CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2009-4985

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.

    Published: 25 Aug 2010
    6.8
    Medium

    CVE-2009-4986

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env parameter.

    Published: 25 Aug 2010
    7.5
    High

    CVE-2009-4987

    Last Modified: 11 Apr 2025

    admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211.

    Published: 25 Aug 2010
    4.3
    Medium

    CVE-2009-4990

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform report module 5.x and 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a submission.

    Published: 25 Aug 2010
    4.3
    Medium

    CVE-2009-4991

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to inject arbitrary web script or HTML via the job2 parameter.

    Published: 25 Aug 2010
    7.5
    High

    CVE-2009-4992

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 25 Aug 2010
    7.5
    High

    CVE-2009-4993

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in home.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 25 Aug 2010
    4.3
    Medium

    CVE-2009-4994

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in frmKBSearch.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Published: 25 Aug 2010
    6.8
    Medium

    CVE-2010-1808

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document.

    Published: 25 Aug 2010
    10
    Critical

    CVE-2010-2362

    Last Modified: 11 Apr 2025

    Winny 2.0b7.1 and earlier does not properly process node information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks.

    Published: 25 Aug 2010
    6.4
    Medium

    CVE-2010-2711

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the HP MagCloud app before 1.0.5 for the iPad allows remote attackers to read and modify MagCloud application data via unknown vectors.

    Published: 25 Aug 2010
    7.5
    High

    CVE-2009-4979

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in search.php in Photokorn Gallery 1.81 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) where[], (2) sort, (3) order, and (4) Match parameters.

    Published: 25 Aug 2010
    4.3
    Medium

    CVE-2009-4989

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbitrary web script or HTML via the txtkeyword parameter in a search action.

    Published: 25 Aug 2010
    4.3
    Medium

    CVE-2009-4995

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in frmTickets.aspx in SmarterTools SmarterTrack before 4.0.3504 allows remote attackers to inject arbitrary web script or HTML via the email address field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 Aug 2010
    6.8
    Medium

    CVE-2010-1801

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file.

    Published: 25 Aug 2010
    6.4
    Medium

    CVE-2010-1802

    Last Modified: 11 Apr 2025

    libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof www.example.com.

    Published: 25 Aug 2010
    5
    Medium

    CVE-2010-3122

    Last Modified: 11 Apr 2025

    The DevonIT thin-client management tool relies on a shared secret for authentication but transmits the secret in cleartext, which makes it easier for remote attackers to discover the secret value, and consequently obtain administrative control over client machines, by sniffing the network.

    Published: 25 Aug 2010
    10
    Critical

    CVE-2009-4988

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote attackers to execute arbitrary code via a long GIOP request to TCP port 30000.

    Published: 25 Aug 2010
    5
    Medium

    CVE-2010-1800

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses.

    Published: 25 Aug 2010
    7.5
    High

    CVE-2010-3121

    Last Modified: 11 Apr 2025

    Buffer overflow in tm-console-bin in the DevonIT thin-client management tool might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 25 Aug 2010
    3.3
    Low

    CVE-2010-2792

    Last Modified: 11 Apr 2025

    Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

    Published: 25 Aug 2010
    3.3
    Low

    CVE-2010-2794

    Last Modified: 11 Apr 2025

    The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.

    Published: 25 Aug 2010
    6.8
    Medium

    CVE-2010-2575

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the RLE decompression functionality in the TranscribePalmImageToJPEG function in generators/plucker/inplug/image.cpp in Okular in KDE SC 4.3.0 through 4.5.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image in a PDB file.

    Published: 25 Aug 2010
    6.8
    Medium

    CVE-2010-1526

    Last Modified: 11 Apr 2025

    Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; (2) a crafted JPEG file, related to the gdip_load_jpeg_image_internal function in jpegcodec.c; or (3) a crafted BMP file, related to the gdip_read_bmp_image function in bmpcodec.c, leading to heap-based buffer overflows.

    Published: 24 Aug 2010
    7.5
    High

    CVE-2010-3055

    Last Modified: 11 Apr 2025

    The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file, which allows remote attackers to execute arbitrary PHP code via a crafted POST request.

    Published: 24 Aug 2010
    10
    Critical

    CVE-2010-3111

    Last Modified: 11 Apr 2025

    Google Chrome before 6.0.472.53 does not properly mitigate an unspecified flaw in the Windows kernel, which has unknown impact and attack vectors, a different vulnerability than CVE-2010-2897.

    Published: 24 Aug 2010
    10
    Critical

    CVE-2010-3112

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127 does not properly implement file dialogs, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 24 Aug 2010
    5
    Medium

    CVE-2010-3118

    Last Modified: 11 Apr 2025

    The autosuggest feature in the Omnibox implementation in Google Chrome before 5.0.375.127 does not anticipate entry of passwords, which might allow remote attackers to obtain sensitive information by reading the network traffic generated by this feature.

    Published: 24 Aug 2010
    10
    Critical

    CVE-2010-3120

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127 does not properly implement the Geolocation feature, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 24 Aug 2010
    10
    Critical

    CVE-2010-2947

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that is inconsistent with the expected number of fields.

    Published: 24 Aug 2010
    4.3
    Medium

    CVE-2010-3056

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 2.11.x before 2.11.10.1 and 3.x before 3.3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) db_search.php, (2) db_sql.php, (3) db_structure.php, (4) js/messages.php, (5) libraries/common.lib.php, (6) libraries/database_interface.lib.php, (7) libraries/dbi/mysql.dbi.lib.php, (8) libraries/dbi/mysqli.dbi.lib.php, (9) libraries/db_info.inc.php, (10) libraries/sanitizing.lib.php, (11) libraries/sqlparser.lib.php, (12) server_databases.php, (13) server_privileges.php, (14) setup/config.php, (15) sql.php, (16) tbl_replace.php, and (17) tbl_sql.php.

    Published: 24 Aug 2010
    10
    Critical

    CVE-2010-3117

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via unknown vectors.

    Published: 24 Aug 2010
    5.1
    Medium

    CVE-2010-2940

    Last Modified: 11 Apr 2025

    The auth_send function in providers/ldap/ldap_auth.c in System Security Services Daemon (SSSD) 1.3.0, when LDAP authentication and anonymous bind are enabled, allows remote attackers to bypass the authentication requirements of pam_authenticate via an empty password.

    Published: 24 Aug 2010
    9.3
    Critical

    CVE-2009-3743

    Last Modified: 11 Apr 2025

    Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

    Published: 24 Aug 2010
    9.3
    Critical

    CVE-2010-3105

    Last Modified: 11 Apr 2025

    The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Aug 2010
    9.3
    Critical

    CVE-2010-3108

    Last Modified: 11 Apr 2025

    Buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code by using EMBED elements to pass parameters with long names.

    Published: 23 Aug 2010
    9.3
    Critical

    CVE-2010-3109

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code via a long operation parameter.

    Published: 23 Aug 2010
    7.1
    High

    CVE-2010-3107

    Last Modified: 11 Apr 2025

    A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.

    Published: 23 Aug 2010
    9.3
    Critical

    CVE-2010-1527

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a long call-back-url parameter in an op-client-interface-version action.

    Published: 23 Aug 2010
    9.3
    Critical

    CVE-2010-3106

    Last Modified: 11 Apr 2025

    The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.

    Published: 23 Aug 2010
    3.6
    Low

    CVE-2010-4819

    Last Modified: 11 Apr 2025

    The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."

    Published: 22 Aug 2010
    Unknown

    CVE-2010-2533

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2621. Reason: This candidate is a reservation duplicate of CVE-2010-2621. Notes: All CVE users should reference CVE-2010-2621 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3101

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FTPx Corp FTP Explorer 10.5.19.1 for Windows, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3102

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SiteDesigner Technologies, Inc. 3D-FTP Client 9.0 build 2, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3103

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FTPGetter Team FTPGetter 3.51.0.05, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3104

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in DeskShare AutoFTP Manager 4.31, and probably earlier versions, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    10
    Critical

    CVE-2010-2710

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-1795

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Apple iTunes before 9.1, when running on Windows 7, Vista, and XP, allows local users and possibly remote attackers to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3096

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via "..\" (dot dot backslash) sequences in a filename.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3100

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Porta+ FTP Client 4.1, and possibly other versions, allows remote FTP servers to overwrite arbitrary files via a directory traversal sequences in a filename.

    Published: 20 Aug 2010