CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-3200

    Last Modified: 11 Apr 2025

    MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.

    Published: 20 Sept 2010
    4.3
    Medium

    CVE-2010-3262

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.

    Published: 20 Sept 2010
    9.8
    Critical

    CVE-2010-4478

    Last Modified: 28 May 2026

    OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

    Published: 20 Sept 2010
    5.1
    Medium

    CVE-2010-0405

    Last Modified: 11 Apr 2025

    Integer overflow in the BZ2_decompress function in decompress.c in bzip2 and libbzip2 before 1.0.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted compressed file.

    Published: 20 Sept 2010
    5.5
    Medium

    CVE-2010-4238

    Last Modified: 11 Apr 2025

    The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a denial of service (host OS panic) via an attempted access to a virtual CD-ROM device through the blkback driver. NOTE: some of these details are obtained from third party information.

    Published: 20 Sept 2010
    6.8
    Medium

    CVE-2010-4697

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Zend engine in PHP before 5.2.15 and 5.3.x before 5.3.4 might allow context-dependent attackers to cause a denial of service (heap memory corruption) or have unspecified other impact via vectors related to use of __set, __get, __isset, and __unset methods on objects accessed by a reference.

    Published: 18 Sept 2010
    9.3
    Critical

    CVE-2011-3194

    Last Modified: 11 Apr 2025

    Buffer overflow in the TIFF reader in gui/image/qtiffhandler.cpp in Qt 4.7.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the TIFFTAG_SAMPLESPERPIXEL tag in a greyscale TIFF image with multiple samples per pixel.

    Published: 18 Sept 2010
    4.3
    Medium

    CVE-2010-3012

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: this issue was originally assigned CVE-2010-3010 due to a CNA error.

    Published: 17 Sept 2010
    5
    Medium

    CVE-2010-3456

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 17 Sept 2010
    7.5
    High

    CVE-2010-3458

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3459

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ajax WebMail interface in AXIGEN Mail Server before 7.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Sept 2010
    5
    Medium

    CVE-2010-3460

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL.

    Published: 17 Sept 2010
    7.5
    High

    CVE-2010-3461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Publisher module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL commands via the artid parameter in a printarticle action to mod.php, a different vector than CVE-2007-3394.

    Published: 17 Sept 2010
    6.8
    Medium

    CVE-2010-3464

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admin/manager_users.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests, as demonstrated by adding administrative users via the save_admin action to admin/index.php.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3465

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in XSE Shopping Cart 1.5.2.1 and 1.5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to Default.aspx and the (2) type parameter to SearchResults.aspx.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3466

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in the hosted_signup module in NetArt Media iBoutique.MALL 1.2 allows remote attackers to inject arbitrary web script or HTML via the tmpl parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2010
    6.8
    Medium

    CVE-2010-3467

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3455

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in AChecker 1.0 allows remote attackers to inject arbitrary web script or HTML via the uri parameter.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3457

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] parameter in the post comments feature in articles/a-primer-to-symphony-2s-default-theme/ or (2) send-email[recipient] parameter to about/. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3463

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in modules/search/search.class.php in SantaFox 2.02, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the search parameter to search.html.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3462

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in backend/plugin/Registration/index.php in Mollify 1.6, 1.6.5.5, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the confirm parameter. NOTE: some of these details are obtained from third party information.

    Published: 17 Sept 2010
    5
    Medium

    CVE-2010-3011

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in HP System Management Homepage (SMH) before 6.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 17 Sept 2010
    2.1
    Low

    CVE-2010-3073

    Last Modified: 11 Apr 2025

    SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.

    Published: 17 Sept 2010
    2.1
    Low

    CVE-2010-3074

    Last Modified: 11 Apr 2025

    SSL_Cipher.cpp in EncFS before 1.7.0 uses an improper combination of an AES cipher and a CBC cipher mode for encrypted filesystems, which allows local users to obtain sensitive information via a watermark attack.

    Published: 17 Sept 2010
    5
    Medium

    CVE-2010-3075

    Last Modified: 11 Apr 2025

    EncFS before 1.7.0 encrypts multiple blocks by means of the CFB cipher mode with the same initialization vector, which makes it easier for local users to obtain sensitive information via calculations involving recovery of XORed data, as demonstrated by an attack on encrypted data in which the last block contains only one byte.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3324

    Last Modified: 11 Apr 2025

    The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.

    Published: 17 Sept 2010
    8.8
    High

    CVE-2010-1822

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3 and Google Chrome before 6.0.472.62, does not properly perform a cast of an unspecified variable, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG element in a non-SVG document.

    Published: 17 Sept 2010
    4.3
    Medium

    CVE-2010-3418

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) car_id parameter to index.php and (2) y parameter to include/images.php.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3419

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the current_user_id parameter to (1) familynews.php and (2) settings.php.

    Published: 16 Sept 2010
    4.3
    Medium

    CVE-2010-3420

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Products_Results.php in PowerStore 3.0 allows remote attackers to inject arbitrary web script or HTML via the totalRows_WADAProducts parameter.

    Published: 16 Sept 2010
    4.3
    Medium

    CVE-2010-3421

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in AffiliateLogin.asp in ProductCart 3, 4.1 SP1, and possibly other versions allows remote attackers to inject arbitrary web script or HTML via the redirectUrl parameter, a different vector than CVE-2004-2174 and CVE-2005-0995. NOTE: some of these details are obtained from third party information.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3422

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JGen (com_jgen) component 0.9.33 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a view action to index.php.

    Published: 16 Sept 2010
    4.3
    Medium

    CVE-2010-3425

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly other 5.3 versions, allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3426

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Published: 16 Sept 2010
    4.3
    Medium

    CVE-2010-3427

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3428

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.

    Published: 16 Sept 2010
    4.3
    Medium

    CVE-2010-3424

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/sources/classes/bbcode/custom/defaults.php in Invision Power Board (IP.Board) 3.1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3423

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Yr Weatherdata module for Drupal 6.x before 6.x-1.6 allows remote attackers to execute arbitrary SQL commands via the sorting method.

    Published: 16 Sept 2010
    1.7
    Low

    CVE-2010-3406

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in sa_snap in the bos.esagent fileset in IBM AIX 5.3 allows local users to leverage system group membership and delete files via unknown vectors.

    Published: 16 Sept 2010
    5
    Medium

    CVE-2010-3411

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.59 on Linux does not properly handle cursors, which might allow attackers to cause a denial of service (assertion failure) via unspecified vectors.

    Published: 16 Sept 2010
    9.3
    Critical

    CVE-2010-3412

    Last Modified: 11 Apr 2025

    Race condition in the console implementation in Google Chrome before 6.0.472.59 has unspecified impact and attack vectors.

    Published: 16 Sept 2010
    5
    Medium

    CVE-2010-3413

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the pop-up blocking functionality in Google Chrome before 6.0.472.59 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 16 Sept 2010
    10
    Critical

    CVE-2010-3414

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.59 on Mac OS X does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. NOTE: this issue exists because of an incorrect fix for CVE-2010-3112 on Mac OS X.

    Published: 16 Sept 2010
    5
    Medium

    CVE-2010-3417

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.59 does not prompt the user before granting access to the extension history, which allows attackers to obtain potentially sensitive information via unspecified vectors.

    Published: 16 Sept 2010
    6.8
    Medium

    CVE-2010-3405

    Last Modified: 11 Apr 2025

    Buffer overflow in sa_snap in the bos.esagent fileset in IBM AIX 6.1, 5.3, and earlier and VIOS 2.1, 1.5, and earlier allows local users to leverage system group membership and gain privileges via unspecified vectors.

    Published: 16 Sept 2010
    9.3
    Critical

    CVE-2010-3407

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

    Published: 16 Sept 2010
    10
    Critical

    CVE-2010-3415

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 16 Sept 2010
    9.8
    Critical

    CVE-2010-3416

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 16 Sept 2010
    9.3
    Critical

    CVE-2010-3403

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Qualcomm eXtensible Diagnostic Monitor (QXDM) 03.09.19 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .isf file.

    Published: 16 Sept 2010
    7.5
    High

    CVE-2010-3404

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in eshtery CMS (aka eshtery.com) allow remote attackers to execute arbitrary SQL commands via the (1) Criteria field in an unspecified form related to catlgsearch.aspx or (2) user name to an unspecified form related to adminlogin.aspx.

    Published: 16 Sept 2010