CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2009-4876

    Last Modified: 11 Apr 2025

    admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.

    Published: 26 May 2010
    6.8
    Medium

    CVE-2009-4877

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in WebGUI before 7.7.14 allow remote attackers to hijack the authentication of users for unspecified requests via unknown vectors.

    Published: 26 May 2010
    4.3
    Medium

    CVE-2010-1639

    Last Modified: 11 Apr 2025

    The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.

    Published: 26 May 2010
    4.3
    Medium

    CVE-2009-4879

    Last Modified: 11 Apr 2025

    The Identity Server in Novell Access Manager before 3.1 SP1 allows attackers with disabled Active Directory accounts to authenticate using X.509 authentication, which bypasses intended access restrictions.

    Published: 26 May 2010
    4.3
    Medium

    CVE-2009-4878

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Administration Console in Novell Access Manager before 3.1 SP1 allows attackers to access system files via unknown attack vectors.

    Published: 26 May 2010
    5
    Medium

    CVE-2010-2101

    Last Modified: 11 Apr 2025

    The (1) strip_tags, (2) setcookie, (3) strtok, (4) wordwrap, (5) str_word_count, and (6) str_pad functions in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.

    Published: 26 May 2010
    4.4
    Medium

    CVE-2010-4820

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.

    Published: 26 May 2010
    7.2
    High

    CVE-2010-2055

    Last Modified: 11 Apr 2025

    Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than CVE-2010-4820.

    Published: 26 May 2010
    Unknown

    CVE-2010-2077

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1640. Reason: This candidate is a duplicate of CVE-2010-1640. Notes: All CVE users should reference CVE-2010-1640 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 May 2010
    5
    Medium

    CVE-2010-2078

    Last Modified: 11 Apr 2025

    DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI.

    Published: 25 May 2010
    5
    Medium

    CVE-2010-2079

    Last Modified: 11 Apr 2025

    DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions, and read arbitrary files, via a trailing backslash in a URI, as demonstrated by (1) web.config\ and (2) .ascx\ files.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2044

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Konsultasi (com_konsultasi) component 1.0.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sid parameter in a detail action to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2045

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2047

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information.

    Published: 25 May 2010
    3.5
    Low

    CVE-2010-2048

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Heartbeat module 6.x before 6.x-4.9 for Drupal allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 May 2010
    4.3
    Medium

    CVE-2010-2049

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in jsp/audit/reports/ExportReport.jsp in ManageEngine ADAudit Plus 4.0.0 build 4043 allows remote attackers to inject arbitrary web script or HTML via the reportList parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2050

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Moron Solutions MS Comment (com_mscomment) component 0.8.0b for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2051

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in article.php in Debliteck DBCart allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 25 May 2010
    4.3
    Medium

    CVE-2010-2046

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the ActiveHelper LiveHelp (com_activehelper_livehelp) component 2.0.3 for Joomla! allow remote attackers to inject arbitrary web script or HTML via (1) the DOMAINID parameter to server/cookies.php or (2) the SERVER parameter to server/index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2033

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Percha Multicategory Article (com_perchacategoriestree) component 0.6 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2034

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2035

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2036

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Percha Fields Attach (com_perchafieldsattach) component 1.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2037

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Percha Downloads Attach (com_perchadownloadsattach) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 25 May 2010
    6.8
    Medium

    CVE-2010-2039

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in gpEasy CMS 1.6.2, 1.6.1, and earlier allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an Admin_Users action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 25 May 2010
    4.3
    Medium

    CVE-2010-2040

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in V-EVA Shopzilla Affiliate Script PHP allows remote attackers to inject arbitrary web script or HTML via the s parameter.

    Published: 25 May 2010
    4.3
    Medium

    CVE-2010-2041

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP-Calendar before 2.0 Beta7 allow remote attackers to inject arbitrary web script or HTML via the (1) description and (2) lastaction parameters.

    Published: 25 May 2010
    7.5
    High

    CVE-2010-2042

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in ECShop 2.7.2 allows remote attackers to execute arbitrary SQL commands via the encode parameter. NOTE: some of these details are obtained from third party information.

    Published: 25 May 2010
    4.3
    Medium

    CVE-2010-2043

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Home.aspx in DataTrack System 3.5 and 3.5.8019.4 allows remote attackers to inject arbitrary web script or HTML via the Work_Order_Summary parameter (aka the request summary). NOTE: some of these details are obtained from third party information.

    Published: 25 May 2010
    2.1
    Low

    CVE-2010-2038

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in include/tool/editing_files.php in gpEasy CMS 1.6.2 allows remote authenticated users, with Edit privileges, to inject arbitrary web script or HTML via the gpcontent parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 25 May 2010
    5.1
    Medium

    CVE-2010-0830

    Last Modified: 11 Apr 2025

    Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF header.

    Published: 25 May 2010
    7.2
    High

    CVE-2010-0296

    Last Modified: 11 Apr 2025

    The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount request.

    Published: 25 May 2010
    9.3
    Critical

    CVE-2010-1688

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.

    Published: 24 May 2010
    1.9
    Low

    CVE-2010-2027

    Last Modified: 11 Apr 2025

    Mathematica 7, when running on Linux, allows local users to overwrite arbitrary files via a symlink attack on (1) files within /tmp/MathLink/ or (2) /tmp/fonts$$.conf.

    Published: 24 May 2010
    10
    Critical

    CVE-2010-2028

    Last Modified: 11 Apr 2025

    Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long transport mode.

    Published: 24 May 2010
    4.3
    Medium

    CVE-2010-2032

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.1.5, 3.1.10, 4.0.6, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via the (1) digest_realm or (2) digest_username parameters. NOTE: some of these details are obtained from third party information.

    Published: 24 May 2010
    7.2
    High

    CVE-2010-2031

    Last Modified: 11 Apr 2025

    KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel memory via a crafted request to IOCTL 0x830020d4 on the KAVSafe device.

    Published: 24 May 2010
    4.3
    Medium

    CVE-2010-2030

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the External Link Page module 5.x before 5.x-1.0 and 6.x before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors related to the administration and redirect pages.

    Published: 24 May 2010
    5.8
    Medium

    CVE-2010-2029

    Last Modified: 11 Apr 2025

    Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.

    Published: 24 May 2010
    7.5
    High

    CVE-2010-2016

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via the p_id parameter.

    Published: 24 May 2010
    4.3
    Medium

    CVE-2010-2017

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in hasil-pencarian.html in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to inject arbitrary web script or HTML via the kata parameter. NOTE: some of these details are obtained from third party information.

    Published: 24 May 2010
    5
    Medium

    CVE-2010-2018

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 24 May 2010
    6.8
    Medium

    CVE-2010-2012

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in function.php in MigasCMS 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categorie parameter in a catalogo action. NOTE: some of these details are obtained from third party information.

    Published: 24 May 2010
    4.3
    Medium

    CVE-2010-2014

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cp/list_content.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the cl or possibly id parameter.

    Published: 24 May 2010
    4.3
    Medium

    CVE-2010-2013

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cp/edit_email.php in LiSK CMS 4.4 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 24 May 2010
    6.8
    Medium

    CVE-2010-2015

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in a view_inbox action to cp/cp_messages.php or (2) the id parameter to cp/edit_email.php.

    Published: 24 May 2010
    6.8
    Medium

    CVE-2010-2019

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in downlot.php in Lokomedia CMS 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the file parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 24 May 2010
    4.6
    Medium

    CVE-2010-1641

    Last Modified: 11 Apr 2025

    The do_gfs2_set_flags function in fs/gfs2/file.c in the Linux kernel before 2.6.34-git10 does not verify the ownership of a file, which allows local users to bypass intended access restrictions via a SETFLAGS ioctl request.

    Published: 24 May 2010
    6.8
    Medium

    CVE-2010-2304

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1773. Reason: This candidate is a duplicate of CVE-2010-1773. Notes: All CVE users should reference CVE-2010-1773 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 May 2010
    7.5
    High

    CVE-2010-2060

    Last Modified: 11 Apr 2025

    The put command functionality in beanstalkd 1.4.5 and earlier allows remote attackers to execute arbitrary Beanstalk commands via the body in a job that is too big, which is not properly handled by the dispatch_cmd function in prot.c.

    Published: 23 May 2010