CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2010-4167

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.

    Published: 30 Oct 2010
    9.3
    Critical

    CVE-2010-2582

    Last Modified: 11 Apr 2025

    An unspecified function in TextXtra.x32 in Adobe Shockwave Player before 11.5.9.615 does not properly reallocate a buffer when processing a DEMX chunk in a Director file, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code.

    Published: 29 Oct 2010
    10
    Critical

    CVE-2010-3036

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-3655

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 29 Oct 2010
    5
    Medium

    CVE-2010-3700

    Last Modified: 11 Apr 2025

    VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attackers to bypass security constraints via a path parameter.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4084

    Last Modified: 11 Apr 2025

    dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4085

    Last Modified: 11 Apr 2025

    dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4086, and CVE-2010-4088.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4088

    Last Modified: 11 Apr 2025

    dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with "duplicated references to the same KEY* chunk," a different vulnerability than CVE-2010-2581, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4086.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4089

    Last Modified: 11 Apr 2025

    IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file containing "duplicated LCSM entries in mmap record," a different vulnerability than CVE-2010-4087.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4090

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-2581

    Last Modified: 11 Apr 2025

    dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director file containing a crafted pamm chunk with an invalid (1) size and (2) number of sub-chunks, a different vulnerability than CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4087

    Last Modified: 11 Apr 2025

    IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with a crafted mmap record containing an invalid length of a VSWV entry, a different vulnerability than CVE-2010-4089.

    Published: 29 Oct 2010
    9.3
    Critical

    CVE-2010-4086

    Last Modified: 11 Apr 2025

    dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Director (.dir) media file with an invalid element size, a different vulnerability than CVE-2010-2581, CVE-2010-2880, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4088.

    Published: 29 Oct 2010
    7.2
    High

    CVE-2010-3865

    Last Modified: 11 Apr 2025

    Integer overflow in the rds_rdma_pages function in net/rds/rdma.c in the Linux kernel allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a crafted iovec struct in a Reliable Datagram Sockets (RDS) request, which triggers a buffer overflow.

    Published: 29 Oct 2010
    4.3
    Medium

    CVE-2010-4120

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.

    Published: 28 Oct 2010
    7.5
    High

    CVE-2010-4121

    Last Modified: 11 Apr 2025

    The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.

    Published: 28 Oct 2010
    6.2
    Medium

    CVE-2010-4026

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the service API in HP Palm webOS 1.4.1 allows local users to gain privileges by leveraging the ability to perform certain service calls.

    Published: 28 Oct 2010
    5
    Medium

    CVE-2010-3988

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to bypass intended access restrictions and cause a denial of service via unknown vectors.

    Published: 28 Oct 2010
    5
    Medium

    CVE-2010-3990

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 28 Oct 2010
    4.3
    Medium

    CVE-2010-3991

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2010
    9
    Critical

    CVE-2010-3992

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 28 Oct 2010
    7.5
    High

    CVE-2010-4028

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors.

    Published: 28 Oct 2010
    7.5
    High

    CVE-2010-4029

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Essentials before 6.3.0, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 28 Oct 2010
    4.3
    Medium

    CVE-2010-4023

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2010
    6.8
    Medium

    CVE-2010-4024

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 28 Oct 2010
    9.3
    Critical

    CVE-2010-4025

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Doc Viewer in HP Palm webOS 1.4.1 allows remote attackers to execute arbitrary code via a crafted document, as demonstrated by a Word document.

    Published: 28 Oct 2010
    7.5
    High

    CVE-2010-0112

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Administrative Interface in the IIS extension in Symantec IM Manager before 8.4.16 allow remote attackers to execute arbitrary SQL commands via (1) the rdReport parameter to rdpageimlogic.aspx, related to the sGetDefinition function in rdServer.dll, and SQL statements contained within a certain report file; (2) unspecified parameters in a DetailReportGroup (aka DetailReportGroup.lgx) action to rdpageimlogic.aspx; the (3) selclause, (4) whereTrendTimeClause, (5) TrendTypeForReport, (6) whereProtocolClause, or (7) groupClause parameter in a SummaryReportGroup (aka SummaryReportGroup.lgx) action to rdpageimlogic.aspx; the (8) loginTimeStamp, (9) dbo, (10) dateDiffParam, or (11) whereClause parameter in a LoggedInUsers (aka LoggedInUSers.lgx) action to (a) rdpageimlogic.aspx or (b) rdPage.aspx; the (12) selclause, (13) whereTrendTimeClause, (14) TrendTypeForReport, (15) whereProtocolClause, or (16) groupClause parameter to rdpageimlogic.aspx; (17) the groupList parameter to IMAdminReportTrendFormRun.asp; or (18) the email parameter to IMAdminScheduleReport.asp.

    Published: 28 Oct 2010
    4.3
    Medium

    CVE-2010-3987

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2010
    6.8
    Medium

    CVE-2010-3989

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 28 Oct 2010
    6.4
    Medium

    CVE-2010-3993

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to obtain sensitive information or modify data via unknown vectors.

    Published: 28 Oct 2010
    4.3
    Medium

    CVE-2010-3994

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Oct 2010
    5.6
    Medium

    CVE-2010-4027

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors.

    Published: 28 Oct 2010
    9.8
    Critical

    CVE-2010-2941

    Last Modified: 11 Apr 2025

    ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request.

    Published: 28 Oct 2010
    9.3
    Critical

    CVE-2010-3654

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in Adobe Reader and Acrobat 9.x through 9.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted SWF content, as exploited in the wild in October 2010.

    Published: 28 Oct 2010
    9.8
    Critical

    CVE-2010-3765

    Last Modified: 22 Apr 2026

    Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x before 2.0.10, when JavaScript is enabled, allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption, as exploited in the wild in October 2010 by the Belmoo malware.

    Published: 27 Oct 2010
    4.3
    Medium

    CVE-2010-3713

    Last Modified: 11 Apr 2025

    rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended access restrictions by reading a forum feed in combination with a topic feed.

    Published: 27 Oct 2010
    5.8
    Medium

    CVE-2010-3842

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backslash) as a separator of path components within the Content-disposition HTTP header.

    Published: 27 Oct 2010
    6.4
    Medium

    CVE-2010-3933

    Last Modified: 11 Apr 2025

    Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.

    Published: 27 Oct 2010
    4.3
    Medium

    CVE-2010-3712

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded entities," as demonstrated by the query string to index.php in the com_weblinks or com_content component.

    Published: 27 Oct 2010
    4.6
    Medium

    CVE-2010-4096

    Last Modified: 11 Apr 2025

    share/ma/keys_for_user in Monkeysphere 0.31 and 0.32 allows local users to execute arbitrary code via unknown manipulations related to the "monkeysphere-authentication keys-for-user" command.

    Published: 27 Oct 2010
    5
    Medium

    CVE-2010-4098

    Last Modified: 11 Apr 2025

    monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.

    Published: 27 Oct 2010
    6.8
    Medium

    CVE-2010-4099

    Last Modified: 11 Apr 2025

    ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.

    Published: 27 Oct 2010
    4.3
    Medium

    CVE-2010-4097

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3) u, and (4) url parameters. NOTE: the q parameter is already covered by CVE-2009-2302.

    Published: 27 Oct 2010
    9.3
    Critical

    CVE-2010-3227

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the UpdateFrameTitleForDocument method in the CFrameWnd class in mfc42.dll in the Microsoft Foundation Class (MFC) Library in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows context-dependent attackers to execute arbitrary code via a long window title that this library attempts to create at the request of an application, as demonstrated by the Trident PowerZip 7.2 Build 4010 application, aka "Windows MFC Document Title Updating Buffer Overflow Vulnerability."

    Published: 26 Oct 2010
    9.3
    Critical

    CVE-2010-4095

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via a .. (dot dot) in a filename in a server response.

    Published: 26 Oct 2010
    5
    Medium

    CVE-2010-2584

    Last Modified: 11 Apr 2025

    The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restrict certain property values, which allows remote attackers to read arbitrary files via a filename in the SourceFile property in conjunction with an http URL in the DestURL property.

    Published: 26 Oct 2010
    10
    Critical

    CVE-2010-2585

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls allow remote attackers to execute arbitrary code via a long (1) DestURL or (2) SourceFile property value.

    Published: 26 Oct 2010
    4.3
    Medium

    CVE-2010-2885

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allows remote attackers to inject arbitrary web script or HTML via vectors related to WebHelp generation with RoboHelp for Word.

    Published: 26 Oct 2010
    4.3
    Medium

    CVE-2010-3985

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Oct 2010
    4.3
    Medium

    CVE-2010-2886

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 7 and 8, and RoboHelp Server 7 and 8, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Oct 2010