CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-1557

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP Insight Control Server Migration before 6.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-1562

    Last Modified: 11 Apr 2025

    The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed Contact header, aka Bug ID CSCsj98521.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-1563

    Last Modified: 11 Apr 2025

    The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsk04588.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-1561

    Last Modified: 11 Apr 2025

    The SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S11 and 9.7(3)P before 9.7(3)P11 allows remote attackers to cause a denial of service (device crash) via a long message, aka Bug ID CSCsk44115.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-1567

    Last Modified: 11 Apr 2025

    The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.8(1)S5 allows remote attackers to cause a denial of service (device crash) via a malformed header, aka Bug ID CSCsz13590.

    Published: 14 May 2010
    4.3
    Medium

    CVE-2010-1940

    Last Modified: 11 Apr 2025

    Apple Safari 4.0.5 on Windows sends the "Authorization: Basic" header appropriate for one web site to a different web site named in a Location header received from the first site, which allows remote web servers to obtain sensitive information by logging HTTP requests. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-0604

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via unknown SIP traffic, as demonstrated by "SIP testing," aka Bug ID CSCsk38165.

    Published: 14 May 2010
    6.4
    Medium

    CVE-2010-1556

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Systems Insight Manager (SIM) 5.3, 5.3 Update 1, and 6.0 allows remote attackers to obtain sensitive information and modify data via unknown vectors.

    Published: 14 May 2010
    7.8
    High

    CVE-2010-1565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SIP implementation on the Cisco PGW 2200 Softswitch with software 9.7(3)S before 9.7(3)S9 and 9.7(3)P before 9.7(3)P9 allows remote attackers to cause a denial of service (TCP socket exhaustion) via unknown vectors, aka Bug ID CSCsk13561.

    Published: 14 May 2010
    5
    Medium

    CVE-2010-1568

    Last Modified: 11 Apr 2025

    The Send Secure functionality in the Cisco IronPort Desktop Flag Plug-in for Outlook before 6.5.0-006 does not properly handle simultaneously composed messages, which might allow remote attackers to obtain cleartext contents of e-mail messages that were intended to be encrypted, aka bug 65623.

    Published: 14 May 2010
    4.3
    Medium

    CVE-2010-0475

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in esp/editUser.esp in the Palo Alto Networks firewall 3.0.x before 3.0.9 and 3.1.x before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the role parameter.

    Published: 14 May 2010
    5
    Medium

    CVE-2010-1510

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in IrfanView before 4.27 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PSD image with RLE compression.

    Published: 14 May 2010
    4.7
    Medium

    CVE-2010-1558

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Multifunction Peripheral (MFP) Digital Sending Software before 4.18.3 allows local users to bypass intended restrictions on the MFP "Send to e-mail" feature, and obtain sensitive information, via unknown vectors.

    Published: 14 May 2010
    5
    Medium

    CVE-2010-1509

    Last Modified: 11 Apr 2025

    IrfanView before 4.27 does not properly handle an unspecified integer variable during processing of PSD images, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted image file that triggers a heap-based buffer overflow, related to a "sign-extension error."

    Published: 14 May 2010
    9.3
    Critical

    CVE-2009-3678

    Last Modified: 11 Apr 2025

    Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."

    Published: 14 May 2010
    6.8
    Medium

    CVE-2010-2950

    Last Modified: 11 Apr 2025

    Format string vulnerability in stream.c in the phar extension in PHP 5.3.x through 5.3.3 allows context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the phar_stream_flush function, leading to errors in the php_stream_wrapper_log_error function. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-2094.

    Published: 14 May 2010
    6.8
    Medium

    CVE-2010-2094

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in the phar extension in PHP 5.3 before 5.3.2 allow context-dependent attackers to obtain sensitive information (memory contents) and possibly execute arbitrary code via a crafted phar:// URI that is not properly handled by the (1) phar_stream_flush, (2) phar_wrapper_unlink, (3) phar_parse_url, or (4) phar_wrapper_open_url functions in ext/phar/stream.c; and the (5) phar_wrapper_open_dir function in ext/phar/dirstream.c, which triggers errors in the php_stream_wrapper_log_error function.

    Published: 14 May 2010
    7.6
    High

    CVE-2010-1939

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Apple Safari 4.0.5 on Windows allows remote attackers to execute arbitrary code by using window.open to create a popup window for a crafted HTML document, and then calling the parent window's close method, which triggers improper handling of a deleted window object.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1284

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1286

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1287

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1289, CVE-2010-1290, and CVE-2010-1291.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1288

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow attackers to execute arbitrary code via unspecified vectors.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1289

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1290, and CVE-2010-1291.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1290

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1291.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1291

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-1289, and CVE-2010-1290.

    Published: 13 May 2010
    4.3
    Medium

    CVE-2009-3467

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in an unspecified method in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-0127

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-0130

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.

    Published: 13 May 2010
    6.5
    Medium

    CVE-2010-1282

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted ATOM size in a .dir (aka Director) file.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1550

    Last Modified: 11 Apr 2025

    Format string vulnerability in ovet_demandpoll.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via format string specifiers in the sel parameter.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1551

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the _OVParseLLA function in ov.dll in netmon.exe in Network Monitor in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the sel parameter.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1554

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1555

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid Hostname parameter.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-0129

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-0986

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 does not properly process asset entries, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted Shockwave file.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-0987

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-1280

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-1281

    Last Modified: 11 Apr 2025

    iml32.dll in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.

    Published: 13 May 2010
    8.8
    High

    CVE-2010-1283

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-1292

    Last Modified: 11 Apr 2025

    The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file.

    Published: 13 May 2010
    4.3
    Medium

    CVE-2010-1293

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrator page in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 May 2010
    2.1
    Low

    CVE-2010-1294

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe ColdFusion 8.0, 8.0.1, and 9.0 allows local users to obtain sensitive information via unknown vectors.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1553

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.

    Published: 13 May 2010
    9.3
    Critical

    CVE-2010-0128

    Last Modified: 11 Apr 2025

    Integer signedness error in dirapi.dll in Adobe Shockwave Player before 11.5.7.609 and Adobe Director before 11.5.7.609 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir file that triggers an invalid read operation.

    Published: 13 May 2010
    10
    Critical

    CVE-2010-1552

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.

    Published: 13 May 2010
    6.4
    Medium

    CVE-2010-1511

    Last Modified: 11 Apr 2025

    KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to overwrite arbitrary files via a crafted metalink file.

    Published: 13 May 2010
    6.5
    Medium

    CVE-2010-1848

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to bypass intended table grants to read field definitions of arbitrary tables, and on 5.1 to read or delete content of arbitrary tables, via a .. (dot dot) in a table name.

    Published: 13 May 2010
    5
    Medium

    CVE-2010-1849

    Last Modified: 11 Apr 2025

    The my_net_skip_rest function in sql/net_serv.cc in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a large number of packets that exceed the maximum length.

    Published: 13 May 2010
    5.8
    Medium

    CVE-2010-1000

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in KGet in KDE SC 4.0.0 through 4.4.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.

    Published: 13 May 2010
    6
    Medium

    CVE-2010-1850

    Last Modified: 11 Apr 2025

    Buffer overflow in MySQL 5.0 through 5.0.91 and 5.1 before 5.1.47 allows remote authenticated users to execute arbitrary code via a COM_FIELD_LIST command with a long table name.

    Published: 13 May 2010