CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2010-2539

    Last Modified: 11 Apr 2025

    Buffer overflow in the msTmpFile function in maputil.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 allows local users to cause a denial of service via vectors involving names of temporary files.

    Published: 2 Aug 2010
    10
    Critical

    CVE-2010-2540

    Last Modified: 11 Apr 2025

    mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were intended for debugging, which allows remote attackers to have an unspecified impact via crafted arguments.

    Published: 2 Aug 2010
    6.8
    Medium

    CVE-2010-2786

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Piwik 0.6 through 0.6.3 allows remote attackers to include arbitrary local files and possibly have unspecified other impact via directory traversal sequences in a crafted data-renderer request.

    Published: 2 Aug 2010
    7.8
    High

    CVE-2010-2633

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EMC Disk Library (EDL) before 3.2.7, 3.3.x before 3.3.2 epatch 8, and 4.0.x before 4.0.1 epatch 4 allows remote attackers to cause a denial of service (communication-module crash) by sending a crafted message through TCP.

    Published: 2 Aug 2010
    4.3
    Medium

    CVE-2009-4976

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webkitpart.cpp in kwebkitpart allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.

    Published: 2 Aug 2010
    4.3
    Medium

    CVE-2010-2536

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in rekonq 0.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) a URL associated with a nonexistent domain name, related to webpage.cpp, aka a "universal XSS" issue; (2) unspecified vectors related to webview.cpp; and the about: views for (3) favorites, (4) bookmarks, (5) closed tabs, and (6) history.

    Published: 2 Aug 2010
    7.2
    High

    CVE-2010-2929

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via a modified PATH environment variable, which is used during execution of the (1) route, (2) mv, and (3) cp programs, a different vulnerability than CVE-2010-1671.

    Published: 2 Aug 2010
    7.2
    High

    CVE-2010-2930

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in hsolinkcontrol in hsolink 1.0.118 allow local users to gain privileges via long command-line arguments, a different vulnerability than CVE-2010-1671. NOTE: some of these details are obtained from third party information.

    Published: 2 Aug 2010
    4.3
    Medium

    CVE-2009-4975

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webview.cpp in QtDemoBrowser allows remote attackers to inject arbitrary web script or HTML via a URL associated with a nonexistent domain name, related to a "universal XSS" issue, a similar vulnerability to CVE-2010-2536.

    Published: 2 Aug 2010
    7.2
    High

    CVE-2010-1671

    Last Modified: 11 Apr 2025

    hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via shell metacharacters in command-line arguments, as demonstrated by the second argument in a down action.

    Published: 2 Aug 2010
    10
    Critical

    CVE-2010-1518

    Last Modified: 11 Apr 2025

    Array index error in the SetDLInfo method in the GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via the item argument.

    Published: 2 Aug 2010
    4.9
    Medium

    CVE-2010-1794

    Last Modified: 11 Apr 2025

    The webdav_mount function in webdav_vfsops.c in the WebDAV kernel extension (aka webdav_fs.kext) for Mac OS X 10.6 allows local users to cause a denial of service (panic) via a mount request with a large integer in the pa_socket_namelen field.

    Published: 2 Aug 2010
    5
    Medium

    CVE-2010-2195

    Last Modified: 11 Apr 2025

    bozotic HTTP server (aka bozohttpd) 20090522 through 20100512 allows attackers to cause a denial of service via vectors related to a "wrong code generation interaction with GCC."

    Published: 2 Aug 2010
    5
    Medium

    CVE-2010-2320

    Last Modified: 11 Apr 2025

    bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.

    Published: 2 Aug 2010
    6.5
    Medium

    CVE-2010-2785

    Last Modified: 11 Apr 2025

    The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which allows remote authenticated users to execute arbitrary CTCP commands via vectors involving \r and \40 sequences, a different vulnerability than CVE-2010-2451 and CVE-2010-2452.

    Published: 2 Aug 2010
    5
    Medium

    CVE-2010-2927

    Last Modified: 11 Apr 2025

    The slapi_printmessage function in IBM Tivoli Directory Server (ITDS) before 6.0.0.8-TIV-ITDS-IF0006 allows remote attackers to cause a denial of service (daemon crash) via multiple incomplete DIGEST-MD5 connection attempts.

    Published: 2 Aug 2010
    6.5
    Medium

    CVE-2009-4896

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the mlmmj-php-admin web interface for Mailing List Managing Made Joyful (mlmmj) 1.2.15 through 1.2.17 allow remote authenticated users to overwrite, create, or delete arbitrary files, or determine the existence of arbitrary directories, via a .. (dot dot) in a list name in a (1) edit or (2) save action.

    Published: 2 Aug 2010
    10
    Critical

    CVE-2010-1517

    Last Modified: 11 Apr 2025

    The GIGABYTE Dldrv2 ActiveX control 1.4.206.11 allows remote attackers to (1) download arbitrary programs onto a client system, and execute these programs, via vectors involving the dl method; and (2) download arbitrary programs onto a client system via vectors involving the SetDLInfo method in conjunction with the Bdl method.

    Published: 2 Aug 2010
    4.3
    Medium

    CVE-2009-2696

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in jsp/cal/cal2.jsp in the calendar application in the examples web application in Apache Tomcat on Red Hat Enterprise Linux 5, Desktop Workstation 5, and Linux Desktop 5 allows remote attackers to inject arbitrary web script or HTML via the time parameter, related to "invalid HTML." NOTE: this is due to a missing fix for CVE-2009-0781.

    Published: 2 Aug 2010
    3.3
    Low

    CVE-2011-1585

    Last Modified: 11 Apr 2025

    The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user.

    Published: 2 Aug 2010
    7.8
    High

    CVE-2018-10901

    Last Modified: 21 Nov 2024

    A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An attacker can use this to escalate their privileges.

    Published: 2 Aug 2010
    9.3
    Critical

    CVE-2010-1780

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to element focus.

    Published: 30 Jul 2010
    4.3
    Medium

    CVE-2010-1778

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to inject arbitrary web script or HTML via an RSS feed.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1785

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; accesses uninitialized memory during processing of the (1) :first-letter and (2) :first-line pseudo-elements in an SVG text element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1786

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a foreignObject element in an SVG document.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1789

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a JavaScript string object.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1791

    Last Modified: 11 Apr 2025

    Integer signedness error in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a JavaScript array index.

    Published: 30 Jul 2010
    4.3
    Medium

    CVE-2010-2914

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in nessusd_www_server.nbin in the Nessus Web Server plugin 1.2.4 for Nessus allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2915

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2918

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2919

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 30 Jul 2010
    6.8
    Medium

    CVE-2010-2920

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2921

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2925

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2926

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1782

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to the rendering of an inline element.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1783

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle dynamic modification of a text node, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1788

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a use element in an SVG document.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1790

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; does not properly handle just-in-time (JIT) compiled JavaScript stubs, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to a "reentrancy issue."

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1792

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted regular expression.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1793

    Last Modified: 11 Apr 2025

    Multiple use-after-free vulnerabilities in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a (1) font-face or (2) use element in an SVG document.

    Published: 30 Jul 2010
    2.6
    Low

    CVE-2010-1796

    Last Modified: 11 Apr 2025

    The AutoFill feature in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4, allows remote attackers to obtain sensitive Address Book Card information via JavaScript code that forces keystroke events for input fields.

    Published: 30 Jul 2010
    4.3
    Medium

    CVE-2010-2917

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2923

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1784

    Last Modified: 11 Apr 2025

    The counters functionality in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1787

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0.1 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.1 on Mac OS X 10.4; and webkitgtk before 1.2.6; allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a floating element in an SVG document.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2916

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2922

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 30 Jul 2010
    7.5
    High

    CVE-2010-2924

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Jul 2010
    9.3
    Critical

    CVE-2010-1777

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple iTunes before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted itpc: URL.

    Published: 29 Jul 2010