CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2009-4918

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (IKE process hang) via malformed NAT-T packets, aka Bug ID CSCsr74439.

    Published: 29 Jun 2010
    10
    Critical

    CVE-2009-4919

    Last Modified: 11 Apr 2025

    Buffer overflow on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to have an unspecified impact via long IKE attributes, aka Bug ID CSCsu43121.

    Published: 29 Jun 2010
    7.8
    High

    CVE-2009-4920

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CTM on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software 8.1(2) allows remote attackers to cause a denial of service (watchdog traceback) via a large amount of small-packet data, aka Bug ID CSCsu11412.

    Published: 29 Jun 2010
    7.8
    High

    CVE-2009-4921

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allow remote attackers to cause a denial of service (traceback) via malformed TCP packets, aka Bug ID CSCsm84110.

    Published: 29 Jun 2010
    7.8
    High

    CVE-2009-4923

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the DTLS implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (traceback) via TLS fragments, aka Bug ID CSCso53162.

    Published: 29 Jun 2010
    7.8
    High

    CVE-2009-4915

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (device reload) via unknown network traffic, as demonstrated by a "connection stress test," aka Bug ID CSCsq68451.

    Published: 29 Jun 2010
    6.8
    Medium

    CVE-2009-4922

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (traceback) by establishing many IPsec L2L tunnels from remote peer IP addresses, aka Bug ID CSCso15583.

    Published: 29 Jun 2010
    7.8
    High

    CVE-2009-4914

    Last Modified: 11 Apr 2025

    Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879.

    Published: 29 Jun 2010
    10
    Critical

    CVE-2010-2451

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2452

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the DCC functionality in KVIrc 3.4 and 4.0 allows remote attackers to overwrite arbitrary files via unknown vectors.

    Published: 29 Jun 2010
    7.5
    High

    CVE-2010-2516

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2202

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.

    Published: 29 Jun 2010
    6.8
    Medium

    CVE-2010-2203

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3 on UNIX allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2205

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, access uninitialized memory, which allows attackers to execute arbitrary code via unspecified vectors.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2206

    Last Modified: 11 Apr 2025

    Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2208

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, dereference a heap object after this object's deletion, which allows attackers to execute arbitrary code via unspecified vectors.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2209

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.

    Published: 29 Jun 2010
    5
    Medium

    CVE-2010-2621

    Last Modified: 11 Apr 2025

    The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-1285

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified manipulations involving the newclass (0x58) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-2168 and CVE-2010-2201.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-1295

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2168

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction (0x44) operator and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2201.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2201

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2207

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2209, CVE-2010-2210, CVE-2010-2211, and CVE-2010-2212.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2212

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a PDF file containing Flash content with a crafted #1023 (3FFh) tag, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2211.

    Published: 29 Jun 2010
    7.2
    High

    CVE-2010-2478

    Last Modified: 11 Apr 2025

    Integer overflow in the ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.33.7 on 32-bit platforms allows local users to cause a denial of service or possibly have unspecified other impact via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value that triggers a buffer overflow, a different vulnerability than CVE-2010-3084.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2204

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2210

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2211, and CVE-2010-2212.

    Published: 29 Jun 2010
    9.3
    Critical

    CVE-2010-2211

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-1295, CVE-2010-2202, CVE-2010-2207, CVE-2010-2209, CVE-2010-2210, and CVE-2010-2212.

    Published: 29 Jun 2010
    6.8
    Medium

    CVE-2010-2507

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 28 Jun 2010
    6.8
    Medium

    CVE-2010-2515

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL commands via the id parameter, and (2) remote authenticated users with "Public Front-end" permissions to execute arbitrary SQL commands via the titlu parameter (title field). NOTE: some of these details are obtained from third party information.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2508

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Published: 28 Jun 2010
    4.3
    Medium

    CVE-2010-2509

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and the (2) password parameter to memberlogin.php.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2510

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2511

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2512

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2513

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.

    Published: 28 Jun 2010
    4.3
    Medium

    CVE-2010-2514

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add2 action to index.php.

    Published: 28 Jun 2010
    7.5
    High

    CVE-2010-2502

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an unknown impact via redirects, aka SPL-31067.

    Published: 28 Jun 2010
    4.3
    Medium

    CVE-2010-2503

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067; (2) unspecified "user->user or user->admin" vectors, aka SPL-31084; or (3) unspecified "user input," aka SPL-31085.

    Published: 28 Jun 2010
    6
    Medium

    CVE-2010-2504

    Last Modified: 11 Apr 2025

    Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allows remote authenticated users to obtain sensitive information via HTTP header injection, aka SPL-31066.

    Published: 28 Jun 2010
    5
    Medium

    CVE-2010-2505

    Last Modified: 11 Apr 2025

    Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long GET request.

    Published: 28 Jun 2010
    2.9
    Low

    CVE-2010-2506

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter.

    Published: 28 Jun 2010
    1.9
    Low

    CVE-2010-0180

    Last Modified: 11 Apr 2025

    Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

    Published: 28 Jun 2010
    5
    Medium

    CVE-2010-1930

    Last Modified: 11 Apr 2025

    Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.

    Published: 28 Jun 2010
    4.3
    Medium

    CVE-2010-2228

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors involving extended characters in a username.

    Published: 28 Jun 2010
    4.3
    Medium

    CVE-2010-2229

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 28 Jun 2010
    4
    Medium

    CVE-2010-2230

    Last Modified: 11 Apr 2025

    The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via HTML input.

    Published: 28 Jun 2010
    6.8
    Medium

    CVE-2010-2231

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of arbitrary users for requests that delete quiz attempts via the attemptid parameter.

    Published: 28 Jun 2010
    9
    Critical

    CVE-2010-1929

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.

    Published: 28 Jun 2010
    1.9
    Low

    CVE-2010-2470

    Last Modified: 11 Apr 2025

    Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

    Published: 28 Jun 2010