CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2010-3852

    Last Modified: 11 Apr 2025

    The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authentication via a forged ticket cookie.

    Published: 21 Oct 2010
    6.9
    Medium

    CVE-2010-3350

    Last Modified: 11 Apr 2025

    bareFTP 0.3.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3351

    Last Modified: 11 Apr 2025

    startBristol in Bristol 0.60.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3353

    Last Modified: 11 Apr 2025

    Cowbell 0.2.7.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3354

    Last Modified: 11 Apr 2025

    dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3355

    Last Modified: 11 Apr 2025

    Ember 0.5.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3357

    Last Modified: 11 Apr 2025

    gnome-subtitles 1.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3360

    Last Modified: 11 Apr 2025

    Hipo 0.6.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3362

    Last Modified: 11 Apr 2025

    lastfm 1.5.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3363

    Last Modified: 11 Apr 2025

    roarify in roaraudio 0.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3364

    Last Modified: 11 Apr 2025

    The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3365

    Last Modified: 11 Apr 2025

    Mistelix 0.31 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3376

    Last Modified: 11 Apr 2025

    The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3377

    Last Modified: 11 Apr 2025

    The (1) runSalome, (2) runTestMedCorba, (3) runLightSalome, and (4) hxx2salome scripts in SALOME 5.1.3 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3381

    Last Modified: 11 Apr 2025

    The (1) tangerine and (2) tangerine-properties scripts in Tangerine 0.3.2.2 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3382

    Last Modified: 11 Apr 2025

    tauex in Tuning and Analysis Utilities (TAU) 2.16.4 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3383

    Last Modified: 11 Apr 2025

    The (1) teamspeak and (2) teamspeak-server scripts in TeamSpeak 2.0.32 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3384

    Last Modified: 11 Apr 2025

    The (1) torcs, (2) nfsperf, (3) accc, (4) texmapper, (5) trackgen, and (6) nfs2ac scripts in TORCS 1.3.1 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3385

    Last Modified: 11 Apr 2025

    TuxGuitar 1.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3386

    Last Modified: 11 Apr 2025

    usttrace in LTTng Userspace Tracer (aka UST) 0.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3393

    Last Modified: 11 Apr 2025

    magics-config in Magics++ 2.10.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3394

    Last Modified: 11 Apr 2025

    The (1) texmacs and (2) tm_mupad_help scripts in TeXmacs 1.0.7.4 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    5
    Medium

    CVE-2010-4007

    Last Modified: 11 Apr 2025

    Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.

    Published: 20 Oct 2010
    4.3
    Medium

    CVE-2010-0782

    Last Modified: 11 Apr 2025

    IBM WebSphere MQ 6.x before 6.0.2.10 and 7.x before 7.0.1.3 allows remote attackers to spoof X.509 certificate authentication, and send or receive channel messages, via a crafted Subject Distinguished Name (DN) value in a certificate.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3349

    Last Modified: 11 Apr 2025

    Ardour 2.8.11 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3361

    Last Modified: 11 Apr 2025

    The (1) iked, (2) ikea, and (3) ikec scripts in Shrew Soft IKE 2.1.5 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3358

    Last Modified: 11 Apr 2025

    HenPlus JDBC SQL-Shell 0.9.7 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3366

    Last Modified: 11 Apr 2025

    Mn_Fit 5.13 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3369

    Last Modified: 11 Apr 2025

    The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3378

    Last Modified: 11 Apr 2025

    The (1) scilab, (2) scilab-cli, and (3) scilab-adv-cli scripts in Scilab 5.2.2 place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 20 Oct 2010
    6.9
    Medium

    CVE-2010-3387

    Last Modified: 11 Apr 2025

    vdrleaktest in Video Disk Recorder (VDR) 1.6.0 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: a third party disputes this issue because the script erroneously uses a semicolon in a context where a colon was intended

    Published: 20 Oct 2010
    7.5
    High

    CVE-2010-2891

    Last Modified: 11 Apr 2025

    Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.

    Published: 20 Oct 2010
    Unknown

    CVE-2010-4014

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 20 Oct 2010
    Unknown

    CVE-2010-4016

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 20 Oct 2010
    Unknown

    CVE-2010-4017

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 20 Oct 2010
    4
    Medium

    CVE-2010-3711

    Last Modified: 11 Apr 2025

    libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a crafted message, related to the plugins for MSN, MySpaceIM, XMPP, and Yahoo! and the NTLM authentication support.

    Published: 20 Oct 2010
    9.3
    Critical

    CVE-2010-3975

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Flash Player 9 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll that is located in the same folder as a file that is processed by Flash.

    Published: 19 Oct 2010
    9.3
    Critical

    CVE-2010-3976

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Flash Player.

    Published: 19 Oct 2010
    4.3
    Medium

    CVE-2009-5010

    Last Modified: 11 Apr 2025

    Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.1 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected return value of None, a different vulnerability than CVE-2010-3494.

    Published: 19 Oct 2010
    4.3
    Medium

    CVE-2010-3494

    Last Modified: 11 Apr 2025

    Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the accept function having an unexpected value of None for the address, or an ECONNABORTED, EAGAIN, or EWOULDBLOCK error, a related issue to CVE-2010-3492.

    Published: 19 Oct 2010
    6.5
    Medium

    CVE-2007-6736

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.2.0 allow remote authenticated users to access arbitrary files and directories via a .. (dot dot) in a (1) LIST, (2) STOR, or (3) RETR command.

    Published: 19 Oct 2010
    7.5
    High

    CVE-2007-6737

    Last Modified: 11 Apr 2025

    FTPServer.py in pyftpdlib before 0.2.0 does not increment the attempted_logins count for a USER command that specifies an invalid username, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 19 Oct 2010
    5
    Medium

    CVE-2007-6738

    Last Modified: 11 Apr 2025

    pyftpdlib before 0.1.1 does not choose a random value for the port associated with the PASV command, which makes it easier for remote attackers to obtain potentially sensitive information about the number of in-progress data connections by reading the response to this command.

    Published: 19 Oct 2010
    5
    Medium

    CVE-2007-6739

    Last Modified: 11 Apr 2025

    FTPServer.py in pyftpdlib before 0.2.0 allows remote attackers to cause a denial of service via a long command.

    Published: 19 Oct 2010
    4
    Medium

    CVE-2007-6740

    Last Modified: 11 Apr 2025

    The ftp_STOU function in FTPServer.py in pyftpdlib before 0.2.0 does not limit the number of attempts to discover a unique filename, which might allow remote authenticated users to cause a denial of service via a STOU command.

    Published: 19 Oct 2010
    7.5
    High

    CVE-2008-7263

    Last Modified: 11 Apr 2025

    ftpserver.py in pyftpdlib before 0.5.0 does not delay its response after receiving an invalid login attempt, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 19 Oct 2010
    4
    Medium

    CVE-2008-7264

    Last Modified: 11 Apr 2025

    The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt.

    Published: 19 Oct 2010
    4.3
    Medium

    CVE-2009-5011

    Last Modified: 11 Apr 2025

    Race condition in the FTPHandler class in ftpserver.py in pyftpdlib before 0.5.2 allows remote attackers to cause a denial of service (daemon outage) by establishing and then immediately closing a TCP connection, leading to the getpeername function having an ENOTCONN error, a different vulnerability than CVE-2010-3494.

    Published: 19 Oct 2010
    4
    Medium

    CVE-2009-5012

    Last Modified: 11 Apr 2025

    ftpserver.py in pyftpdlib before 0.5.2 does not require the l permission for the MLST command, which allows remote authenticated users to bypass intended access restrictions and list the root directory via an FTP session.

    Published: 19 Oct 2010
    4
    Medium

    CVE-2009-5013

    Last Modified: 11 Apr 2025

    Memory leak in the on_dtp_close function in ftpserver.py in pyftpdlib before 0.5.2 allows remote authenticated users to cause a denial of service (memory consumption) by sending a QUIT command during a data transfer.

    Published: 19 Oct 2010