CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-2306

    Last Modified: 11 Apr 2025

    The default installation of Sourcefire 3D Sensor 1000, 2000, and 9900; and Defense Center 1000; uses the same static, private SSL keys for multiple devices and installations, which allows remote attackers to decrypt SSL traffic via a man-in-the-middle (MITM) attack.

    Published: 16 Jun 2010
    7.5
    High

    CVE-2010-2063

    Last Modified: 11 Apr 2025

    Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0.x before 3.3.13 allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted field in a packet.

    Published: 16 Jun 2010
    1.9
    Low

    CVE-2010-2192

    Last Modified: 11 Apr 2025

    The make_lockdir_name function in policy.c in pmount 0.9.18 allow local users to overwrite arbitrary files via a symlink attack on a file in /var/lock/.

    Published: 16 Jun 2010
    4.3
    Medium

    CVE-2010-2483

    Last Modified: 11 Apr 2025

    The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values.

    Published: 16 Jun 2010
    4
    Medium

    CVE-2010-3836

    Last Modified: 11 Apr 2025

    MySQL 5.0 before 5.0.92, 5.1 before 5.1.51, and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (assertion failure and server crash) via vectors related to view preparation, pre-evaluation of LIKE predicates, and IN Optimizers.

    Published: 16 Jun 2010
    9.3
    Critical

    CVE-2010-2189

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, when used in conjunction with VMWare Tools on a VMWare platform, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2295

    Last Modified: 11 Apr 2025

    page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a change of the focused frame during the dispatching of keydown, which allows user-assisted remote attackers to redirect keystrokes via a crafted HTML document, aka rdar problem 7018610. NOTE: this might overlap CVE-2010-1422.

    Published: 15 Jun 2010
    10
    Critical

    CVE-2010-2298

    Last Modified: 11 Apr 2025

    browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions via vectors involving fchdir and chdir calls.

    Published: 15 Jun 2010
    10
    Critical

    CVE-2010-2300

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to handlers for DOM mutation events, aka rdar problem 7948784. NOTE: this might overlap CVE-2010-1759.

    Published: 15 Jun 2010
    10
    Critical

    CVE-2010-2299

    Last Modified: 11 Apr 2025

    The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitrary code via vectors involving crafted data from the renderer process, related to a "Type Confusion" issue.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2301

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.

    Published: 15 Jun 2010
    Unknown

    CVE-2010-2303

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1772. Reason: This candidate is a duplicate of CVE-2010-1772. Notes: All CVE users should reference CVE-2010-1772 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Jun 2010
    9.3
    Critical

    CVE-2010-2296

    Last Modified: 11 Apr 2025

    The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attackers to bypass the Same Origin Policy via unknown vectors.

    Published: 15 Jun 2010
    9.3
    Critical

    CVE-2010-2297

    Last Modified: 11 Apr 2025

    rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.

    Published: 15 Jun 2010
    10
    Critical

    CVE-2010-2302

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow DOM trees, aka rdar problem 8007953. NOTE: this might overlap CVE-2010-1771.

    Published: 15 Jun 2010
    6.8
    Medium

    CVE-2009-4893

    Last Modified: 11 Apr 2025

    Buffer overflow in UnrealIRCd 3.2beta11 through 3.2.8, when allow::options::noident is enabled, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2009-4894

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in PunBB before 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) password or (2) e-mail.

    Published: 15 Jun 2010
    7.5
    High

    CVE-2010-2075

    Last Modified: 11 Apr 2025

    UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2290

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cgi-bin/cgix/help in McAfee Unified Threat Management (UTM) Firewall (formerly SnapGear) firmware 3.0.0 through 4.0.6 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 15 Jun 2010
    3.3
    Low

    CVE-2010-2291

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the web interface in snom VoIP Phone firmware 8 before 8.2.35 allows remote attackers to bypass intended restrictions and modify user credentials via unknown vectors. NOTE: some of these details are obtained from third party information.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2292

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ping tools web interface in Dlink Di-604 router allows remote attackers to inject arbitrary web script or HTML via the IP field.

    Published: 15 Jun 2010
    6.8
    Medium

    CVE-2010-2293

    Last Modified: 11 Apr 2025

    The Ping tools web interface in Dlink Di-604 router allows remote authenticated users to cause a denial of service via a large "ip textfield" size.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2289

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2288

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in dana/nc/ncrun.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to inject arbitrary web script or HTML via the DSSignInURL cookie.

    Published: 15 Jun 2010
    6.8
    Medium

    CVE-2010-2294

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Plume CMS 1.2.4 and possibly earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via unspecified vectors.

    Published: 15 Jun 2010
    6.8
    Medium

    CVE-2010-2065

    Last Modified: 11 Apr 2025

    Integer overflow in the TIFFroundup macro in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TIFF file that triggers a buffer overflow.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-3053

    Last Modified: 11 Apr 2025

    bdf/bdflib.c in FreeType before 2.4.2 allows remote attackers to cause a denial of service (application crash) via a crafted BDF font file, related to an attempted modification of a value in a static string.

    Published: 15 Jun 2010
    6
    Medium

    CVE-2010-0540

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, allows remote attackers to hijack the authentication of administrators for requests that change settings.

    Published: 15 Jun 2010
    2.6
    Low

    CVE-2010-2431

    Last Modified: 11 Apr 2025

    The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cache/cups/job.cache file.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-2482

    Last Modified: 11 Apr 2025

    LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted TIFF file, a different vulnerability than CVE-2010-2443.

    Published: 15 Jun 2010
    9.8
    Critical

    CVE-2010-2076

    Last Modified: 11 Apr 2025

    Apache CXF 2.0.x before 2.0.13, 2.1.x before 2.1.10, and 2.2.x before 2.2.9, as used in Apache ServiceMix, Apache Camel, Apache Chemistry, Apache jUDDI, Apache Geronimo, and other products, does not properly reject DTDs in SOAP messages, which allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via a crafted DTD, as demonstrated by an entity declaration in a request to samples/wsdl_first_pure_xml, a similar issue to CVE-2010-1632.

    Published: 15 Jun 2010
    5
    Medium

    CVE-2010-2443

    Last Modified: 11 Apr 2025

    The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.

    Published: 15 Jun 2010
    4.3
    Medium

    CVE-2010-3878

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests that deploy WAR files.

    Published: 15 Jun 2010
    6
    Medium

    CVE-2010-1514

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in TomatoCMS 2.0.6 and earlier allows remote authenticated users, with certain privileges, to execute arbitrary PHP code by uploading an image file, and then accessing it via a direct request to the file in an unspecified directory.

    Published: 14 Jun 2010
    2.6
    Low

    CVE-2010-1515

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) article-id parameter in conjunction with a /admin/news/article/list PATH_INFO; the (3) keyword parameter in conjunction with a /admin/multimedia/set/list PATH_INFO; the (4) keyword or (5) fileId parameter in conjunction with a /admin/multimedia/file/list PATH_INFO; or the (6) name, (7) email, or (8) address parameter in conjunction with a /admin/ad/client/list PATH_INFO.

    Published: 14 Jun 2010
    6.8
    Medium

    CVE-2010-2268

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to hijack the authentication of administrators for requests that create user accounts.

    Published: 14 Jun 2010
    5
    Medium

    CVE-2010-2269

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in loadstatic.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.

    Published: 14 Jun 2010
    7.5
    High

    CVE-2010-2270

    Last Modified: 11 Apr 2025

    Accoria Web Server (aka Rock Web Server) 1.4.7 uses a predictable httpmod-sessionid cookie, which makes it easier for remote attackers to hijack sessions via a modified cookie.

    Published: 14 Jun 2010
    7.5
    High

    CVE-2010-2271

    Last Modified: 11 Apr 2025

    Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter.

    Published: 14 Jun 2010
    10
    Critical

    CVE-2010-2272

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in iframe_history.html in Dojo 0.4.x before 0.4.4 has unknown impact and remote attack vectors.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2275

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

    Published: 14 Jun 2010
    10
    Critical

    CVE-2010-2276

    Last Modified: 11 Apr 2025

    The default configuration of the build process in Dojo 0.4.x before 0.4.4, 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 has the copyTests=true and mini=false options, which makes it easier for remote attackers to have an unspecified impact via a request to a (1) test or (2) demo component.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2277

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Connections 2.5.x before 2.5.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) create or (2) edit form in the Communities component, the (3) verbiage field in the Bookmarks component, or (4) unspecified vectors related to the Mobile Blogs component.

    Published: 14 Jun 2010
    4
    Medium

    CVE-2010-2278

    Last Modified: 11 Apr 2025

    The bookmarklet pop-up in the Bookmarks component in IBM Lotus Connections 2.5.x before 2.5.0.2 does not properly follow the "force SSL" setting, which might make it easier for remote attackers to obtain the cleartext of network communication by sniffing the network, or spoof arbitrary servers via a man-in-the-middle attack.

    Published: 14 Jun 2010
    7.6
    High

    CVE-2010-2279

    Last Modified: 11 Apr 2025

    The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2280

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2274

    Last Modified: 11 Apr 2025

    Multiple open redirect vulnerabilities in Dojo 1.0.x before 1.0.3, 1.1.x before 1.1.2, 1.2.x before 1.2.4, 1.3.x before 1.3.3, and 1.4.x before 1.4.2 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, possibly related to dojo/resources/iframe_history.html, dojox/av/FLAudio.js, dojox/av/FLVideo.js, dojox/av/resources/audio.swf, dojox/av/resources/video.swf, util/buildscripts/jslib/build.js, util/buildscripts/jslib/buildUtil.js, and util/doh/runner.html.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2281

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in TomatoCMS 2.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword or (2) bannerid parameter in conjunction with a /admin/ad/banner/list PATH_INFO; and allow remote authenticated users, with certain privileges, to inject arbitrary web script or HTML via the (3) title or (4) answers parameter in conjunction with a /admin/poll/add PATH_INFO, or the (5) name parameter in conjunction with a /admin/category/add PATH_INFO.

    Published: 14 Jun 2010
    5.1
    Medium

    CVE-2010-2282

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password.

    Published: 14 Jun 2010
    4.3
    Medium

    CVE-2010-2267

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Accoria Web Server (aka Rock Web Server) 1.4.7 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the getenv sample program, (2) the desc parameter to loadstatic.cgi, (3) the name parameter to httpdcfg.cgi, or (4) the dns parameter to servercfg.cgi.

    Published: 14 Jun 2010