CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2010-2552

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB Stack Exhaustion Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2553

    Last Modified: 11 Apr 2025

    The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression Vulnerability."

    Published: 11 Aug 2010
    6.8
    Medium

    CVE-2010-2555

    Last Modified: 11 Apr 2025

    The Tracing Feature for Services in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the length of strings in the registry, which allows local users to gain privileges or cause a denial of service (memory corruption) via vectors involving a long string, aka "Tracing Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2558

    Last Modified: 11 Apr 2025

    Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2559

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, CVE-2010-0245, and CVE-2010-0246.

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2560

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Layout Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2561

    Last Modified: 11 Apr 2025

    Microsoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted response, aka "Msxml2.XMLHTTP.3.0 Response Handling Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2562

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Excel file, aka "Excel Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    4.3
    Medium

    CVE-2010-1258

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handler Cross-Domain Vulnerability."

    Published: 11 Aug 2010
    7.8
    High

    CVE-2010-1889

    Last Modified: 11 Apr 2025

    Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."

    Published: 11 Aug 2010
    4.6
    Medium

    CVE-2010-1890

    Last Modified: 11 Apr 2025

    The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."

    Published: 11 Aug 2010
    8.4
    High

    CVE-2010-1896

    Last Modified: 11 Apr 2025

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2 do not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Win32k User Input Validation Vulnerability."

    Published: 11 Aug 2010
    7.2
    High

    CVE-2010-1897

    Last Modified: 11 Apr 2025

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2556

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2557

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-2564

    Last Modified: 11 Apr 2025

    Buffer overflow in Microsoft Windows Movie Maker (WMM) 2.1, 2.6, and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted project file, aka "Movie Maker Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.8
    Critical

    CVE-2010-2861

    Last Modified: 21 Apr 2026

    Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-0019

    Last Modified: 11 Apr 2025

    Microsoft Silverlight 3 before 3.0.50611.0 on Windows, and before 3.0.41130.0 on Mac OS X, does not properly handle pointers, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and framework outage) via a crafted web site, aka "Microsoft Silverlight Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    4.4
    Medium

    CVE-2010-1887

    Last Modified: 11 Apr 2025

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."

    Published: 11 Aug 2010
    6.8
    Medium

    CVE-2010-1893

    Last Modified: 11 Apr 2025

    Integer overflow in the TCP/IP stack in Microsoft Windows Vista SP1, Windows Server 2008 Gold and R2, and Windows 7 allows local users to gain privileges via a buffer of user-mode data that is copied to kernel mode, aka "Integer Overflow in Windows Networking Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-1901

    Last Modified: 11 Apr 2025

    Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly handle unspecified properties in rich text data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RTF document, aka "Word RTF Parsing Engine Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-1903

    Last Modified: 11 Apr 2025

    Microsoft Office Word 2002 SP3 and 2003 SP3, and Office Word Viewer, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed record in a Word file, aka "Word HTML Linked Objects Memory Corruption Vulnerability."

    Published: 11 Aug 2010
    5
    Medium

    CVE-2010-2219

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service (memory consumption) via unknown vectors.

    Published: 11 Aug 2010
    6.2
    Medium

    CVE-2011-1095

    Last Modified: 11 Apr 2025

    locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.

    Published: 11 Aug 2010
    7.2
    High

    CVE-2010-2959

    Last Modified: 11 Apr 2025

    Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.

    Published: 11 Aug 2010
    9.3
    Critical

    CVE-2010-0209

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2213, CVE-2010-2214, and CVE-2010-2216.

    Published: 10 Aug 2010
    9.3
    Critical

    CVE-2010-2214

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2216.

    Published: 10 Aug 2010
    4.3
    Medium

    CVE-2010-2215

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to trick a user into (1) selecting a link or (2) completing a dialog, related to a "click-jacking" issue.

    Published: 10 Aug 2010
    9.3
    Critical

    CVE-2010-2216

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2213, and CVE-2010-2214.

    Published: 10 Aug 2010
    3.6
    Low

    CVE-2010-1172

    Last Modified: 11 Apr 2025

    DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services.

    Published: 10 Aug 2010
    9.3
    Critical

    CVE-2010-2213

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.280 and 10.x before 10.1.82.76, and Adobe AIR before 2.0.3, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-0209, CVE-2010-2214, and CVE-2010-2216.

    Published: 10 Aug 2010
    2.1
    Low

    CVE-2010-2574

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in manage_proj_cat_add.php in MantisBT 1.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the name parameter in an Add Category action.

    Published: 9 Aug 2010
    4
    Medium

    CVE-2010-2634

    Last Modified: 11 Apr 2025

    RSA enVision before 3.7 SP1 allows remote authenticated users to cause a denial of service via unspecified vectors.

    Published: 9 Aug 2010
    4.3
    Medium

    CVE-2010-2988

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtf35333.

    Published: 9 Aug 2010
    5
    Medium

    CVE-2010-2989

    Last Modified: 11 Apr 2025

    nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to obtain sensitive information via a request to the /feed method, which reveals the version in a response.

    Published: 9 Aug 2010
    9.3
    Critical

    CVE-2010-0834

    Last Modified: 11 Apr 2025

    The base-files package before 5.0.0ubuntu7.1 on Ubuntu 9.10 and before 5.0.0ubuntu20.10.04.2 on Ubuntu 10.04 LTS, as shipped on Dell Latitude 2110 netbooks, does not require authentication for package installation, which allows remote archive servers and man-in-the-middle attackers to execute arbitrary code via a crafted package.

    Published: 9 Aug 2010
    4.3
    Medium

    CVE-2010-2985

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Service Registry and Repository (WSRR) 6.3 allow remote attackers to inject arbitrary web script or HTML via (1) the searchTerm parameter to ServiceRegistry/HelpSearch.do or (2) the queryItems[0].value parameter to ServiceRegistry/QueryWizardProcessStep1.do.

    Published: 9 Aug 2010
    4.3
    Medium

    CVE-2010-2986

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webacs/QuickSearchAction.do in the search feature in the web interface in Cisco Wireless Control System (WCS) before 6.0(194.0) and 7.x before 7.0.164 allows remote attackers to inject arbitrary web script or HTML via the searchText parameter, aka Bug ID CSCtf14288.

    Published: 9 Aug 2010
    4.3
    Medium

    CVE-2010-2987

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Wireless Control System (WCS) 7.x before 7.0.164, as used in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCtg33854.

    Published: 9 Aug 2010
    10
    Critical

    CVE-2010-2976

    Last Modified: 11 Apr 2025

    The controller in Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 has (1) a default SNMP read-only community of public, (2) a default SNMP read-write community of private, and a value of "default" for the (3) SNMP v3 username, (4) SNMP v3 authentication password, and (5) SNMP v3 privacy password, which makes it easier for remote attackers to obtain access.

    Published: 9 Aug 2010
    10
    Critical

    CVE-2010-2977

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not properly implement TLS and SSL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtd01611.

    Published: 9 Aug 2010
    10
    Critical

    CVE-2010-2978

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 does not use an adequate message-digest algorithm for a self-signed certificate, which allows remote attackers to bypass intended access restrictions via vectors involving collisions, aka Bug ID CSCtd67660.

    Published: 9 Aug 2010
    7.8
    High

    CVE-2010-2979

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 5508 series controllers allows remote attackers to cause a denial of service (buffer leak and device crash) via ARP requests that trigger an ARP storm, aka Bug ID CSCte43508.

    Published: 9 Aug 2010
    7.8
    High

    CVE-2010-2980

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 5508 series controllers allows remote attackers to cause a denial of service (pbuf exhaustion and device crash) via fragmented traffic, aka Bug ID CSCtd26794.

    Published: 9 Aug 2010
    7.1
    High

    CVE-2010-2981

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (device crash) by pinging a virtual interface, aka Bug ID CSCte55370.

    Published: 9 Aug 2010
    2.1
    Low

    CVE-2010-2975

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544.

    Published: 9 Aug 2010
    7.1
    High

    CVE-2010-2982

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to discover a group password via a series of SNMP requests, as demonstrated by an SNMP walk, aka Bug ID CSCtb74037.

    Published: 9 Aug 2010
    7.8
    High

    CVE-2010-2983

    Last Modified: 11 Apr 2025

    The workgroup bridge (aka WGB) functionality in Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 allows remote attackers to cause a denial of service (dropped connection) via a series of spoofed EAPoL-Logoff frames, related to an "EAPoL logoff attack," aka Bug ID CSCte43374.

    Published: 9 Aug 2010
    10
    Critical

    CVE-2010-2984

    Last Modified: 11 Apr 2025

    Cisco Unified Wireless Network (UWN) Solution 7.x before 7.0.98.0 on 4404 series controllers does not properly implement the WEBAUTH_REQD state, which allows remote attackers to bypass intended access restrictions via WLAN traffic, aka Bug ID CSCtb75305.

    Published: 9 Aug 2010
    Unknown

    CVE-2008-7260

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 9 Aug 2010