CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2010-4091

    Last Modified: 11 Apr 2025

    The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.

    Published: 4 Nov 2010
    8.8
    High

    CVE-2010-4198

    Last Modified: 11 Apr 2025

    WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.

    Published: 4 Nov 2010
    8.8
    High

    CVE-2010-4199

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SVG document.

    Published: 4 Nov 2010
    9.8
    Critical

    CVE-2010-4201

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text control selections.

    Published: 4 Nov 2010
    9.8
    Critical

    CVE-2010-4204

    Last Modified: 11 Apr 2025

    WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 4 Nov 2010
    9.3
    Critical

    CVE-2010-3640

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3641, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3649, CVE-2010-3650, and CVE-2010-3652.

    Published: 4 Nov 2010
    9.3
    Critical

    CVE-2010-3649

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, a different vulnerability than CVE-2010-3640, CVE-2010-3641, CVE-2010-3642, CVE-2010-3643, CVE-2010-3644, CVE-2010-3645, CVE-2010-3646, CVE-2010-3647, CVE-2010-3648, CVE-2010-3650, and CVE-2010-3652.

    Published: 4 Nov 2010
    9.8
    Critical

    CVE-2010-4197

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.

    Published: 4 Nov 2010
    3.5
    Low

    CVE-2010-4644

    Last Modified: 11 Apr 2025

    Multiple memory leaks in rev_hunt.c in Apache Subversion before 1.6.15 allow remote authenticated users to cause a denial of service (memory consumption and daemon crash) via the -g option to the blame command.

    Published: 4 Nov 2010
    7.5
    High

    CVE-2010-4152

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.

    Published: 3 Nov 2010
    9.3
    Critical

    CVE-2010-4154

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 3 Nov 2010
    9.3
    Critical

    CVE-2010-4153

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in CrossFTP Pro 1.65a, and probably earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 3 Nov 2010
    4.3
    Medium

    CVE-2010-4155

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and the sumb parameter to (2) modules/news/archive.php, (3) modules/news/topics.php, and (4) modules/contact/index.php, different vectors than CVE-2007-1965.

    Published: 3 Nov 2010
    7.5
    High

    CVE-2010-4006

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.

    Published: 3 Nov 2010
    6.8
    Medium

    CVE-2010-4151

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.

    Published: 3 Nov 2010
    9.3
    Critical

    CVE-2010-2583

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.

    Published: 3 Nov 2010
    9.3
    Critical

    CVE-2010-3914

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.

    Published: 3 Nov 2010
    4.3
    Medium

    CVE-2010-3977

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

    Published: 3 Nov 2010
    4.9
    Medium

    CVE-2010-3880

    Last Modified: 11 Apr 2025

    net/ipv4/inet_diag.c in the Linux kernel before 2.6.37-rc2 does not properly audit INET_DIAG bytecode, which allows local users to cause a denial of service (kernel infinite loop) via crafted INET_DIAG_REQ_BYTECODE instructions in a netlink message that contains multiple attribute elements, as demonstrated by INET_DIAG_BC_JMP instructions.

    Published: 3 Nov 2010
    5
    Medium

    CVE-2010-4150

    Last Modified: 11 Apr 2025

    Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

    Published: 2 Nov 2010
    3.3
    Low

    CVE-2011-0541

    Last Modified: 11 Apr 2025

    fuse 2.8.5 and earlier does not properly handle when /etc/mtab cannot be updated, which allows local users to unmount arbitrary directories via a symlink attack.

    Published: 2 Nov 2010
    3.3
    Low

    CVE-2011-0542

    Last Modified: 11 Apr 2025

    fusermount in fuse 2.8.5 and earlier does not perform a chdir to / before performing a mount or umount, which allows local users to unmount arbitrary directories via unspecified vectors.

    Published: 2 Nov 2010
    3.3
    Low

    CVE-2011-0543

    Last Modified: 11 Apr 2025

    Certain legacy functionality in fusermount in fuse 2.8.5 and earlier, when util-linux does not support the --no-canonicalize option, allows local users to bypass intended access restrictions and unmount arbitrary directories via a symlink attack.

    Published: 2 Nov 2010
    5.8
    Medium

    CVE-2010-3879

    Last Modified: 11 Apr 2025

    FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the mountpoint of a FUSE filesystem, a different vulnerability than CVE-2010-0789.

    Published: 2 Nov 2010
    2.1
    Low

    CVE-2010-4565

    Last Modified: 11 Apr 2025

    The bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel 2.6.36 and earlier creates a publicly accessible file with a filename containing a kernel memory address, which allows local users to obtain potentially sensitive information about kernel memory use by listing this filename.

    Published: 2 Nov 2010
    4.3
    Medium

    CVE-2010-3611

    Last Modified: 11 Apr 2025

    ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a Relay-Forward message without an address in the Relay-Forward link-address field.

    Published: 2 Nov 2010
    4
    Medium

    CVE-2010-3874

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.

    Published: 2 Nov 2010
    5
    Medium

    CVE-2010-4145

    Last Modified: 11 Apr 2025

    Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.

    Published: 1 Nov 2010
    4.3
    Medium

    CVE-2010-4146

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Nov 2010
    7.5
    High

    CVE-2010-4147

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header to (1) index.php and (2) product-list.php.

    Published: 1 Nov 2010
    9.3
    Critical

    CVE-2010-4148

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in AnyConnect 1.2.3.0, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 1 Nov 2010
    9.3
    Critical

    CVE-2010-4149

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.

    Published: 1 Nov 2010
    6.8
    Medium

    CVE-2010-4143

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Nov 2010
    7.5
    High

    CVE-2010-4144

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.

    Published: 1 Nov 2010
    4.3
    Medium

    CVE-2010-4030

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Nov 2010
    8
    High

    CVE-2010-4031

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Performance Management before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 1 Nov 2010
    6.8
    Medium

    CVE-2010-4032

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 1 Nov 2010
    5
    Medium

    CVE-2010-4100

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Performance Management before 6.1 update 2 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 1 Nov 2010
    4.3
    Medium

    CVE-2010-4101

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Recovery before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Nov 2010
    5
    Medium

    CVE-2010-4104

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 1 Nov 2010
    6.8
    Medium

    CVE-2010-4106

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 1 Nov 2010
    5
    Medium

    CVE-2010-4102

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Recovery before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 1 Nov 2010
    5
    Medium

    CVE-2010-4103

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 1 Nov 2010
    6.4
    Medium

    CVE-2010-4105

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to bypass intended access restrictions, and obtain sensitive information or modify data, via unknown vectors.

    Published: 1 Nov 2010
    10
    Critical

    CVE-2010-4142

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.

    Published: 1 Nov 2010
    6.9
    Medium

    CVE-2010-4160

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or possibly gain privileges via a crafted sendto call.

    Published: 1 Nov 2010
    2.1
    Low

    CVE-2010-3875

    Last Modified: 11 Apr 2025

    The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.

    Published: 31 Oct 2010
    1.9
    Low

    CVE-2010-3877

    Last Modified: 11 Apr 2025

    The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory by reading a copy of this structure.

    Published: 31 Oct 2010
    1.9
    Low

    CVE-2010-3876

    Last Modified: 11 Apr 2025

    net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.

    Published: 31 Oct 2010
    2.1
    Low

    CVE-2010-3881

    Last Modified: 11 Apr 2025

    arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.

    Published: 30 Oct 2010