CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2010-3555

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from a reliable third party coordinator that the ActiveX Plugin does not properly initialize an object field that is used as a window handle, which allows attackers to execute arbitrary code.

    Published: 12 Oct 2010
    7.5
    High

    CVE-2010-3561

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this involves the use of the privileged accept method in the ServerSocket class, which does not limit which hosts can connect and allows remote attackers to bypass intended network access restrictions.

    Published: 12 Oct 2010
    10
    Critical

    CVE-2010-3562

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable downstream vendor that this is a double free vulnerability in IndexColorModel that allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code.

    Published: 12 Oct 2010
    10
    Critical

    CVE-2010-3565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that triggers memory corruption via large values in a subsample of a JPEG image, related to JPEGImageWriter.writeImage in the imageio API.

    Published: 12 Oct 2010
    10
    Critical

    CVE-2010-3566

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update and 25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is an integer overflow that leads to a buffer overflow via a crafted devs (device information) tag structure in a color profile.

    Published: 12 Oct 2010
    6.8
    Medium

    CVE-2010-3855

    Last Modified: 11 Apr 2025

    Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TrueType GX font.

    Published: 11 Oct 2010
    5.5
    Medium

    CVE-2010-4655

    Last Modified: 11 Apr 2025

    net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize certain data structures, which allows local users to obtain potentially sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability for an ethtool ioctl call.

    Published: 11 Oct 2010
    4.3
    Medium

    CVE-2010-3887

    Last Modified: 11 Apr 2025

    The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access restrictions and conduct e-mail communication by leveraging knowledge of a child's e-mail address and a parent's e-mail address, related to parental notification of unapproved e-mail addresses.

    Published: 8 Oct 2010
    7.2
    High

    CVE-2010-3888

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.

    Published: 8 Oct 2010
    4.3
    Medium

    CVE-2010-3886

    Last Modified: 11 Apr 2025

    The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

    Published: 8 Oct 2010
    7.2
    High

    CVE-2010-3889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Microsoft researchers and other researchers.

    Published: 8 Oct 2010
    Unknown

    CVE-2010-3885

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3227. Reason: This candidate is a duplicate of CVE-2010-3227. Notes: All CVE users should reference CVE-2010-3227 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 Oct 2010
    7.5
    High

    CVE-2010-2797

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in lib/translation.functions.php in CMS Made Simple before 1.8.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the default_cms_lang parameter to an admin script, as demonstrated by admin/addbookmark.php, a different vulnerability than CVE-2008-5642.

    Published: 8 Oct 2010
    5
    Medium

    CVE-2010-3743

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published: 8 Oct 2010
    4.3
    Medium

    CVE-2010-3882

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global Content, (3) Edit Global Content, (4) Add Article, (5) Add Category, (6) Add Field Definition, or (7) Add Shortcut module.

    Published: 8 Oct 2010
    6.8
    Medium

    CVE-2010-3883

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make permission modifications.

    Published: 8 Oct 2010
    6.8
    Medium

    CVE-2010-3884

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Oct 2010
    5.1
    Medium

    CVE-2010-3088

    Last Modified: 11 Apr 2025

    The notify function in pidgin-knotify.c in the pidgin-knotify plugin 0.2.1 and earlier for Pidgin allows remote attackers to execute arbitrary commands via shell metacharacters in a message.

    Published: 8 Oct 2010
    4
    Medium

    CVE-2010-4242

    Last Modified: 11 Apr 2025

    The hci_uart_tty_open function in the HCI UART driver (drivers/bluetooth/hci_ldisc.c) in the Linux kernel 2.6.36, and possibly other versions, does not verify whether the tty has a write operation, which allows local users to cause a denial of service (NULL pointer dereference) via vectors related to the Bluetooth driver.

    Published: 8 Oct 2010
    2.1
    Low

    CVE-2010-3861

    Last Modified: 11 Apr 2025

    The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than CVE-2010-2478.

    Published: 8 Oct 2010
    1.5
    Low

    CVE-2010-3321

    Last Modified: 11 Apr 2025

    RSA Authentication Client 2.0.x, 3.0, and 3.5.x before 3.5.3 does not properly handle a SENSITIVE or NON-EXTRACTABLE tag on a secret key object that is stored on a SecurID 800 authenticator, which allows local users to bypass intended access restrictions and read keys via unspecified PKCS#11 API requests.

    Published: 7 Oct 2010
    6.4
    Medium

    CVE-2010-3692

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directory traversal sequences in a Proxy Granting Ticket IOU (PGTiou) parameter.

    Published: 7 Oct 2010
    3.3
    Low

    CVE-2010-3691

    Last Modified: 11 Apr 2025

    PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.

    Published: 7 Oct 2010
    4.3
    Medium

    CVE-2010-3690

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Proxy Granting Ticket IOU (PGTiou) parameter to the callback function in client.php, (2) vectors involving functions that make getCallbackURL calls, or (3) vectors involving functions that make getURL calls.

    Published: 7 Oct 2010
    Unknown

    CVE-2010-3825

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 7 Oct 2010
    4.3
    Medium

    CVE-2010-3083

    Last Modified: 11 Apr 2025

    sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.

    Published: 7 Oct 2010
    Unknown

    CVE-2010-3799

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 7 Oct 2010
    Unknown

    CVE-2010-3815

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 7 Oct 2010
    Unknown

    CVE-2010-3807

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 7 Oct 2010
    4
    Medium

    CVE-2010-4756

    Last Modified: 3 Nov 2025

    The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

    Published: 7 Oct 2010
    6
    Medium

    CVE-2010-3781

    Last Modified: 11 Apr 2025

    The PL/php add-on 1.4 and earlier for PostgreSQL does not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, a related issue to CVE-2010-3433.

    Published: 6 Oct 2010
    4.3
    Medium

    CVE-2010-2367

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.cgi in AD-EDIT2 before 3.0.9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Oct 2010
    9.3
    Critical

    CVE-2010-3623

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 6 Oct 2010
    9.3
    Critical

    CVE-2010-3624

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via a crafted image.

    Published: 6 Oct 2010
    9.3
    Critical

    CVE-2010-3631

    Last Modified: 11 Apr 2025

    Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execute arbitrary code via unspecified vectors.

    Published: 6 Oct 2010
    9.3
    Critical

    CVE-2010-2888

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in an ActiveX control in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Windows allow attackers to execute arbitrary code via unknown vectors.

    Published: 6 Oct 2010
    3.5
    Low

    CVE-2010-3779

    Last Modified: 11 Apr 2025

    Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.beta2 grants the admin permission to the owner of each mailbox in a non-public namespace, which might allow remote authenticated users to bypass intended access restrictions by changing the ACL of a mailbox, as demonstrated by a symlinked shared mailbox.

    Published: 6 Oct 2010
    4
    Medium

    CVE-2010-3780

    Last Modified: 11 Apr 2025

    Dovecot 1.2.x before 1.2.15 allows remote authenticated users to cause a denial of service (master process outage) by simultaneously disconnecting many (1) IMAP or (2) POP3 sessions.

    Published: 6 Oct 2010
    7.5
    High

    CVE-2010-4657

    Last Modified: 21 Nov 2024

    PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.

    Published: 6 Oct 2010
    1.9
    Low

    CVE-2010-4073

    Last Modified: 11 Apr 2025

    The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c; and the (4) compat_sys_mq_open and (5) compat_sys_mq_getsetattr functions in ipc/compat_mq.c.

    Published: 6 Oct 2010
    1.9
    Low

    CVE-2010-4072

    Last Modified: 11 Apr 2025

    The copy_shmid_to_user function in ipc/shm.c in the Linux kernel before 2.6.37-rc1 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the shmctl system call and the "old shm interface."

    Published: 6 Oct 2010
    10
    Critical

    CVE-2010-3754

    Last Modified: 11 Apr 2025

    The FXCLI_OraBR_Exec_Command function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 uses values of packet fields to determine the content and length of data copied to memory, which allows remote attackers to execute arbitrary code via a crafted packet. NOTE: this might overlap CVE-2010-3059.

    Published: 5 Oct 2010
    5
    Medium

    CVE-2010-3755

    Last Modified: 11 Apr 2025

    The _DAS_ReadBlockReply function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via data in a TCP packet. NOTE: this might overlap CVE-2010-3060.

    Published: 5 Oct 2010
    5
    Medium

    CVE-2010-3756

    Last Modified: 11 Apr 2025

    The _CalcHashValueWithLength function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly validate an unspecified length value, which allows remote attackers to cause a denial of service (daemon crash) by sending data over TCP. NOTE: this might overlap CVE-2010-3060.

    Published: 5 Oct 2010
    10
    Critical

    CVE-2010-3759

    Last Modified: 11 Apr 2025

    FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 writes a certain value to a memory location specified by a UDP packet field, which allows remote attackers to execute arbitrary code via multiple requests. NOTE: this might overlap CVE-2010-3058.

    Published: 5 Oct 2010
    10
    Critical

    CVE-2010-3761

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-700. NOTE: this might overlap CVE-2010-3058 or CVE-2010-3059.

    Published: 5 Oct 2010
    4.3
    Medium

    CVE-2010-3763

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.

    Published: 5 Oct 2010
    3.5
    Low

    CVE-2010-3303

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in MantisBT before 1.2.3 allow remote authenticated administrators to inject arbitrary web script or HTML via (1) a plugin name, related to manage_plugin_uninstall.php; (2) an enumeration value or (3) a String value of a custom field, related to core/cfdefs/cfdef_standard.php; or a (4) project or (5) category name to print_all_bug_page_word.php.

    Published: 5 Oct 2010
    10
    Critical

    CVE-2010-3758

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allow remote attackers to execute arbitrary code via vectors involving the (1) AGI_SendToLog (aka _SendToLog) function; the (2) group, (3) workgroup, or (4) domain name field to the USER_S_AddADGroup function; the (5) user_path variable to the FXCLI_checkIndexDBLocation function; or (6) the _AGI_S_ActivateLTScriptReply (aka ActivateLTScriptReply) function. NOTE: this might overlap CVE-2010-3059.

    Published: 5 Oct 2010
    7.8
    High

    CVE-2010-3760

    Last Modified: 11 Apr 2025

    FastBackMount.exe in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 does not properly handle a certain failure to allocate memory, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash, and recovery failure) by specifying a large size value within TCP packet data. NOTE: this might overlap CVE-2010-3061.

    Published: 5 Oct 2010