CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2010-3008

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 on Windows allows local users to gain privileges or cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3007.

    Published: 13 Sept 2010
    4.3
    Medium

    CVE-2010-3317

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Sept 2010
    5
    Medium

    CVE-2010-3318

    Last Modified: 11 Apr 2025

    IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 transmits passwords in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 13 Sept 2010
    5
    Medium

    CVE-2010-3319

    Last Modified: 11 Apr 2025

    IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 places a session token in the URI, which might allow remote attackers to obtain sensitive information by reading a Referer log file.

    Published: 13 Sept 2010
    6.8
    Medium

    CVE-2010-3320

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM Records Manager (RM) 4.5.x before 4.5.1.1-IER-FP001 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 13 Sept 2010
    4.3
    Medium

    CVE-2010-2366

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in futomi CGI Cafe Access Analyzer CGI Professional, and Standard 4.0.2 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Sept 2010
    4.3
    Medium

    CVE-2010-2952

    Last Modified: 11 Apr 2025

    Apache Traffic Server before 2.0.1, and 2.1.x before 2.1.2-unstable, does not properly choose DNS source ports and transaction IDs, and does not properly use DNS query fields to validate responses, which makes it easier for man-in-the-middle attackers to poison the internal DNS cache via a crafted response.

    Published: 13 Sept 2010
    5
    Medium

    CVE-2010-3445

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the dissect_ber_unknown function in epan/dissectors/packet-ber.c in the BER dissector in Wireshark 1.4.x before 1.4.1 and 1.2.x before 1.2.12 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a long string in an unknown ASN.1/BER encoded packet, as demonstrated using SNMP.

    Published: 13 Sept 2010
    9.3
    Critical

    CVE-2010-2884

    Last Modified: 11 Apr 2025

    Adobe Flash Player 10.1.82.76 and earlier on Windows, Mac OS X, Linux, and Solaris and 10.1.92.10 on Android; authplay.dll in Adobe Reader and Acrobat 9.x before 9.4; and authplay.dll in Adobe Reader and Acrobat 8.x before 8.2.5 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in September 2010.

    Published: 13 Sept 2010
    2.1
    Low

    CVE-2010-3296

    Last Modified: 11 Apr 2025

    The cxgb_extension_ioctl function in drivers/net/cxgb3/cxgb3_main.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a CHELSIO_GET_QSET_NUM ioctl call.

    Published: 11 Sept 2010
    2.1
    Low

    CVE-2010-3298

    Last Modified: 11 Apr 2025

    The hso_get_count function in drivers/net/usb/hso.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.

    Published: 11 Sept 2010
    2.1
    Low

    CVE-2010-3297

    Last Modified: 11 Apr 2025

    The eql_g_master_cfg function in drivers/net/eql.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an EQL_GETMASTRCFG ioctl call.

    Published: 11 Sept 2010
    4.3
    Medium

    CVE-2010-3263

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in setup/frames/index.inc.php in the setup script in phpMyAdmin 3.x before 3.3.7 allows remote attackers to inject arbitrary web script or HTML via a server name.

    Published: 10 Sept 2010
    9.3
    Critical

    CVE-2010-3199

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a file that is processed by Tortoise. NOTE: this is only a vulnerability when a file extension is associated with TortoiseProc or TortoiseMerge, which is not the default.

    Published: 10 Sept 2010
    6.9
    Medium

    CVE-2010-1805

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Trojan horse explorer.exe (aka Windows Explorer) program in a directory containing a file that had been downloaded by Safari.

    Published: 10 Sept 2010
    7.8
    High

    CVE-2010-3006

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP ProLiant G6 Lights-Out 100 Remote Management card with firmware before 4.06 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 10 Sept 2010
    7.8
    High

    CVE-2010-0574

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 3.2 before 3.2.215.0; 4.1 and 4.2 before 4.2.205.0; 4.1M and 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.188.0; and 5.2 before 5.2.193.11 allows remote attackers to cause a denial of service (device reload) via a crafted IKE packet, aka Bug ID CSCta56653.

    Published: 10 Sept 2010
    5
    Medium

    CVE-2010-0575

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-3034.

    Published: 10 Sept 2010
    6.8
    Medium

    CVE-2010-2841

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 4.2 before 4.2.209.0; 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.196.0; and 5.2 before 5.2.193.11 allows remote authenticated users to cause a denial of service (device reload) via crafted HTTP packets that trigger invalid arguments to the emweb component, aka Bug ID CSCtd16938.

    Published: 10 Sept 2010
    9
    Critical

    CVE-2010-2842

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2843 and CVE-2010-3033.

    Published: 10 Sept 2010
    9
    Critical

    CVE-2010-2843

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-3033.

    Published: 10 Sept 2010
    2.6
    Low

    CVE-2010-2957

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Serendipity before 1.5.4, when "Remember me" logins are enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Sept 2010
    4.3
    Medium

    CVE-2010-3003

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Sept 2010
    9
    Critical

    CVE-2010-3033

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and modify the configuration, and possibly obtain administrative privileges, via unspecified vectors, a different vulnerability than CVE-2010-2842 and CVE-2010-2843.

    Published: 10 Sept 2010
    5
    Medium

    CVE-2010-3034

    Last Modified: 11 Apr 2025

    Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a different vulnerability than CVE-2010-0575.

    Published: 10 Sept 2010
    Unknown

    CVE-2010-3278

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3110. Reason: This candidate is a reservation duplicate of CVE-2010-3110. Notes: All CVE users should reference CVE-2010-3110 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 Sept 2010
    6.8
    Medium

    CVE-2010-1781

    Last Modified: 11 Apr 2025

    Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.

    Published: 9 Sept 2010
    3.5
    Low

    CVE-2010-1810

    Last Modified: 11 Apr 2025

    FaceTime in Apple iOS before 4.1 on the iPhone and iPod touch does not properly handle invalid X.509 certificates, which allows man-in-the-middle attackers to redirect calls via a crafted certificate.

    Published: 9 Sept 2010
    6.8
    Medium

    CVE-2010-1811

    Last Modified: 11 Apr 2025

    ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF file.

    Published: 9 Sept 2010
    7.2
    High

    CVE-2010-3007

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.

    Published: 9 Sept 2010
    5.7
    Medium

    CVE-2010-3017

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in RSA Access Manager Agent 4.7.1 before 4.7.1.7, when RSA Adaptive Authentication Integration is enabled, allows remote attackers to bypass authentication and obtain sensitive information via unknown vectors.

    Published: 9 Sept 2010
    4.3
    Medium

    CVE-2010-3018

    Last Modified: 11 Apr 2025

    RSA Access Manager Server 5.5.3 before 5.5.3.172, 6.0.4 before 6.0.4.53, and 6.1 before 6.1.2.01 does not properly perform cache updates, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 9 Sept 2010
    6.8
    Medium

    CVE-2010-1817

    Last Modified: 11 Apr 2025

    Buffer overflow in ImageIO in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file.

    Published: 9 Sept 2010
    10
    Critical

    CVE-2010-1809

    Last Modified: 11 Apr 2025

    The Accessibility component in Apple iOS before 4.1 on the iPhone and iPod touch does not perform the expected VoiceOver announcement associated with the location services icon, which has unspecified impact and attack vectors.

    Published: 9 Sept 2010
    4.3
    Medium

    CVE-2010-2763

    Last Modified: 11 Apr 2025

    The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox before 3.5.12, Thunderbird before 3.0.7, and SeaMonkey before 2.0.7 does not properly restrict scripted functions, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted function.

    Published: 9 Sept 2010
    9.3
    Critical

    CVE-2010-2770

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.

    Published: 9 Sept 2010
    3.5
    Low

    CVE-2010-3089

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman before 2.1.14rc1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) the list information field or (2) the list description field.

    Published: 9 Sept 2010
    5
    Medium

    CVE-2010-3492

    Last Modified: 11 Apr 2025

    The asyncore module in Python before 3.2 does not properly handle unsuccessful calls to the accept function, and does not have accompanying documentation describing how daemon applications should handle unsuccessful calls to the accept function, which makes it easier for remote attackers to conduct denial of service attacks that terminate these applications via network connections.

    Published: 9 Sept 2010
    5.5
    Medium

    CVE-2010-3079

    Last Modified: 11 Apr 2025

    kernel/trace/ftrace.c in the Linux kernel before 2.6.35.5, when debugfs is enabled, does not properly handle interaction between mutex possession and llseek operations, which allows local users to cause a denial of service (NULL pointer dereference and outage of all function tracing files) via an lseek call on a file descriptor associated with the set_ftrace_filter file.

    Published: 9 Sept 2010
    4.3
    Medium

    CVE-2010-2958

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in libraries/Error.class.php in phpMyAdmin 3.x before 3.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to a PHP backtrace and error messages (aka debugging messages), a different vulnerability than CVE-2010-3056.

    Published: 8 Sept 2010
    7.5
    High

    CVE-2010-3004

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-3005

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Operations Agent 7.36 and 8.6 on Windows allows local users to gain privileges via unknown vectors.

    Published: 8 Sept 2010
    2.1
    Low

    CVE-2010-3264

    Last Modified: 11 Apr 2025

    The engine installer in Novell Identity Manager (aka IDM) 3.6.1 stores admin tree credentials in /tmp/idmInstall.log, which allows local users to obtain sensitive information by reading this file.

    Published: 8 Sept 2010
    7.3
    High

    CVE-2010-2883

    Last Modified: 21 Apr 2026

    Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-1813

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-1814

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving form menus.

    Published: 8 Sept 2010
    7.2
    High

    CVE-2010-3080

    Last Modified: 11 Apr 2025

    Double free vulnerability in the snd_seq_oss_open function in sound/core/seq/oss/seq_oss_init.c in the Linux kernel before 2.6.36-rc4 might allow local users to cause a denial of service or possibly have unspecified other impact via an unsuccessful attempt to open the /dev/sequencer device.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-1812

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving selections.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-1815

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving scrollbars.

    Published: 8 Sept 2010
    6.8
    Medium

    CVE-2010-3213

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows remote attackers to hijack the authentication of e-mail users for requests that perform Outlook requests, as demonstrated by setting the auto-forward rule.

    Published: 7 Sept 2010