CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-2416

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle E-Business Intelligence component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    4
    Medium

    CVE-2010-2417

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.0.0 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2418

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Territory Management component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    6.5
    Medium

    CVE-2010-2419

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java Virtual Machine component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 13 Oct 2010
    3
    Low

    CVE-2010-3506

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Explorer (Sun Explorer) component in Oracle Sun Products Suite 6.4 allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 13 Oct 2010
    3.5
    Low

    CVE-2010-3512

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0u8 allows remote authenticated users to affect confidentiality, related to DAV (WebDAV).

    Published: 13 Oct 2010
    5.5
    Medium

    CVE-2010-3518

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM GP - Japan component in Oracle PeopleSoft and JDEdwards Suite 8.81 SP1 Bundle #13, 8.9 GP Update 2010-E, 9.0 GP Update 2010-E, and 9.1 GP Update 2010-E allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 13 Oct 2010
    5.8
    Medium

    CVE-2010-2388

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 13 Oct 2010
    3.6
    Low

    CVE-2010-2391

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.1.0.5 and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.

    Published: 13 Oct 2010
    7.5
    High

    CVE-2010-2390

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Database Control component in EM Console in Oracle Database Server 10.1.0.5 and 10.2.0.3, Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3, and Enterprise Manager Grid Control allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 13 Oct 2010
    6
    Medium

    CVE-2010-2405

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel Core - Highly Interactive Client component in Oracle Siebel Suite 7.7.2.12, 7.8.2.14, 8.0.0.10, and 8.1.1.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-3500.

    Published: 13 Oct 2010
    4.6
    Medium

    CVE-2010-2411

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Job Queue component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0.3, 10.2.0.4, and 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DBMS_IJOB.

    Published: 13 Oct 2010
    1
    Low

    CVE-2010-2389

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Perl component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0.3, 10.2.0.4, and 10.1.0.5; and Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0; allows local users to affect integrity via unknown vectors related to Local Logon.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2395

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Cabo/UIX component in Oracle Fusion Middleware 10.1.2.3 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2409 and CVE-2010-2410.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2396

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Forms component in Oracle Fusion Middleware 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    3.5
    Low

    CVE-2010-2404

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect integrity via unknown vectors related to Account.

    Published: 13 Oct 2010
    4
    Medium

    CVE-2010-2406

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel Core - Highly Interactive Client component in Oracle Siebel Suite 7.7.2.12, 7.8.2.14, 8.0.0.10, and 8.1.1.3 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2407

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the XDK component in Oracle Database Server 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2408

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2409

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Cabo/UIX component in Oracle Fusion Middleware 10.1.2.3 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2395 and CVE-2010-2410.

    Published: 13 Oct 2010
    4.3
    Medium

    CVE-2010-2410

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Cabo/UIX component in Oracle Fusion Middleware 10.1.2.3 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2010-2395 and CVE-2010-2409.

    Published: 13 Oct 2010
    7.2
    High

    CVE-2010-2740

    Last Modified: 11 Apr 2025

    The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font parsing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Parsing Vulnerability."

    Published: 13 Oct 2010
    7.2
    High

    CVE-2010-2741

    Last Modified: 11 Apr 2025

    The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font processing, which allows local users to gain privileges via a crafted application, aka "OpenType Font Validation Vulnerability."

    Published: 13 Oct 2010
    7.2
    High

    CVE-2010-2744

    Last Modified: 11 Apr 2025

    The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly manage a window class, which allows local users to gain privileges by creating a window, then using (1) the SetWindowLongPtr function to modify the popup menu structure, or (2) the SwitchWndProc function with a switch window information pointer, which is not re-initialized when a WM_NCCREATE message is processed, aka "Win32k Window Class Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-2748

    Last Modified: 11 Apr 2025

    Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly check an unspecified boundary during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Boundary Check Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-2750

    Last Modified: 11 Apr 2025

    Array index error in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3216

    Last Modified: 11 Apr 2025

    Microsoft Word 2002 SP3 and Office 2004 for Mac allow remote attackers to execute arbitrary code via a crafted Word document containing bookmarks that trigger use of an invalid pointer and memory corruption, aka "Word Bookmarks Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3217

    Last Modified: 11 Apr 2025

    Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3218

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via malformed records in a Word document, aka "Word Heap Overflow Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3219

    Last Modified: 11 Apr 2025

    Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3220

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Microsoft Word 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Parsing Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3221

    Last Modified: 11 Apr 2025

    Microsoft Word 2002 SP3 and 2003 SP3, Office 2004 for Mac, and Word Viewer do not properly handle a malformed record during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Parsing Vulnerability."

    Published: 13 Oct 2010
    7.1
    High

    CVE-2010-3229

    Last Modified: 11 Apr 2025

    The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows remote attackers to cause a denial of service (LSASS outage and reboot) via a crafted packet, aka "TLSv1 Denial of Service Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3230

    Last Modified: 11 Apr 2025

    Integer overflow in Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel document with crafted record information, aka "Excel Record Parsing Integer Overflow Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3233

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3234

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3235

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3236

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bounds Array Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3237

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3238

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3241

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds Memory Write in Parsing Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3242

    Last Modified: 11 Apr 2025

    Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3326

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3329

    Last Modified: 11 Apr 2025

    mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Microsoft Office document that causes the HtmlDlgHelper class destructor to access uninitialized memory, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 13 Oct 2010
    6.5
    Medium

    CVE-2010-3330

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Cross-Domain Information Disclosure Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3331

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory in certain circumstances involving use of Microsoft Word to read Word documents, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 13 Oct 2010
    2.6
    Low

    CVE-2010-0808

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 and 7 on Windows XP and Vista does not prevent script from simulating user interaction with the AutoComplete feature, which allows remote attackers to obtain sensitive form information via a crafted web site, aka "AutoComplete Information Disclosure Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-2747

    Last Modified: 11 Apr 2025

    Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3214

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Office Web Apps; and Word Web App allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Stack Overflow Vulnerability."

    Published: 13 Oct 2010
    9.3
    Critical

    CVE-2010-3215

    Last Modified: 11 Apr 2025

    Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle unspecified return values during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Return Value Vulnerability."

    Published: 13 Oct 2010