certain ActiveX control for the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 allows remote attackers to execute arbitrary code via a long string in the first argument to the connect method.

    Published: 16 Nov 2010
    5
    Medium

    CVE-2010-4270

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the nBill (com_netinvoice) component before 2.0.9 standard edition, 2.0.10 lite edition, and 1.2_10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in unspecified vectors related to (1) administrator/components/com_nbill/admin.nbill.php, (2) components/com_nbill/nbill.php, (3) administrator/components/com_netinvoice/admin.netinvoice.php, or (4) components/com_netinvoice/netinvoice.php, as exploited in the wild in November 2010.

    Published: 16 Nov 2010
    7.5
    High

    CVE-2010-4273

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in imoveis.php in DescargarVista ACC IMoveis 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Nov 2010
    4
    Medium

    CVE-2010-4011

    Last Modified: 11 Apr 2025

    Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue."

    Published: 16 Nov 2010
    6.5
    Medium

    CVE-2010-4215

    Last Modified: 11 Apr 2025

    UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup.

    Published: 16 Nov 2010
    7.5
    High

    CVE-2010-4272

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Pulse Infotech Sponsor Wall (com_sponsorwall) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter to index.php.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-4010

    Last Modified: 11 Apr 2025

    Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document.

    Published: 16 Nov 2010
    7.1
    High

    CVE-2010-1844

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Image Capture in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (memory consumption and system crash) via a crafted image.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-1845

    Last Modified: 11 Apr 2025

    ImageIO in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PSD image.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-1846

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RAW image.

    Published: 16 Nov 2010
    4.9
    Medium

    CVE-2010-1847

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform memory management associated with terminal devices, which allows local users to cause a denial of service (system crash) via unspecified vectors.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-3785

    Last Modified: 11 Apr 2025

    Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Office document.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-3786

    Last Modified: 11 Apr 2025

    QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file.

    Published: 16 Nov 2010
    6.8
    Medium

    CVE-2010-3787

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 image.

    Published: 16 Nov 2010