CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-2111

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in user/user-set.do in Pacific Timesheet 6.74 build 363 allows remote attackers to hijack the authentication of administrators for requests that create a new administrator via a new_admin action.

    Published: 28 May 2010
    8.8
    High

    CVE-2010-2112

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the FTP service in FileCOPA before 5.03 allows remote attackers to read or overwrite arbitrary files via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 28 May 2010
    3.5
    Low

    CVE-2010-2113

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in The Uniform Server 5.6.5 allow remote attackers to hijack the authentication of administrators for requests that change passwords via (1) apsetup.php, (2) psetup.php, (3) sslpsetup.php, or (4) mqsetup.php.

    Published: 28 May 2010
    2.6
    Low

    CVE-2010-2114

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in pbx/gate in Brekeke PBX 2.4.4.8 allows remote attackers to hijack the authentication of users for requests that change passwords via the pbxadmin.web.PbxUserEdit bean.

    Published: 28 May 2010
    5
    Medium

    CVE-2010-2115

    Last Modified: 11 Apr 2025

    SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.

    Published: 28 May 2010
    6.5
    Medium

    CVE-2010-2116

    Last Modified: 11 Apr 2025

    The web interface in McAfee Email Gateway (formerly IronMail) 6.7.1 allows remote authenticated users, with only Read privileges, to gain Write privileges to modify configuration via the save action in a direct request to admin/systemWebAdminConfig.do.

    Published: 28 May 2010
    7.1
    High

    CVE-2010-1919

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in EMC Avamar 4.1.x and 5.0 before SP1 allows remote attackers to cause a denial of service (gsan service hang) by sending a crafted message using TCP.

    Published: 28 May 2010
    6.9
    Medium

    CVE-2010-2020

    Last Modified: 11 Apr 2025

    sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request.

    Published: 28 May 2010
    10
    Critical

    CVE-2010-2105

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.

    Published: 28 May 2010
    4.3
    Medium

    CVE-2010-2106

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 5.0.375.55 might allow remote attackers to spoof the URL bar via vectors involving unload event handlers.

    Published: 28 May 2010
    7.5
    High

    CVE-2010-2108

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 5.0.375.55 allows remote attackers to bypass the whitelist-mode plugin blocker via unknown vectors.

    Published: 28 May 2010
    7.5
    High

    CVE-2010-2109

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 5.0.375.55 allows user-assisted remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the "drag + drop" functionality.

    Published: 28 May 2010
    7.5
    High

    CVE-2010-2110

    Last Modified: 11 Apr 2025

    Google Chrome before 5.0.375.55 does not properly execute JavaScript code in the extension context, which has unspecified impact and remote attack vectors.

    Published: 28 May 2010
    9.3
    Critical

    CVE-2010-1938

    Last Modified: 11 Apr 2025

    Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeBSD 6.4 through 8.1-PRERELEASE and other platforms, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long username, as demonstrated by a long USER command to the FreeBSD 8.0 ftpd.

    Published: 28 May 2010
    3.3
    Low

    CVE-2010-2022

    Last Modified: 11 Apr 2025

    jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations.

    Published: 28 May 2010
    10
    Critical

    CVE-2010-2107

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 5.0.375.55 allows attackers to cause a denial of service (memory error) or possibly have unspecified other impact via vectors related to the Safe Browsing functionality.

    Published: 28 May 2010
    6.2
    Medium

    CVE-2010-1646

    Last Modified: 11 Apr 2025

    The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multiple PATH variables, which might allow local users to gain privileges via a crafted value of the last PATH variable.

    Published: 28 May 2010
    7.5
    High

    CVE-2010-2095

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.

    Published: 27 May 2010
    7.5
    High

    CVE-2010-2096

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in CMSQlite 1.2 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.

    Published: 27 May 2010
    7.5
    High

    CVE-2010-2098

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in usersettings.php in e107 0.7.20 and earlier allows remote attackers to conduct SQL injection attacks via the loginname parameter.

    Published: 27 May 2010
    7.5
    High

    CVE-2010-2099

    Last Modified: 11 Apr 2025

    bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method.

    Published: 27 May 2010
    10
    Critical

    CVE-2010-2102

    Last Modified: 11 Apr 2025

    Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2104

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Orbit Downloader 3.0.0.4 and 3.0.0.5 allows user-assisted remote attackers to write arbitrary files via a metalink file containing directory traversal sequences in the name attribute of a file element.

    Published: 27 May 2010
    9
    Critical

    CVE-2010-0596

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Mediator Framework 2.2 before 2.2.1.dev.1 and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 allows remote authenticated users to read or modify the device configuration, and gain privileges, via a (1) HTTP or (2) HTTPS request, aka Bug ID CSCtb83607.

    Published: 27 May 2010
    10
    Critical

    CVE-2010-0600

    Last Modified: 11 Apr 2025

    Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not properly restrict network access to an unspecified configuration file, which allows remote attackers to read passwords and unspecified other account details via a (1) XML RPC or (2) XML RPC over HTTPS session, aka Bug ID CSCtb83512.

    Published: 27 May 2010
    10
    Critical

    CVE-2010-0595

    Last Modified: 11 Apr 2025

    Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 has a default password for the administrative user account and unspecified other accounts, which makes it easier for remote attackers to obtain privileged access, aka Bug ID CSCtb83495.

    Published: 27 May 2010
    9
    Critical

    CVE-2010-0597

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 allows remote authenticated users to read or modify the device configuration, and gain privileges or cause a denial of service (device reload), via a (1) XML RPC or (2) XML RPC over HTTPS request, aka Bug ID CSCtb83618.

    Published: 27 May 2010
    9.3
    Critical

    CVE-2010-0599

    Last Modified: 11 Apr 2025

    Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83505.

    Published: 27 May 2010
    9.3
    Critical

    CVE-2010-1296

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) .ASL, (2) .ABR, or (3) .GRD file.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2091

    Last Modified: 11 Apr 2025

    Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via an invalid value.

    Published: 27 May 2010
    9.3
    Critical

    CVE-2010-0598

    Last Modified: 11 Apr 2025

    Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt HTTP sessions from operator workstations, which allows remote attackers to discover Administrator credentials by sniffing the network, aka Bug ID CSCtb83631.

    Published: 27 May 2010
    5
    Medium

    CVE-2010-1959

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP TestDirector for Quality Center 9.2 before Patch8 allows remote attackers to modify data via unknown vectors.

    Published: 27 May 2010
    5
    Medium

    CVE-2010-2090

    Last Modified: 11 Apr 2025

    The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2084

    Last Modified: 11 Apr 2025

    Microsoft ASP.NET 2.0 does not prevent setting the InnerHtml property on a control that inherits from HtmlContainerControl, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to an attribute.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2088

    Last Modified: 11 Apr 2025

    ASP.NET in Microsoft .NET 3.5 does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks against the form control via the __VIEWSTATE parameter.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2085

    Last Modified: 11 Apr 2025

    The default configuration of ASP.NET in Microsoft .NET before 1.1 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the __VIEWSTATE parameter.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-0541

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WEBrick HTTP server in Ruby in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote attackers to inject arbitrary web script or HTML via a crafted URI that triggers a UTF-7 error page.

    Published: 27 May 2010
    7.1
    High

    CVE-2010-2064

    Last Modified: 21 Nov 2024

    rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr.

    Published: 27 May 2010
    5.5
    Medium

    CVE-2010-5328

    Last Modified: 20 Apr 2025

    include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper process, which allows local users to cause a denial of service (system crash) by leveraging access to this process group.

    Published: 27 May 2010
    3.3
    Low

    CVE-2010-2056

    Last Modified: 11 Apr 2025

    GNU gv before 3.7.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

    Published: 27 May 2010
    7.8
    High

    CVE-2010-2061

    Last Modified: 21 Nov 2024

    rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.

    Published: 27 May 2010
    4.3
    Medium

    CVE-2010-2117

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.0.19, 3.5.x, and 3.6.x allows remote attackers to cause a denial of service (resource consumption) via JavaScript code containing an infinite loop that creates IFRAME elements for invalid (1) news:// or (2) nntp:// URIs.

    Published: 27 May 2010
    6.8
    Medium

    CVE-2010-1513

    Last Modified: 11 Apr 2025

    Multiple integer overflows in src/image.c in Ziproxy before 3.0.1 allow remote attackers to execute arbitrary code via (1) a large JPG image, related to the jpg2bitmap function or (2) a large PNG image, related to the png2bitmap function, leading to heap-based buffer overflows.

    Published: 26 May 2010
    6.4
    Medium

    CVE-2010-2026

    Last Modified: 11 Apr 2025

    The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.

    Published: 26 May 2010
    5
    Medium

    CVE-2010-2082

    Last Modified: 11 Apr 2025

    The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 has a default administrative password (aka SAPassword) of W2402, which makes it easier for remote attackers to obtain privileged access.

    Published: 26 May 2010
    4
    Medium

    CVE-2010-2083

    Last Modified: 11 Apr 2025

    Microsoft Dynamics GP has a default value of ACCESS for the system password, which might make it easier for remote authenticated users to bypass intended access restrictions via unspecified vectors.

    Published: 26 May 2010
    6.8
    Medium

    CVE-2010-2025

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allow remote attackers to hijack the authentication of administrators for requests that (1) reset the modem, (2) erase the firmware, (3) change the administrative password, (4) install modified firmware, or (5) change the access level, as demonstrated by a request to goform/_aslvl.

    Published: 26 May 2010
    10
    Critical

    CVE-2009-4873

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.

    Published: 26 May 2010
    6.4
    Medium

    CVE-2009-4874

    Last Modified: 11 Apr 2025

    TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.

    Published: 26 May 2010
    5
    Medium

    CVE-2009-4875

    Last Modified: 11 Apr 2025

    FCKeditor.Java 2.4 allows remote attackers to cause a denial of service (infinite loop) via a malformed request parameter that contains "ctrl" characters.

    Published: 26 May 2010