CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2010-3098

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in IoRush Software FTP Rush 1.1.3 and possibly earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    6.9
    Medium

    CVE-2010-1768

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Apple iTunes before 9.1 allows local users to gain console privileges via vectors related to log files, "insecure file operation," and syncing an iPhone, iPad, or iPod touch.

    Published: 20 Aug 2010
    7.5
    High

    CVE-2010-2944

    Last Modified: 11 Apr 2025

    The authenticate function in LDAPUserFolder/LDAPUserFolder.py in zope-ldapuserfolder 2.9-1 does not verify the password for the emergency account, which allows remote attackers to gain privileges.

    Published: 20 Aug 2010
    1.2
    Low

    CVE-2010-3014

    Last Modified: 11 Apr 2025

    The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3097

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in WinFrigate Frigate 3 FTP client 3.36 and earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.

    Published: 20 Aug 2010
    9.3
    Critical

    CVE-2010-3099

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SmartSoft Ltd SmartFTP Client 4.0.1124.0, and possibly other versions before 4.0 Build 1133, allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party information.

    Published: 20 Aug 2010
    5
    Medium

    CVE-2010-2937

    Last Modified: 11 Apr 2025

    The ReadMetaFromId3v2 function in taglib.cpp in the TagLib plugin in VideoLAN VLC media player 0.9.0 through 1.1.2 does not properly process ID3v2 tags, which allows remote attackers to cause a denial of service (application crash) via a crafted media file.

    Published: 20 Aug 2010
    7.5
    High

    CVE-2010-3059

    Last Modified: 11 Apr 2025

    Buffer overflow in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to read and modify data, and possibly have other impact, via an unspecified command.

    Published: 20 Aug 2010
    5
    Medium

    CVE-2010-3060

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the message-protocol implementation in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (daemon outage) via unknown vectors.

    Published: 20 Aug 2010
    5
    Medium

    CVE-2010-3061

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the message-protocol implementation in the Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, allows remote attackers to cause a denial of service (recovery failure), and possibly trigger loss of data, via unknown vectors.

    Published: 20 Aug 2010
    7.5
    High

    CVE-2010-2628

    Last Modified: 11 Apr 2025

    The IKE daemon in strongSwan 4.3.x before 4.3.7 and 4.4.x before 4.4.1 does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted (1) certificate or (2) identity data that triggers buffer overflows.

    Published: 20 Aug 2010
    7.5
    High

    CVE-2010-3058

    Last Modified: 11 Apr 2025

    The Mount service in IBM Tivoli Storage Manager (TSM) FastBack 5.x.x before 5.5.7, and 6.1.0.0, establishes an open UDP port, which might allow remote attackers to overwrite memory locations and execute arbitrary code, or cause a denial of service (application hang), via unspecified vectors.

    Published: 20 Aug 2010
    2.1
    Low

    CVE-2008-7258

    Last Modified: 11 Apr 2025

    The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service (application exit) via an e-mail message containing a long line that begins with a . (dot) character. NOTE: CVE disputes this issue because it is solely a usability problem for senders of messages with certain long lines, and has no security impact

    Published: 20 Aug 2010
    10
    Critical

    CVE-2010-1386

    Last Modified: 11 Apr 2025

    page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.

    Published: 19 Aug 2010
    6.8
    Medium

    CVE-2010-2234

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Apache CouchDB 0.8.0 through 0.11.0 allows remote attackers to hijack the authentication of administrators for direct requests to an installation URL.

    Published: 19 Aug 2010
    6.8
    Medium

    CVE-2010-2809

    Last Modified: 11 Apr 2025

    The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI feature, which allows user-assisted remote attackers to execute arbitrary commands via a crafted HREF attribute of an A element in an HTML document.

    Published: 19 Aug 2010
    10
    Critical

    CVE-2010-1760

    Last Modified: 11 Apr 2025

    loader/DocumentThreadableLoader.cpp in the XMLHttpRequest implementation in WebCore in WebKit before r58409 does not properly handle credentials during a cross-origin synchronous request, which has unspecified impact and remote attack vectors, aka rdar problem 7905150.

    Published: 19 Aug 2010
    6.6
    Medium

    CVE-2010-0429

    Last Modified: 11 Apr 2025

    libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.

    Published: 19 Aug 2010
    6.6
    Medium

    CVE-2010-0431

    Last Modified: 11 Apr 2025

    QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.

    Published: 19 Aug 2010
    4.6
    Medium

    CVE-2010-0435

    Last Modified: 11 Apr 2025

    The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation.

    Published: 19 Aug 2010
    5.7
    Medium

    CVE-2010-2811

    Last Modified: 11 Apr 2025

    Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage) via crafted SSL traffic.

    Published: 19 Aug 2010
    6.5
    Medium

    CVE-2010-2948

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the bgp_route_refresh_receive function in bgp_packet.c in bgpd in Quagga before 0.99.17 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a malformed Outbound Route Filtering (ORF) record in a BGP ROUTE-REFRESH (RR) message.

    Published: 19 Aug 2010
    5
    Medium

    CVE-2010-2949

    Last Modified: 11 Apr 2025

    bgpd in Quagga before 0.99.17 does not properly parse AS paths, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unknown AS type in an AS path attribute in a BGP UPDATE message.

    Published: 19 Aug 2010
    5
    Medium

    CVE-2010-3115

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not properly implement the history feature, which might allow remote attackers to spoof the address bar via unspecified vectors.

    Published: 19 Aug 2010
    3.1
    Low

    CVE-2009-3552

    Last Modified: 21 Nov 2024

    In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network could use this flaw to conduct a man-in-the-middle attack, tricking the user into thinking they are viewing the Red Hat Enterprise Virtualization Manager when the content is actually attacker-controlled, or modifying actions a user requested Red Hat Enterprise Virtualization Manager to perform.

    Published: 19 Aug 2010
    6.6
    Medium

    CVE-2010-0428

    Last Modified: 11 Apr 2025

    libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via unspecified vectors.

    Published: 19 Aug 2010
    10
    Critical

    CVE-2010-3114

    Last Modified: 11 Apr 2025

    The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.

    Published: 19 Aug 2010
    10
    Critical

    CVE-2010-3116

    Last Modified: 11 Apr 2025

    Multiple use-after-free vulnerabilities in WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to improper handling of MIME types by plug-ins.

    Published: 19 Aug 2010
    10
    Critical

    CVE-2010-3119

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127 and webkitgtk before 1.2.6 do not properly support the Ruby language, which allows attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 19 Aug 2010
    10
    Critical

    CVE-2010-3113

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.

    Published: 19 Aug 2010
    5
    Medium

    CVE-2010-2951

    Last Modified: 11 Apr 2025

    dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.

    Published: 18 Aug 2010
    5
    Medium

    CVE-2010-2934

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in ZNC 0.092 allow remote attackers to cause a denial of service (exception and daemon crash) via unknown vectors related to "unsafe substr() calls."

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-1516

    Last Modified: 11 Apr 2025

    Multiple integer overflows in SWFTools 0.9.1 allow remote attackers to execute arbitrary code via (1) a crafted PNG file, related to the getPNG function in lib/png.c; or (2) a crafted JPEG file, related to the jpeg_load function in lib/jpeg.c.

    Published: 17 Aug 2010
    5
    Medium

    CVE-2010-2812

    Last Modified: 11 Apr 2025

    Client.cpp in ZNC 0.092 allows remote attackers to cause a denial of service (exception and daemon crash) via a PING command that lacks an argument.

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-0126

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in an unspecified library in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted compound file, as demonstrated using a Quattro Pro file, which is not properly handled by the Quattro speed reader (qpssr.dll).

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-0131

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the SpreadSheet Lotus 123 reader (wkssr.dll), as used in Autonomy KeyView 10.4 and 10.9, Symantec Mail Security, and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to floating point conversion in unknown record types.

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-0133

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allow remote attackers to execute arbitrary code via unspecified vectors related to "certain records."

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-0134

    Last Modified: 11 Apr 2025

    Integer signedness error in rtfsr.dll in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via a crafted \ls keyword in a list override table entry in an RTF file, which triggers a buffer overflow.

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2009-3737

    Last Modified: 11 Apr 2025

    The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-1525

    Last Modified: 11 Apr 2025

    Integer underflow in the SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted size for an unspecified record type, which triggers a heap-based buffer overflow.

    Published: 17 Aug 2010
    6.8
    Medium

    CVE-2010-3030

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 17 Aug 2010
    10
    Critical

    CVE-2010-3031

    Last Modified: 11 Apr 2025

    Buffer overflow in Wyse ThinOS HF 4.4.079i, and possibly other versions before ThinOS 6.5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the LPD service.

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-0135

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the WordPerfect 5.x reader (wosr.dll), as used in Autonomy KeyView 10.4 and 10.9 and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related to "data blocks."

    Published: 17 Aug 2010
    9.3
    Critical

    CVE-2010-1524

    Last Modified: 11 Apr 2025

    The SpreadSheet Lotus 123 reader (wkssr.dll) in Autonomy KeyView 10.4 and 10.9, as used in multiple IBM, Symantec, and other products, allows remote attackers to execute arbitrary code via unspecified vectors related to allocation of an array of pointers and "string indexing," which triggers memory corruption.

    Published: 17 Aug 2010
    10
    Critical

    CVE-2010-3032

    Last Modified: 11 Apr 2025

    Integer overflow in the OBGIOPServerWorker::extractHeader function in the ebus-3-3-2-6.dll module in SAP Crystal Reports 2008 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a GIOP packet with a crafted size, which triggers a heap-based buffer overflow.

    Published: 17 Aug 2010
    Unknown

    CVE-2010-3016

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2803. Reason: This candidate is a reservation duplicate of CVE-2010-2803. Notes: All CVE users should reference CVE-2010-2803 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Aug 2010
    1.9
    Low

    CVE-2010-2803

    Last Modified: 11 Apr 2025

    The drm_ioctl function in drivers/gpu/drm/drm_drv.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows local users to obtain potentially sensitive information from kernel memory by requesting a large memory-allocation amount.

    Published: 17 Aug 2010
    5.5
    Medium

    CVE-2010-2942

    Last Modified: 11 Apr 2025

    The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the tcf_gact_dump function in net/sched/act_gact.c, (2) the tcf_mirred_dump function in net/sched/act_mirred.c, (3) the tcf_nat_dump function in net/sched/act_nat.c, (4) the tcf_simp_dump function in net/sched/act_simple.c, and (5) the tcf_skbedit_dump function in net/sched/act_skbedit.c.

    Published: 17 Aug 2010
    6.8
    Medium

    CVE-2010-3024

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

    Published: 16 Aug 2010
    4.3
    Medium

    CVE-2010-3025

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) excerpt parameter to application/modules/admin/controllers/posts.php, as reachable by admin/posts/edit; and the (2) content parameter to application/modules/admin/controllers/pages.php, as reachable by admin/posts/edit.

    Published: 16 Aug 2010