CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2010-3757

    Last Modified: 11 Apr 2025

    Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059.

    Published: 5 Oct 2010
    3.5
    Low

    CVE-2010-2535

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Back End in Joomla! 1.5.x before 1.5.20 allow remote authenticated users to inject arbitrary web script or HTML via administrator screens.

    Published: 5 Oct 2010
    10
    Critical

    CVE-2010-3731

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.

    Published: 5 Oct 2010
    3.5
    Low

    CVE-2010-3732

    Last Modified: 11 Apr 2025

    The DRDA Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (database server ABEND) by using the client CLI on Linux, UNIX, or Windows for executing a prepared statement with a large number of parameter markers.

    Published: 5 Oct 2010
    7.2
    High

    CVE-2010-3733

    Last Modified: 11 Apr 2025

    The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow local users to gain privileges by modifying this file.

    Published: 5 Oct 2010
    5
    Medium

    CVE-2010-3734

    Last Modified: 11 Apr 2025

    The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easier for attackers to obtain access via a brute-force attack.

    Published: 5 Oct 2010
    2.1
    Low

    CVE-2010-3735

    Last Modified: 11 Apr 2025

    The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.

    Published: 5 Oct 2010
    4
    Medium

    CVE-2010-3736

    Last Modified: 11 Apr 2025

    Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a, when the connection concentrator is enabled, allows remote authenticated users to cause a denial of service (heap memory consumption) by using a different code page than the database server.

    Published: 5 Oct 2010
    3.5
    Low

    CVE-2010-3737

    Last Modified: 11 Apr 2025

    Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.

    Published: 5 Oct 2010
    4
    Medium

    CVE-2010-3740

    Last Modified: 11 Apr 2025

    The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.

    Published: 5 Oct 2010
    4.7
    Medium

    CVE-2010-3741

    Last Modified: 11 Apr 2025

    The offline backup mechanism in Research In Motion (RIM) BlackBerry Desktop Software uses single-iteration PBKDF2, which makes it easier for local users to decrypt a .ipd file via a brute-force attack.

    Published: 5 Oct 2010
    7.5
    High

    CVE-2010-3742

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) meta or (2) phpincdir parameter, a different issue than CVE-2010-3307.

    Published: 5 Oct 2010
    7.5
    High

    CVE-2010-3307

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) body, (2) footer, (3) header, (4) menu_left, or (5) menu_right parameter.

    Published: 5 Oct 2010
    9.8
    Critical

    CVE-2010-3729

    Last Modified: 11 Apr 2025

    The SPDY protocol implementation in Google Chrome before 6.0.472.62 does not properly manage buffers, which might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 5 Oct 2010
    8.8
    High

    CVE-2010-3730

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.62 does not properly use information about the origin of a document to manage properties, which allows remote attackers to have an unspecified impact via a crafted web site, related to a "property pollution" issue.

    Published: 5 Oct 2010
    5
    Medium

    CVE-2010-3738

    Last Modified: 11 Apr 2025

    The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, instead of a USERID and an AUTHID value corresponding to the logged-in user account, which makes it easier for remote authenticated users to execute Audit administration commands without discovery.

    Published: 5 Oct 2010
    6.4
    Medium

    CVE-2010-3739

    Last Modified: 11 Apr 2025

    The audit facility in the Security component in IBM DB2 UDB 9.5 before FP6a uses instance-level audit settings to capture connection (aka CONNECT and AUTHENTICATION) events in certain circumstances in which database-level audit settings were intended, which might make it easier for remote attackers to connect without discovery.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-2887

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Adobe Reader and Acrobat 9.x before 9.4 on Linux allow attackers to gain privileges via unknown vectors.

    Published: 5 Oct 2010
    6
    Medium

    CVE-2010-3433

    Last Modified: 11 Apr 2025

    The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8.4 before 8.4.5, and 9.0 before 9.0.1 do not properly protect script execution by a different SQL user identity within the same session, which allows remote authenticated users to gain privileges via crafted script code in a SECURITY DEFINER function, as demonstrated by (1) redefining standard functions or (2) redefining operators, a different vulnerability than CVE-2010-1168, CVE-2010-1169, CVE-2010-1170, and CVE-2010-1447.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3619

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3625

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3626

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-2889.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3627

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via unknown vectors.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3629

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3620.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3630

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3632

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3658.

    Published: 5 Oct 2010
    4.3
    Medium

    CVE-2010-3656

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3657.

    Published: 5 Oct 2010
    6.5
    Medium

    CVE-2010-1322

    Last Modified: 11 Apr 2025

    The merge_authdata function in kdc_authdata.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.8.x before 1.8.4 does not properly manage an index into an authorization-data list, which allows remote attackers to cause a denial of service (daemon crash), or possibly obtain sensitive information, spoof authorization, or execute arbitrary code, via a TGS request that triggers an uninitialized pointer dereference, as demonstrated by a request from a Windows Active Directory client.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-2890

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3621

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3622, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3622

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3628, CVE-2010-3632, and CVE-2010-3658.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-2889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted font, a different vulnerability than CVE-2010-3626.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3620

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3629.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3628

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3632, and CVE-2010-3658.

    Published: 5 Oct 2010
    4.3
    Medium

    CVE-2010-3657

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.

    Published: 5 Oct 2010
    9.3
    Critical

    CVE-2010-3658

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2890, CVE-2010-3619, CVE-2010-3621, CVE-2010-3622, CVE-2010-3628, and CVE-2010-3632.

    Published: 5 Oct 2010
    6.9
    Medium

    CVE-2010-3374

    Last Modified: 11 Apr 2025

    Qt Creator before 2.0.1 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

    Published: 4 Oct 2010
    6
    Medium

    CVE-2010-3315

    Last Modified: 11 Apr 2025

    authz.c in the mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion 1.5.x before 1.5.8 and 1.6.x before 1.6.13, when SVNPathAuthz short_circuit is enabled, does not properly handle a named repository as a rule scope, which allows remote authenticated users to bypass intended access restrictions via svn commands.

    Published: 4 Oct 2010
    7.2
    High

    CVE-2010-2962

    Last Modified: 11 Apr 2025

    drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via crafted use of the ioctl interface, related to (1) pwrite and (2) pread operations.

    Published: 3 Oct 2010
    4.9
    Medium

    CVE-2010-4707

    Last Modified: 11 Apr 2025

    The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

    Published: 3 Oct 2010
    4.9
    Medium

    CVE-2010-4706

    Last Modified: 11 Apr 2025

    The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

    Published: 3 Oct 2010
    5.5
    Medium

    CVE-2010-3706

    Last Modified: 11 Apr 2025

    plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving the private namespace of a user, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

    Published: 1 Oct 2010
    5.5
    Medium

    CVE-2010-3707

    Last Modified: 11 Apr 2025

    plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permissions granted by another ACL entry, instead of a directive to replace the permissions granted by another ACL entry, in certain circumstances involving more specific entries that occur after less specific entries, which allows remote authenticated users to bypass intended access restrictions via a request to read or modify a mailbox.

    Published: 1 Oct 2010
    5
    Medium

    CVE-2010-1623

    Last Modified: 11 Apr 2025

    Memory leak in the apr_brigade_split_line function in buckets/apr_brigade.c in the Apache Portable Runtime Utility library (aka APR-util) before 1.3.10, as used in the mod_reqtimeout module in the Apache HTTP Server and other software, allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors related to the destruction of an APR bucket.

    Published: 1 Oct 2010
    8.3
    High

    CVE-2010-3705

    Last Modified: 11 Apr 2025

    The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.

    Published: 1 Oct 2010
    6.8
    Medium

    CVE-2010-3429

    Last Modified: 11 Apr 2025

    flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."

    Published: 30 Sept 2010
    9.3
    Critical

    CVE-2010-3434

    Last Modified: 11 Apr 2025

    Buffer overflow in the find_stream_bounds function in pdf.c in libclamav in ClamAV before 0.96.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document. NOTE: some of these details are obtained from third party information.

    Published: 30 Sept 2010
    7.1
    High

    CVE-2010-2537

    Last Modified: 11 Apr 2025

    The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.

    Published: 30 Sept 2010
    5.5
    Medium

    CVE-2010-2538

    Last Modified: 11 Apr 2025

    Integer overflow in the btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 might allow local users to obtain sensitive information via a BTRFS_IOC_CLONE_RANGE ioctl call.

    Published: 30 Sept 2010
    9.3
    Critical

    CVE-2010-3311

    Last Modified: 11 Apr 2025

    Integer overflow in base/ftstream.c in libXft (aka the X FreeType library) in FreeType before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted Compact Font Format (CFF) font file that triggers a heap-based buffer overflow, related to an "input stream position error" issue, a different vulnerability than CVE-2010-1797.

    Published: 30 Sept 2010