CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2010-1904

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in EMC RSA Key Manager (RKM) C Client 1.5.x allows user-assisted remote attackers to execute arbitrary SQL commands via the metadata section of encrypted key data.

    Published: 7 Jun 2010
    10
    Critical

    CVE-2010-1962

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP StorageWorks Storage Mirroring 5 before 5.2.1.870.0 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 7 Jun 2010
    4.3
    Medium

    CVE-2010-1963

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Jun 2010
    2.1
    Low

    CVE-2010-2157

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in CA ARCserve Backup r11.5 SP4, r12.0 SP2, and r12.5 SP1 on Windows allows local users to obtain sensitive information via unknown vectors.

    Published: 7 Jun 2010
    2.1
    Low

    CVE-2010-2158

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) phone, or (3) im parameter in a stormperson action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 Jun 2010
    3.3
    Low

    CVE-2010-2053

    Last Modified: 11 Apr 2025

    emesenelib/ProfileManager.py in emesene before 1.6.2 allows local users to overwrite arbitrary files via a symlink attack on the emsnpic temporary file.

    Published: 7 Jun 2010
    2.1
    Low

    CVE-2010-2058

    Last Modified: 11 Apr 2025

    setup.py in Prewikka 0.9.14 installs prewikka.conf with world-readable permissions, which allows local users to obtain the SQL database password.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1392

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to HTML buttons and the first-letter CSS style.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1397

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to a layout change during selection rendering and the DOCUMENT_POSITION_DISCONNECTED attribute in a container of an unspecified type.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1399

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during a selection change on a form input element, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1400

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving caption elements.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1401

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving the :first-letter pseudo-element.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1404

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an SVG document that contains recursive Use elements, which are not properly handled during page deconstruction.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1414

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the removeChild DOM method.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1415

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle libxml contexts, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to an "API abuse issue."

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1417

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via HTML content that contains multiple :after pseudo-selectors.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1749

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Cascading Style Sheets (CSS) run-in property and multiple invocations of a destructor for a child element that has been referenced multiple times.

    Published: 7 Jun 2010
    7.5
    High

    CVE-2010-1766

    Last Modified: 11 Apr 2025

    Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade header that is long and invalid.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1771

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving fonts.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1774

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses out-of-bounds memory during processing of HTML tables, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1387

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in JavaScriptCore in WebKit in Apple iTunes before 9.2 on Windows, and Apple iOS before 4 on the iPhone and iPod touch, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page transitions, a different vulnerability than CVE-2010-1763 and CVE-2010-1769.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1396

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the contentEditable attribute and removing container elements.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1398

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly perform ordered list insertions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document, related to the insertion of an unspecified element into an editable container and the access of an uninitialized element.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1403

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, accesses uninitialized memory during the handling of a use element in an SVG document, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document containing XML that triggers a parsing error, related to ProcessInstruction.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1405

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML element that has custom vertical positioning.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1410

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an SVG document with nested use elements.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1759

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1761

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML document subtrees.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1770

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."

    Published: 7 Jun 2010
    8.8
    High

    CVE-2010-1772

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1402

    Last Modified: 11 Apr 2025

    Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to an event listener in an SVG document, related to duplicate event listeners, a timer, and an AnimateTransform object.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1412

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to hover events.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1419

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving a certain window close action that occurs during a drag-and-drop operation.

    Published: 7 Jun 2010
    9.3
    Critical

    CVE-2010-1758

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving DOM Range objects.

    Published: 7 Jun 2010
    8.8
    High

    CVE-2010-1773

    Last Modified: 11 Apr 2025

    Off-by-one error in the toAlphabetic function in rendering/RenderListMarker.cpp in WebCore in WebKit before r59950, as used in Google Chrome before 5.0.375.70, allows remote attackers to obtain sensitive information, cause a denial of service (memory corruption and application crash), or possibly execute arbitrary code via vectors related to list markers for HTML lists, aka rdar problem 8009118.

    Published: 7 Jun 2010
    5.8
    Medium

    CVE-2010-0831

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

    Published: 6 Jun 2010
    2.6
    Low

    CVE-2010-2322

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

    Published: 6 Jun 2010
    9.3
    Critical

    CVE-2010-0395

    Last Modified: 11 Apr 2025

    OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.

    Published: 5 Jun 2010
    7.8
    High

    CVE-2010-1297

    Last Modified: 21 Apr 2026

    Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.

    Published: 4 Jun 2010
    4
    Medium

    CVE-2010-2149

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Fujitsu e-Pares V01 L01, L03, L10, L20, L30 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 3 Jun 2010
    2.6
    Low

    CVE-2010-2151

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Fujitsu e-Pares V01 L01 V01 L01, L03, L10, L20, L30, and L40 allows remote attackers to hijack the authentication of users for requests that modify "facility reservation data" via unknown vectors.

    Published: 3 Jun 2010
    6.8
    Medium

    CVE-2010-2153

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in cache/.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2010-2155

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in zc/publisher/html.rb in ZoneCheck 2.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) xmlnode.value, (2) zc-error text, (3) $zc_version, (4) domainname in a zc-title row, different vulnerabilities than CVE-2009-4882.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2010-2154

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: some of these details are obtained from third party information.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2010-2150

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability Fujitsu e-Pares V01 L01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Jun 2010
    9.3
    Critical

    CVE-2010-2152

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitrary code via unknown vectors related to "product character attribute processing" for a document.

    Published: 3 Jun 2010
    7.5
    High

    CVE-2010-2143

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the mode parameter.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2010-2144

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information.

    Published: 3 Jun 2010
    7.5
    High

    CVE-2010-2145

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in ClearSite Beta 4.50, and possibly other versions, allow remote attackers to execute arbitrary PHP code via a URL in the cs_base_path parameter to (1) docs.php and (2) include/admin/device_admin.php. NOTE: the header.php vector is already covered by CVE-2009-3306. NOTE: this issue may be due to a variable extraction error.

    Published: 3 Jun 2010
    7.5
    High

    CVE-2010-2146

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP code via a URL in the VL_include_path parameter.

    Published: 3 Jun 2010