CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2010-2913

    Last Modified: 11 Apr 2025

    The Citibank Citi Mobile app before 2.0.3 for iOS stores account data in a file, which allows local users to obtain sensitive information via vectors involving (1) the mobile device or (2) a synchronized computer.

    Published: 29 Jul 2010
    4.3
    Medium

    CVE-2010-5321

    Last Modified: 20 Apr 2025

    Memory leak in drivers/media/video/videobuf-core.c in the videobuf subsystem in the Linux kernel 2.6.x through 4.x allows local users to cause a denial of service (memory consumption) by leveraging /dev/video access for a series of mmap calls that require new allocations, a different vulnerability than CVE-2007-6761. NOTE: as of 2016-06-18, this affects only 11 drivers that have not been updated to use videobuf2 instead of videobuf.

    Published: 29 Jul 2010
    7.5
    High

    CVE-2010-2906

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2909

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2910

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2911

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2912

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.

    Published: 28 Jul 2010
    4.3
    Medium

    CVE-2010-2904

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the System Landscape Directory (SLD) component 6.4 through 7.02 in SAP NetWeaver allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter to testsdic and the (2) helpstring parameter to paramhelp.jsp.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2908

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2905

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2907

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.

    Published: 28 Jul 2010
    4.3
    Medium

    CVE-2010-2896

    Last Modified: 11 Apr 2025

    IBM FileNet Content Manager (CM) 4.0.0, 4.0.1, 4.5.0, and 4.5.1 before FP4 does not properly manage the InheritParentPermissions setting during an upgrade from 3.x, which might allow attackers to bypass intended folder permissions via unspecified vectors.

    Published: 28 Jul 2010
    10
    Critical

    CVE-2010-2897

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the Windows kernel, which has unknown impact and attack vectors.

    Published: 28 Jul 2010
    10
    Critical

    CVE-2010-2898

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.125 does not properly mitigate an unspecified flaw in the GNU C Library, which has unknown impact and attack vectors.

    Published: 28 Jul 2010
    7.5
    High

    CVE-2010-2903

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.125 performs unexpected truncation and improper eliding of hostnames, which has unspecified impact and remote attack vectors.

    Published: 28 Jul 2010
    10
    Critical

    CVE-2010-2900

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.125 does not properly handle a large canvas, which has unspecified impact and remote attack vectors.

    Published: 28 Jul 2010
    10
    Critical

    CVE-2010-2902

    Last Modified: 11 Apr 2025

    The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 28 Jul 2010
    5
    Medium

    CVE-2010-2899

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the layout implementation in Google Chrome before 5.0.375.125 allows remote attackers to obtain sensitive information from process memory via unknown vectors.

    Published: 28 Jul 2010
    9.1
    Critical

    CVE-2010-2548

    Last Modified: 21 Nov 2024

    IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.

    Published: 28 Jul 2010
    9.1
    Critical

    CVE-2010-2783

    Last Modified: 21 Nov 2024

    IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.

    Published: 28 Jul 2010
    4.6
    Medium

    CVE-2011-1024

    Last Modified: 11 Apr 2025

    chain.c in back-ldap in OpenLDAP 2.4.x before 2.4.24, when a master-slave configuration with a chain overlay and ppolicy_forward_updates (aka authentication-failure forwarding) is used, allows remote authenticated users to bypass external-program authentication by sending an invalid password to a slave server.

    Published: 28 Jul 2010
    6.6
    Medium

    CVE-2010-2784

    Last Modified: 11 Apr 2025

    The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain privileges via unspecified vectors.

    Published: 28 Jul 2010
    4.6
    Medium

    CVE-2010-2526

    Last Modified: 11 Apr 2025

    The cluster logical volume manager daemon (clvmd) in lvm2-cluster in LVM2 before 2.02.72, as used in Red Hat Global File System (GFS) and other products, does not verify client credentials upon a socket connection, which allows local users to cause a denial of service (daemon exit or logical-volume change) or possibly have unspecified other impact via crafted control commands.

    Published: 28 Jul 2010
    6
    Medium

    CVE-2010-2337

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors.

    Published: 27 Jul 2010
    5
    Medium

    CVE-2010-2534

    Last Modified: 11 Apr 2025

    The NetworkSyncCommandQueue function in network/network_command.cpp in OpenTTD before 1.0.3 does not properly clear a pointer in a linked list, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted request, related to the client command queue.

    Published: 27 Jul 2010
    10
    Critical

    CVE-2010-2703

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

    Published: 27 Jul 2010
    10
    Critical

    CVE-2010-2704

    Last Modified: 11 Apr 2025

    Buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long HTTP request to nnmrptconfig.exe.

    Published: 27 Jul 2010
    9.3
    Critical

    CVE-2010-0833

    Last Modified: 11 Apr 2025

    The pam_lsass library in Likewise Open 5.4 and CIFS 5.4 before build 8046, and 6.0 before build 8234, as used in HP StorageWorks X9000 Network Storage Systems and possibly other products, uses "SetPassword logic" when running as part of a root service, which allows remote attackers to bypass authentication for a Likewise Security Authority (lsassd) account whose password is marked as expired.

    Published: 27 Jul 2010
    7.8
    High

    CVE-2010-1577

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Cisco Internet Streamer, as used in Cisco Content Delivery System (CDS) 2.2.x, 2.3.x, 2.4.x, and 2.5.x before 2.5.7 allows remote attackers to read arbitrary files via a crafted URL.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4958

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to execute arbitrary SQL commands via the idd parameter.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4959

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the T3M E-Mail Marketing Tool (t3m) extension 0.2.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    5
    Medium

    CVE-2009-4960

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in modules/backup/download.php in Lanai Core 0.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.

    Published: 27 Jul 2010
    3.5
    Low

    CVE-2009-4963

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Commerce extension before 0.9.9 for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Jul 2010
    9.3
    Critical

    CVE-2009-4964

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in KSP 2006 FINAL allows remote attackers to execute arbitrary code via a long string in a .M3U playlist file.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4965

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the AIRware Lexicon (air_lexicon) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4966

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the AST ZipCodeSearch (ast_addresszipsearch) extension 0.5.4 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4967

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Car (car) extension before 0.1.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4968

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Event Registration (event_registr) extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4969

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Solidbase Bannermanagement (SBbanner) extension 1.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    4.3
    Medium

    CVE-2009-4972

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php (aka the log in page) in SimpleID before 0.6.5 allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4973

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands via the selectedCal parameter in a SwitchCal action.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4974

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in box_display.php in TotalCalendar 2.4 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the box parameter.

    Published: 27 Jul 2010
    9.3
    Critical

    CVE-2009-4962

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a .wav file. NOTE: some of these details are obtained from third party information.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4971

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the AJAX Chat (vjchat) extension before 0.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    7.5
    High

    CVE-2009-4970

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the t3m_affiliate extension 0.5.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 27 Jul 2010
    5
    Medium

    CVE-2009-4961

    Last Modified: 11 Apr 2025

    Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls the phpinfo function.

    Published: 27 Jul 2010
    8.8
    High

    CVE-2010-1871

    Last Modified: 22 Apr 2026

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

    Published: 27 Jul 2010
    4
    Medium

    CVE-2010-3835

    Last Modified: 11 Apr 2025

    MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (mysqld server crash) by performing a user-variable assignment in a logical expression that is calculated and stored in a temporary table for GROUP BY, then causing the expression value to be used after the table is created, which causes the expression to be re-evaluated instead of accessing its value from the table.

    Published: 26 Jul 2010
    9.3
    Critical

    CVE-2010-2935

    Last Modified: 11 Apr 2025

    simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle integer values associated with dictionary property items, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PowerPoint document that triggers a heap-based buffer overflow, related to an "integer truncation error."

    Published: 26 Jul 2010
    9.3
    Critical

    CVE-2010-2936

    Last Modified: 11 Apr 2025

    Integer overflow in simpress.bin in the Impress module in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted polygons in a PowerPoint document that triggers a heap-based buffer overflow.

    Published: 26 Jul 2010