CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2010-1757

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element, which allows remote attackers to spoof the user interface via a crafted HTML document.

    Published: 22 Jun 2010
    1.9
    Low

    CVE-2010-1775

    Last Modified: 11 Apr 2025

    Race condition in Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch allows physically proximate attackers to bypass intended passcode requirements, and pair a locked device with a computer and access arbitrary data, via vectors involving the initial boot.

    Published: 22 Jun 2010
    6.8
    Medium

    CVE-2010-1753

    Last Modified: 11 Apr 2025

    ImageIO in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted JPEG image.

    Published: 22 Jun 2010
    6.9
    Medium

    CVE-2010-1754

    Last Modified: 11 Apr 2025

    Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote Lock operations through MobileMe, which allows physically proximate attackers to bypass intended passcode requirements via unspecified vectors.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-1407

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 4 on the iPhone and iPod touch does not properly implement the history.replaceState method in certain situations involving IFRAME elements, which allows remote attackers to obtain sensitive information via a crafted HTML document.

    Published: 22 Jun 2010
    6.8
    Medium

    CVE-2010-1752

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in CFNetwork in Apple iOS before 4 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to URL handling.

    Published: 22 Jun 2010
    6.8
    Medium

    CVE-2010-2420

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Fenrir Inc. ActiveGeckoBrowser 1.0.0 and 1.0.5 alpha, a module for the Sleipnir web browser, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to the Gecko engine.

    Published: 22 Jun 2010
    5
    Medium

    CVE-2010-1638

    Last Modified: 11 Apr 2025

    The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted request to an unspecified test script. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

    Published: 22 Jun 2010
    10
    Critical

    CVE-2010-2421

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe" issues.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-0183

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1203

    Last Modified: 11 Apr 2025

    The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.

    Published: 22 Jun 2010
    2.1
    Low

    CVE-2010-2224

    Last Modified: 11 Apr 2025

    The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-2631

    Last Modified: 11 Apr 2025

    LibTIFF 3.9.0 ignores tags in certain situations during the first stage of TIFF file processing and does not properly handle this during the second stage, which allows remote attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2010-2481.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-4665

    Last Modified: 11 Apr 2025

    Integer overflow in the ReadDirectory function in tiffdump.c in tiffdump in LibTIFF before 3.9.5 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF file containing a directory data structure with many directory entries.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1196

    Last Modified: 11 Apr 2025

    Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-1197

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1198

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1199

    Last Modified: 11 Apr 2025

    Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1200

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1201

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 22 Jun 2010
    9.3
    Critical

    CVE-2010-1202

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 22 Jun 2010
    4.3
    Medium

    CVE-2010-2356

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.

    Published: 21 Jun 2010
    7.5
    High

    CVE-2010-2357

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.

    Published: 21 Jun 2010
    7.5
    High

    CVE-2010-2359

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.

    Published: 21 Jun 2010
    4.3
    Medium

    CVE-2010-2355

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jun 2010
    7.5
    High

    CVE-2010-2354

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.

    Published: 21 Jun 2010
    5.1
    Medium

    CVE-2010-2358

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path] parameter. NOTE: some of these details are obtained from third party information.

    Published: 21 Jun 2010
    2.1
    Low

    CVE-2010-1958

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the FileField module 5.x before 5.x-2.5 and 6.x before 6.x-3.4 for Drupal allows remote authenticated users, with create or edit permissions and 'Path to File' or 'URL to File' display enabled, to inject arbitrary web script or HTML via the file name (filepath parameter).

    Published: 21 Jun 2010
    9.3
    Critical

    CVE-2010-2348

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.

    Published: 21 Jun 2010
    5
    Medium

    CVE-2010-2349

    Last Modified: 11 Apr 2025

    H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.

    Published: 21 Jun 2010
    6.8
    Medium

    CVE-2010-2350

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNG file.

    Published: 21 Jun 2010
    10
    Critical

    CVE-2010-2351

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.

    Published: 21 Jun 2010
    5
    Medium

    CVE-2010-2352

    Last Modified: 11 Apr 2025

    The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes.

    Published: 21 Jun 2010
    5
    Medium

    CVE-2010-2353

    Last Modified: 11 Apr 2025

    The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, which allows remote attackers to discover titles and IDs of controlled nodes.

    Published: 21 Jun 2010
    4.9
    Medium

    CVE-2010-2347

    Last Modified: 11 Apr 2025

    The Telnet interface in the SAP J2EE Engine Core (SAP-JEECOR) 6.40 through 7.02, and Server Core (SERVERCORE) 7.10 through 7.30 allows remote authenticated users to bypass a security check and conduct SMB relay attacks via unspecified vectors.

    Published: 21 Jun 2010
    7.5
    High

    CVE-2010-2342

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Published: 21 Jun 2010
    9.3
    Critical

    CVE-2010-2343

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.

    Published: 21 Jun 2010
    4.3
    Medium

    CVE-2010-2344

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php, (2) _members/index.php, (3) _forum/index.php, (4) _docs/index.php, and (5) _announcements/index.php.

    Published: 21 Jun 2010
    6.8
    Medium

    CVE-2010-2345

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password, and other unspecified requests.

    Published: 21 Jun 2010
    6.8
    Medium

    CVE-2010-2067

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.

    Published: 21 Jun 2010
    4.3
    Medium

    CVE-2010-2422

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transform.

    Published: 21 Jun 2010
    8.1
    High

    CVE-2010-2943

    Last Modified: 11 Apr 2025

    The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.

    Published: 20 Jun 2010
    7.5
    High

    CVE-2010-2338

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.

    Published: 18 Jun 2010
    7.5
    High

    CVE-2010-2339

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.

    Published: 18 Jun 2010
    7.5
    High

    CVE-2010-2341

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.

    Published: 18 Jun 2010
    6.8
    Medium

    CVE-2010-2340

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.

    Published: 18 Jun 2010
    9.3
    Critical

    CVE-2010-2329

    Last Modified: 11 Apr 2025

    Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file.

    Published: 18 Jun 2010
    9.3
    Critical

    CVE-2010-2330

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.

    Published: 18 Jun 2010
    9.3
    Critical

    CVE-2010-2331

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request.

    Published: 18 Jun 2010
    5
    Medium

    CVE-2010-2332

    Last Modified: 11 Apr 2025

    Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.

    Published: 18 Jun 2010