CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2010-3072

    Last Modified: 11 Apr 2025

    The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

    Published: 3 Sept 2010
    6.1
    Medium

    CVE-2010-5312

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.

    Published: 3 Sept 2010
    4.3
    Medium

    CVE-2010-3259

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.

    Published: 2 Sept 2010
    7.8
    High

    CVE-2010-2960

    Last Modified: 11 Apr 2025

    The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a KEYCTL_SESSION_TO_PARENT argument to the keyctl function.

    Published: 2 Sept 2010
    4.3
    Medium

    CVE-2010-3198

    Last Modified: 11 Apr 2025

    ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

    Published: 2 Sept 2010
    9.3
    Critical

    CVE-2010-3257

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving element focus.

    Published: 2 Sept 2010
    9.3
    Critical

    CVE-2010-3255

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.53 and webkitgtk before 1.2.6 do not properly handle counter nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 2 Sept 2010
    2.1
    Low

    CVE-2010-3477

    Last Modified: 11 Apr 2025

    The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel memory via vectors involving a dump operation. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2942.

    Published: 1 Sept 2010
    10
    Critical

    CVE-2010-3193

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.

    Published: 31 Aug 2010
    5
    Medium

    CVE-2010-3195

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 on Windows Server 2008 allows attackers to cause a denial of service (trap) via vectors involving "special group and user enumeration."

    Published: 31 Aug 2010
    3.5
    Low

    CVE-2010-3196

    Last Modified: 11 Apr 2025

    IBM DB2 9.7 before FP2, when AUTO_REVAL is IMMEDIATE, allows remote authenticated users to cause a denial of service (loss of privileges) to a view owner by defining a dependent view.

    Published: 31 Aug 2010
    4.3
    Medium

    CVE-2010-2365

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs2 before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Aug 2010
    4.3
    Medium

    CVE-2010-2364

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Free CGI Moo moobbs before 1.03 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Aug 2010
    7.5
    High

    CVE-2010-3194

    Last Modified: 11 Apr 2025

    The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via unspecified vectors related to overwriting files owned by an instance owner.

    Published: 31 Aug 2010
    5
    Medium

    CVE-2010-3197

    Last Modified: 11 Apr 2025

    IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 31 Aug 2010
    7.8
    High

    CVE-2010-3190

    Last Modified: 28 May 2026

    Untrusted search path vulnerability in the Microsoft Foundation Class (MFC) Library in Microsoft Visual Studio .NET 2003 SP1; Visual Studio 2005 SP1, 2008 SP1, and 2010; Visual C++ 2005 SP1, 2008 SP1, and 2010; and Exchange Server 2010 Service Pack 3, 2013, and 2013 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory during execution of an MFC application such as AtlTraceTool8.exe (aka ATL MFC Trace Tool), as demonstrated by a directory that contains a TRC, cur, rs, rct, or res file, aka "MFC Insecure Library Loading Vulnerability."

    Published: 31 Aug 2010
    9.3
    Critical

    CVE-2010-1818

    Last Modified: 11 Apr 2025

    The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.

    Published: 31 Aug 2010
    9.3
    Critical

    CVE-2010-3191

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Captivate 5.0.0.596, and possibly other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .cptx file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 31 Aug 2010
    7.5
    High

    CVE-2010-3188

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.aspx in BugTracker.NET 3.4.3 and earlier allows remote attackers to execute arbitrary SQL commands via a custom field to the search page.

    Published: 31 Aug 2010
    9.3
    Critical

    CVE-2010-3189

    Last Modified: 11 Apr 2025

    The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.

    Published: 31 Aug 2010
    4.9
    Medium

    CVE-2010-2954

    Last Modified: 11 Apr 2025

    The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via multiple unsuccessful calls to bind on an AF_IRDA (aka PF_IRDA) socket.

    Published: 31 Aug 2010
    4.3
    Medium

    CVE-2010-3070

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes.

    Published: 31 Aug 2010
    7.5
    High

    CVE-2010-3035

    Last Modified: 22 Apr 2026

    Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in August 2010 with attribute type code 99, aka Bug ID CSCti62211.

    Published: 30 Aug 2010
    6.8
    Medium

    CVE-2010-2712

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Software Distributor (sd) in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges via unknown vectors.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-0116

    Last Modified: 11 Apr 2025

    Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-0117

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows do not properly handle dimensions during YUV420 transformations, which might allow remote attackers to execute arbitrary code via crafted MP4 content.

    Published: 30 Aug 2010
    5.8
    Medium

    CVE-2010-2363

    Last Modified: 11 Apr 2025

    The IPv6 Unicast Reverse Path Forwarding (RPF) implementation on the SEIL/X1, SEIL/X2, and SEIL/B1 routers with firmware 1.00 through 2.73, when strict mode is used, does not properly drop packets, which might allow remote attackers to bypass intended access restrictions via a spoofed IP address.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-2996

    Last Modified: 11 Apr 2025

    Array index error in RealNetworks RealPlayer 11.0 through 11.1 on Windows allows remote attackers to execute arbitrary code via a malformed header in a RealMedia .IVR file.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-3001

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in an ActiveX control in the Internet Explorer (IE) plugin in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows has unknown impact and attack vectors related to "multiple browser windows."

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-3002

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in RealNetworks RealPlayer 11.0 through 11.1 allows attackers to bypass intended access restrictions on files via unknown vectors.

    Published: 30 Aug 2010
    10
    Critical

    CVE-2010-3186

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 7.x before 7.0.0.13, and WebSphere Application Server Feature Pack for Web Services 6.1.0.9 through 6.1.0.32, when a JAX-WS application is used, does not properly handle an IncludeTimestamp setting in the WS-Security policy, which has unspecified impact and remote attack vectors.

    Published: 30 Aug 2010
    10
    Critical

    CVE-2010-3187

    Last Modified: 11 Apr 2025

    Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-0120

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allows remote attackers to execute arbitrary code via large size values in QCP audio content.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-3000

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.

    Published: 30 Aug 2010
    6.9
    Medium

    CVE-2010-2945

    Last Modified: 11 Apr 2025

    The default configuration of SLiM before 1.3.2 places ./ (dot slash) at the beginning of the default_path option, which might allow local users to gain privileges via a Trojan horse program in the current working directory, related to slim.conf and cfg.cpp.

    Published: 30 Aug 2010
    9.3
    Critical

    CVE-2010-3139

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse imm.dll that is located in the same folder as a .grp file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3141

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3143

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .contact, .group, .p7c, .vcf, or .wab file. NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3147.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3148

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3149

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse qtcf.dll that is located in the same folder as an ADCP file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3150

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as a .pproj, .prfpset, .prexport, .prm, .prmp, .prpreset, .prproj, .prsl, .prtl, or .vpr file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3153

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe InCopy CS5 7.0.2 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an .indl, .indp, .indt, or .inx file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3140

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll that is located in the same folder as an ISP file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3142

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3144

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3146

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3147

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3151

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3152

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.

    Published: 27 Aug 2010
    9.3
    Critical

    CVE-2010-3154

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .mxi or .mxp file.

    Published: 27 Aug 2010