CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2010-3491

    Last Modified: 11 Apr 2025

    The (1) ActiveMatrix Runtime and (2) ActiveMatrix Administrator components in TIBCO ActiveMatrix Service Grid before 2.3.1, ActiveMatrix Service Bus before 2.3.1, ActiveMatrix BusinessWorks Service Engine before 5.8.1, and ActiveMatrix Service Performance Manager before 1.3.2 do not properly handle JMX connections, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service via unspecified vectors.

    Published: 26 Oct 2010
    6.3
    Medium

    CVE-2010-1693

    Last Modified: 11 Apr 2025

    openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/ib_set_node_desc.sh temporary file.

    Published: 26 Oct 2010
    9.3
    Critical

    CVE-2010-3653

    Last Modified: 11 Apr 2025

    The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value is used as a pointer offset, as exploited in the wild in October 2010. NOTE: some of these details are obtained from third party information.

    Published: 26 Oct 2010
    5
    Medium

    CVE-2010-3986

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Virtual Connect Enterprise Manager (VCEM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 26 Oct 2010
    5
    Medium

    CVE-2010-4094

    Last Modified: 11 Apr 2025

    The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.

    Published: 26 Oct 2010
    6.9
    Medium

    CVE-2010-3156

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in K2 K2Editor before 1.5.9 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3160

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Archive Decoder 1.23 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3161

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in TeraPad before 1.00 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3162

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Apsaly before 3.74 allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3163

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Fenrir Sleipnir before 2.9.5 and Grani before 4.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3164

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Fenrir Sleipnir 2.9.4 and earlier and Grani 4.3 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    7.1
    High

    CVE-2010-3714

    Last Modified: 11 Apr 2025

    The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values during access-control decisions, which allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 25 Oct 2010
    4.3
    Medium

    CVE-2010-3715

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the RemoveXSS function, and allow remote authenticated users to inject arbitrary web script or HTML via vectors related to (2) the backend.

    Published: 25 Oct 2010
    6
    Medium

    CVE-2010-3716

    Last Modified: 11 Apr 2025

    The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrary group memberships.

    Published: 25 Oct 2010
    5
    Medium

    CVE-2010-3717

    Last Modified: 11 Apr 2025

    The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a long e-mail address string, a related issue to CVE-2010-3710.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3159

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Explzh 5.67 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    8.5
    High

    CVE-2010-4069

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenticated users to execute arbitrary code via long DBINFO keyword arguments in a SQL statement, aka idsdb00165017, idsdb00165019, idsdb00165021, idsdb00165022, and idsdb00165023.

    Published: 25 Oct 2010
    10
    Critical

    CVE-2010-4070

    Last Modified: 11 Apr 2025

    Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before 10.00.xC8, and 11.10 before 11.10.xC2 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted parameter size, aka idsdb00146931, idsdb00146930, idsdb00146929, and idsdb00138308.

    Published: 25 Oct 2010
    6.9
    Medium

    CVE-2010-3165

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Yokka NoEditor 1.33.1.1 and earlier, OuiEditor 1.6.1.1 and earlier, UnEditor 1.10.1.2 and earlier, DeuxEditor 1.7.1.2 and earlier, SQLEditorXP 3.14.1.2 and earlier, SQLEditorTE 1.9.1.3 and earlier, SQLEditor8 3.8.1.2 and earlier, and SQLEditorClassic 1.8.1.3 and earlier allows local users to gain privileges via a Trojan horse executable file in the current working directory.

    Published: 25 Oct 2010
    4.9
    Medium

    CVE-2010-4068

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbitrary files via a crafted parameter, a different vulnerability than CVE-2010-3714.

    Published: 25 Oct 2010
    4.3
    Medium

    CVE-2010-3289

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Oct 2010
    6.5
    Medium

    CVE-2010-3290

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 22 Oct 2010
    9
    Critical

    CVE-2010-4053

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute arbitrary code via a crafted EXPLAIN directive, aka idsdb00154125 and idsdb00154243.

    Published: 22 Oct 2010
    5
    Medium

    CVE-2010-4055

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.

    Published: 22 Oct 2010
    5
    Medium

    CVE-2010-4056

    Last Modified: 11 Apr 2025

    solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.

    Published: 22 Oct 2010
    5
    Medium

    CVE-2010-4057

    Last Modified: 11 Apr 2025

    solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.

    Published: 22 Oct 2010
    6.8
    Medium

    CVE-2010-3288

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Systems Insight Manager (SIM) before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 22 Oct 2010
    7.2
    High

    CVE-2010-3856

    Last Modified: 11 Apr 2025

    ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcprofile.so.

    Published: 22 Oct 2010
    6.9
    Medium

    CVE-2010-3859

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in the TIPC implementation in the Linux kernel before 2.6.36.2 allow local users to gain privileges via a crafted sendmsg call that triggers a heap-based buffer overflow, related to the tipc_msg_build function in net/tipc/msg.c and the verify_iovec function in net/core/iovec.c.

    Published: 22 Oct 2010
    7.8
    High

    CVE-2010-4656

    Last Modified: 11 Apr 2025

    The iowarrior_write function in drivers/usb/misc/iowarrior.c in the Linux kernel before 2.6.37 does not properly allocate memory, which might allow local users to trigger a heap-based buffer overflow, and consequently cause a denial of service or gain privileges, via a long report.

    Published: 22 Oct 2010
    6.9
    Medium

    CVE-2010-3853

    Last Modified: 11 Apr 2025

    pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as demonstrated by the sudo program.

    Published: 22 Oct 2010
    9.3
    Critical

    CVE-2010-3174

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 21 Oct 2010
    6.9
    Medium

    CVE-2010-3181

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 21 Oct 2010
    5
    Medium

    CVE-2010-4033

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.

    Published: 21 Oct 2010
    9.3
    Critical

    CVE-2010-4034

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

    Published: 21 Oct 2010
    9.3
    Critical

    CVE-2010-4035

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document.

    Published: 21 Oct 2010
    9.8
    Critical

    CVE-2010-4039

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.

    Published: 21 Oct 2010
    9.8
    Critical

    CVE-2010-4041

    Last Modified: 11 Apr 2025

    The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4046

    Last Modified: 11 Apr 2025

    Opera before 10.63 does not properly verify the origin of video content, which allows remote attackers to obtain sensitive information by using a video stream as HTML5 canvas content.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4047

    Last Modified: 11 Apr 2025

    Opera before 10.63 does not properly select the security context of JavaScript code associated with an error page, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4048

    Last Modified: 11 Apr 2025

    Opera before 10.63 allows user-assisted remote web servers to cause a denial of service (application crash) by sending a redirect during the saving of a file.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4049

    Last Modified: 11 Apr 2025

    Opera before 10.63 allows remote attackers to cause a denial of service (application crash) via a Flash movie with a transparent Window Mode (aka wmode) property, which is not properly handled during navigation away from the containing HTML document.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4050

    Last Modified: 11 Apr 2025

    Opera before 10.63 allows remote attackers to cause a denial of service (memory corruption) by referencing an SVG document in an IMG element.

    Published: 21 Oct 2010
    7.5
    High

    CVE-2010-4038

    Last Modified: 11 Apr 2025

    The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdown action, which allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4044

    Last Modified: 11 Apr 2025

    Opera before 10.63 does not ensure that the portion of a URL shown in the Address Bar contains the beginning of the URL, which allows remote attackers to spoof URLs by changing a window's size.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-3291

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP AssetCenter 5.0x through AC_5.03, and AssetManager 5.1x through AM_5.12 and 5.2x through AM_5.22, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Oct 2010
    6.8
    Medium

    CVE-2010-4036

    Last Modified: 11 Apr 2025

    Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.

    Published: 21 Oct 2010
    4.3
    Medium

    CVE-2010-4043

    Last Modified: 11 Apr 2025

    Opera before 10.63 does not prevent interpretation of a cross-origin document as a CSS stylesheet when the document lacks a CSS token sequence, which allows remote attackers to obtain sensitive information via a crafted document.

    Published: 21 Oct 2010
    9.3
    Critical

    CVE-2010-4045

    Last Modified: 11 Apr 2025

    Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers to spoof the Address Bar, conduct cross-site scripting (XSS) attacks, and possibly execute arbitrary code by leveraging the ability of a script to interact with a web page from (1) a different domain or (2) a different security context.

    Published: 21 Oct 2010
    6.9
    Medium

    CVE-2010-3846

    Last Modified: 11 Apr 2025

    Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based buffer overflow.

    Published: 21 Oct 2010