CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-2148

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the pagina parameter to index.php.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2010-2147

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the modveh parameter to index.php.

    Published: 3 Jun 2010
    4.4
    Medium

    CVE-2010-2023

    Last Modified: 11 Apr 2025

    transports/appendfile.c in Exim before 4.72, when a world-writable sticky-bit mail directory is used, does not verify the st_nlink field of mailbox files, which allows local users to cause a denial of service or possibly gain privileges by creating a hard link to another user's file.

    Published: 3 Jun 2010
    4.4
    Medium

    CVE-2010-2024

    Last Modified: 11 Apr 2025

    transports/appendfile.c in Exim before 4.72, when MBX locking is enabled, allows local users to change permissions of arbitrary files or create arbitrary files, and cause a denial of service or possibly gain privileges, via a symlink attack on a lockfile in /tmp/.

    Published: 3 Jun 2010
    8.8
    High

    CVE-2010-4664

    Last Modified: 21 Nov 2024

    In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.

    Published: 3 Jun 2010
    4.3
    Medium

    CVE-2009-4882

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in zc/publisher/html.rb in ZoneCheck 2.0.4-13 and 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the ns parameter to zc.cgi.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2140

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in itemdetail.php in Multishop CMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2141

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands via the PictureId parameter in an open action.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2142

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in Cyberhost allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2139

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in pages.php in Multishop CMS allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 2 Jun 2010
    4.3
    Medium

    CVE-2010-2130

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbitrary web script or HTML via the errmsg parameter.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2134

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in Project Man 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2135

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in HazelPress Lite 0.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) password fields.

    Published: 2 Jun 2010
    6.8
    Medium

    CVE-2010-2136

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in admin/index.php in Article Friendly, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2137

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in _center.php in ProMan 0.1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2132

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Open Education System (OES) 0.1 beta allow remote attackers to execute arbitrary PHP code via a URL in the CONF_INCLUDE_PATH parameter to (1) forum/admin.php and (2) plotgraph/index.php in admin/modules/modules/, and (3) admin_user/mod_admuser.php and (4) ogroup/mod_group.php in admin/modules/user_account/, different vectors than CVE-2007-1446.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2133

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.

    Published: 2 Jun 2010
    6.8
    Medium

    CVE-2010-2138

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in ProMan 0.1.1 and earlier allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the _SESSION[userLang] parameter to (1) elisttasks.php, (2) managepmanagers.php, (3) manageusers.php, (4) helpfunc.php, (5) managegroups.php, (6) manageprocess.php, and (7) manageusersgroups.php.

    Published: 2 Jun 2010
    7.5
    High

    CVE-2010-2131

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Calendar Base (cal) extension before 1.3.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via iCalendar data.

    Published: 2 Jun 2010
    5.5
    Medium

    CVE-2010-2066

    Last Modified: 11 Apr 2025

    The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.

    Published: 2 Jun 2010
    2.1
    Low

    CVE-2010-2125

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Rotor Banner module 5.x before 5.x-1.8 and 6.x before 6.x-2.5 for Drupal allow remote authenticated users, with "create rotor item" or "edit any rotor item" privileges, to inject arbitrary web script or HTML via the (1) srs, (2) title, or (3) alt image attribute.

    Published: 1 Jun 2010
    7.5
    High

    CVE-2010-2126

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Snipe Gallery 3.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the cfg_admin_path parameter to (1) index.php, (2) view.php, (3) image.php, (4) search.php, (5) admin/index.php, (6) admin/gallery/index.php, (7) admin/gallery/view.php, (8) admin/gallery/gallery.php, (9) admin/gallery/image.php, and (10) admin/gallery/crop.php.

    Published: 1 Jun 2010
    7.5
    High

    CVE-2010-2127

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in gallery.php in JV2 Folder Gallery 3.1 allows remote attackers to execute arbitrary PHP code via a URL in the lang_file parameter.

    Published: 1 Jun 2010
    7.5
    High

    CVE-2010-2128

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JE Quotation Form (com_jequoteform) component 1.0b1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

    Published: 1 Jun 2010
    6.8
    Medium

    CVE-2010-2129

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.1 and 1.0.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 1 Jun 2010
    6.8
    Medium

    CVE-2010-2122

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Published: 1 Jun 2010
    2.1
    Low

    CVE-2010-2123

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Storm module 5.x and 6.x before 6.x-1.33 for Drupal allow remote authenticated users, with certain module privileges, to inject arbitrary web script or HTML via the (1) fullname, (2) address, (3) city, (4) provstate (aka state), (5) phone, or (6) taxid parameter in a stormorganization action to index.php; the (7) name parameter in a stormperson action to index.php; the (8) stepno (aka Step no.) or (9) title parameter in a stormtask action to index.php; the (10) title (aka Project) parameter in a stormticket action to index.php; or (11) unspecified parameters in a stormproject action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 1 Jun 2010
    7.5
    High

    CVE-2010-2124

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in firma.php in Bartels Schone ConPresso 4.0.7 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 1 Jun 2010
    4.3
    Medium

    CVE-2010-2119

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6.0.2900.2180 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid nntp:// URIs.

    Published: 1 Jun 2010
    4.3
    Medium

    CVE-2010-2120

    Last Modified: 11 Apr 2025

    Google Chrome 1.0.154.48 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.

    Published: 1 Jun 2010
    4.3
    Medium

    CVE-2010-2121

    Last Modified: 11 Apr 2025

    Opera 9.52 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.

    Published: 1 Jun 2010
    4.3
    Medium

    CVE-2010-2118

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6.0.2900.2180 and 8.0.7600.16385 allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid news:// URIs.

    Published: 1 Jun 2010
    3.6
    Low

    CVE-2010-1439

    Last Modified: 11 Apr 2025

    yum-rhn-plugin in Red Hat Network Client Tools (aka rhn-client-tools) on Red Hat Enterprise Linux (RHEL) 5 and Fedora uses world-readable permissions for the /var/spool/up2date/loginAuth.pkl file, which allows local users to access the Red Hat Network profile, and possibly prevent future security updates, by leveraging authentication data from this file.

    Published: 1 Jun 2010
    7.2
    High

    CVE-2005-4889

    Last Modified: 11 Apr 2025

    lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file, a related issue to CVE-2010-2059.

    Published: 1 Jun 2010
    7.5
    High

    CVE-2010-0742

    Last Modified: 11 Apr 2025

    The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.

    Published: 1 Jun 2010
    6.4
    Medium

    CVE-2010-1633

    Last Modified: 11 Apr 2025

    RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass intended key requirements or obtain sensitive information via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 1 Jun 2010
    7.2
    High

    CVE-2010-2059

    Last Modified: 11 Apr 2025

    lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade, which might allow local users to gain privileges by creating a hard link to a vulnerable (1) setuid or (2) setgid file.

    Published: 1 Jun 2010
    5
    Medium

    CVE-2010-2156

    Last Modified: 11 Apr 2025

    ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID.

    Published: 1 Jun 2010
    7.2
    High

    CVE-2010-2199

    Last Modified: 11 Apr 2025

    lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to bypass intended access restrictions by creating a hard link to a vulnerable file that has a POSIX ACL, a related issue to CVE-2010-2059.

    Published: 1 Jun 2010
    10
    Critical

    CVE-2010-1937

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB before 1.3.8 might allow remote attackers to execute arbitrary code via a Content-Length HTTP header that specifies a value too small for the amount of POST data, aka bug #3001896.

    Published: 1 Jun 2010
    10
    Critical

    CVE-2010-2054

    Last Modified: 11 Apr 2025

    Integer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB 1.3.4 through 1.3.7, when the configuration sets httpMaxContentLength to a zero value, allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a large integer in the Content-Length HTTP header, aka bug #3001915. NOTE: some of these details are obtained from third party information.

    Published: 1 Jun 2010
    7.2
    High

    CVE-2010-2198

    Last Modified: 11 Apr 2025

    lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrade or deletion of the file in an RPM package removal, which might allow local users to gain privileges or bypass intended access restrictions by creating a hard link to a vulnerable file that has (1) POSIX file capabilities or (2) SELinux context information, a related issue to CVE-2010-2059.

    Published: 1 Jun 2010
    6.4
    Medium

    CVE-2010-2191

    Last Modified: 11 Apr 2025

    The (1) parse_str, (2) preg_match, (3) unpack, and (4) pack functions; the (5) ZEND_FETCH_RW, (6) ZEND_CONCAT, and (7) ZEND_ASSIGN_CONCAT opcodes; and the (8) ArrayObject::uasort method in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal function or handler. NOTE: vectors 2 through 4 are related to the call time pass by reference feature.

    Published: 31 May 2010
    5
    Medium

    CVE-2010-3062

    Last Modified: 11 Apr 2025

    mysqlnd_wireprotocol.c in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows remote attackers to (1) read sensitive memory via a modified length value, which is not properly handled by the php_mysqlnd_ok_read function; or (2) trigger a heap-based buffer overflow via a modified length value, which is not properly handled by the php_mysqlnd_rset_header_read function.

    Published: 31 May 2010
    5
    Medium

    CVE-2010-3063

    Last Modified: 11 Apr 2025

    The php_mysqlnd_read_error_from_line function in the Mysqlnd extension in PHP 5.3 through 5.3.2 does not properly calculate a buffer length, which allows context-dependent attackers to trigger a heap-based buffer overflow via crafted inputs that cause a negative length value to be used.

    Published: 31 May 2010
    5
    Medium

    CVE-2010-2190

    Last Modified: 11 Apr 2025

    The (1) trim, (2) ltrim, (3) rtrim, and (4) substr_replace functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.

    Published: 31 May 2010
    5
    Medium

    CVE-2010-3065

    Last Modified: 11 Apr 2025

    The default session serializer in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 does not properly handle the PS_UNDEF_MARKER marker, which allows context-dependent attackers to modify arbitrary session variables via a crafted session variable name.

    Published: 31 May 2010
    6.8
    Medium

    CVE-2010-3064

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the php_mysqlnd_auth_write function in the Mysqlnd extension in PHP 5.3 through 5.3.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) username or (2) database name argument to the (a) mysql_connect or (b) mysqli_connect function.

    Published: 31 May 2010
    4.3
    Medium

    CVE-2010-3697

    Last Modified: 11 Apr 2025

    The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requests, which allows remote attackers to cause a denial of service (daemon crash) by sending many requests.

    Published: 30 May 2010
    4.3
    Medium

    CVE-2010-3696

    Last Modified: 11 Apr 2025

    The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause a denial of service (infinite loop and daemon outage) via a packet that has more than one sub-option. NOTE: some of these details are obtained from third party information.

    Published: 30 May 2010