CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-2637

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 6.0 before 6.0.2.9 and 7.0 before 7.0.1.1 does not encrypt the username and password in the security parameters field, which allows remote attackers to obtain sensitive information by sniffing the network traffic from a .NET client application.

    Published: 12 Nov 2010
    3.3
    Low

    CVE-2010-3282

    Last Modified: 21 Nov 2024

    389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.

    Published: 12 Nov 2010
    7.8
    High

    CVE-2010-3333

    Last Modified: 22 Apr 2026

    Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."

    Published: 10 Nov 2010
    10
    Critical

    CVE-2010-3635

    Last Modified: 11 Apr 2025

    Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vulnerability."

    Published: 10 Nov 2010
    7.8
    High

    CVE-2010-2572

    Last Modified: 22 Apr 2026

    Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint 95 document, aka "PowerPoint Parsing Buffer Overflow Vulnerability."

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-2733

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Monitor in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "UAG XSS Allows EOP Vulnerability."

    Published: 10 Nov 2010
    9.3
    Critical

    CVE-2010-3334

    Last Modified: 11 Apr 2025

    Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via an Office document containing an Office Art Drawing record with crafted msofbtSp records and unspecified flags, which triggers memory corruption, aka "Office Art Drawing Records Vulnerability."

    Published: 10 Nov 2010
    9.3
    Critical

    CVE-2010-3335

    Last Modified: 11 Apr 2025

    Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "Drawing Exception Handling Vulnerability."

    Published: 10 Nov 2010
    9.3
    Critical

    CVE-2010-3336

    Last Modified: 11 Apr 2025

    Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV Vulnerability."

    Published: 10 Nov 2010
    9.3
    Critical

    CVE-2010-3337

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Office 2007 SP2 and 2010 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Insecure Library Loading Vulnerability." NOTE: this might overlap CVE-2010-3141 and CVE-2010-3142.

    Published: 10 Nov 2010
    5
    Medium

    CVE-2010-3633

    Last Modified: 11 Apr 2025

    Memory leak in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 10 Nov 2010
    5
    Medium

    CVE-2010-3634

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the edge process in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service via unknown vectors.

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-3936

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS in Signurl.asp Vulnerability."

    Published: 10 Nov 2010
    9.3
    Critical

    CVE-2010-2573

    Last Modified: 11 Apr 2025

    Integer underflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3, PowerPoint Viewer SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Integer Underflow Causes Heap Corruption Vulnerability."

    Published: 10 Nov 2010
    5.8
    Medium

    CVE-2010-2732

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the web interface in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka "UAG Redirection Spoofing Vulnerability."

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-2734

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mobile portal in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "XSS Issue on UAG Mobile Portal Website in Forefront Unified Access Gateway Vulnerability."

    Published: 10 Nov 2010
    4.9
    Medium

    CVE-2010-4161

    Last Modified: 11 Apr 2025

    The udp_queue_rcv_skb function in net/ipv4/udp.c in a certain Red Hat build of the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (deadlock and system hang) by sending UDP traffic to a socket that has a crafted socket filter, a related issue to CVE-2010-4158.

    Published: 10 Nov 2010
    4.7
    Medium

    CVE-2010-4163

    Last Modified: 11 Apr 2025

    The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-2761

    Last Modified: 11 Apr 2025

    The multipart_init function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier uses a hardcoded value of the MIME boundary string in multipart/x-mixed-replace content, which allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input that contains this value, a different vulnerability than CVE-2010-3172.

    Published: 10 Nov 2010
    4.7
    Medium

    CVE-2010-4162

    Last Modified: 11 Apr 2025

    Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.

    Published: 10 Nov 2010
    4.9
    Medium

    CVE-2010-4165

    Last Modified: 11 Apr 2025

    The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-4410

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via vectors related to non-whitespace characters preceded by newline characters, a different vulnerability than CVE-2010-2761 and CVE-2010-3172.

    Published: 10 Nov 2010
    4.7
    Medium

    CVE-2010-4668

    Last Modified: 11 Apr 2025

    The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.37-rc7 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device, related to an unaligned map. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4163.

    Published: 10 Nov 2010
    2.1
    Low

    CVE-2010-4158

    Last Modified: 11 Apr 2025

    The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.

    Published: 10 Nov 2010
    4.3
    Medium

    CVE-2010-4220

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Integrated Solution Console in the Administrative Console component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related in part to "URL injection."

    Published: 9 Nov 2010
    10
    Critical

    CVE-2010-4221

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.

    Published: 9 Nov 2010
    4
    Medium

    CVE-2008-7265

    Last Modified: 11 Apr 2025

    The pr_data_xfer function in ProFTPD before 1.3.2rc3 allows remote authenticated users to cause a denial of service (CPU consumption) via an ABOR command during a data transfer.

    Published: 9 Nov 2010
    6.5
    Medium

    CVE-2010-2635

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters to "Commerce Organization Admin Console JavaServer pages."

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-2636

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 9 Nov 2010
    6.8
    Medium

    CVE-2010-3039

    Last Modified: 11 Apr 2025

    /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.

    Published: 9 Nov 2010
    10
    Critical

    CVE-2010-3040

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in agent.exe in Setup Manager in Cisco Intelligent Contact Manager (ICM) before 7.0 allow remote attackers to execute arbitrary code via a long parameter in a (1) HandleUpgradeAll, (2) AgentUpgrade, (3) HandleQueryNodeInfoReq, or (4) HandleUpgradeTrace TCP packet, aka Bug IDs CSCti45698, CSCti45715, CSCti45726, and CSCti46164.

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-3077

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.

    Published: 9 Nov 2010
    6.8
    Medium

    CVE-2010-3694

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspecified victims for requests to a preference form.

    Published: 9 Nov 2010
    7.1
    High

    CVE-2010-3867

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modify file timestamps via directory traversal sequences in a (1) SITE MKDIR, (2) SITE RMDIR, (3) SITE SYMLINK, or (4) SITE UTIME command.

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-3871

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 9 Nov 2010
    5
    Medium

    CVE-2010-4217

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the proxy server in IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 and 6.1.x before 6.1.0-TIV-ITDS-FP0005 allows remote attackers to cause a denial of service (daemon crash) via an unbind request that occurs during a certain search operation.

    Published: 9 Nov 2010
    10
    Critical

    CVE-2010-4218

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Web Services in IBM ENOVIA 6 has unknown impact and attack vectors, related to a system that becomes "exposed to the internet."

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-0783

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-0784

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Nov 2010
    6
    Medium

    CVE-2010-0785

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.13 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 9 Nov 2010
    5
    Medium

    CVE-2010-0786

    Last Modified: 11 Apr 2025

    The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data.

    Published: 9 Nov 2010
    5
    Medium

    CVE-2010-4216

    Last Modified: 11 Apr 2025

    IBM Tivoli Directory Server (TDS) 6.0.0.x before 6.0.0.8-TIV-ITDS-IF0007 does not properly handle invalid buffer references in LDAP BER requests, which might allow remote attackers to cause a denial of service (daemon crash) via vectors involving a buffer that has a memory address near the maximum possible address.

    Published: 9 Nov 2010
    4.3
    Medium

    CVE-2010-4219

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SemanticTagService.js in IBM WebSphere Portal 6.1.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 9 Nov 2010
    4.9
    Medium

    CVE-2010-4169

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.

    Published: 9 Nov 2010
    4.9
    Medium

    CVE-2010-3086

    Last Modified: 11 Apr 2025

    include/asm-x86/futex.h in the Linux kernel before 2.6.25 does not properly implement exception fixup, which allows local users to cause a denial of service (panic) via an invalid application that triggers a page fault.

    Published: 9 Nov 2010
    2.9
    Low

    CVE-2010-4211

    Last Modified: 11 Apr 2025

    The PayPal app before 3.0.1 for iOS does not verify that the server hostname matches the domain name of the subject of an X.509 certificate, which allows man-in-the-middle attackers to spoof a PayPal web server via an arbitrary certificate.

    Published: 8 Nov 2010
    1.9
    Low

    CVE-2010-4212

    Last Modified: 11 Apr 2025

    The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.

    Published: 8 Nov 2010
    4.3
    Medium

    CVE-2010-4213

    Last Modified: 11 Apr 2025

    The Bank of America application 2.12 for Android stores a security question's answer in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.

    Published: 8 Nov 2010
    4.3
    Medium

    CVE-2010-4214

    Last Modified: 11 Apr 2025

    The Wells Fargo Mobile application 1.1 for Android stores a username and password, along with account balances, in cleartext, which might allow physically proximate attackers to obtain sensitive information by reading application data.

    Published: 8 Nov 2010
    5.8
    Medium

    CVE-2010-3868

    Last Modified: 11 Apr 2025

    Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sniffing the network for SCEP requests and then sending decryption requests to the Certificate Authority component.

    Published: 8 Nov 2010