CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2009-4867

    Last Modified: 11 Apr 2025

    Buffer overflow in Tuniac 090517c allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long URL in a .m3u playlist file.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4868

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Hitron Soft Answer Me 1.0 allows remote attackers to inject arbitrary web script or HTML via the q_id parameter to the answers script (aka answers.php). NOTE: some of these details are obtained from third party information.

    Published: 10 May 2010
    7.5
    High

    CVE-2009-4871

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in globepersonnel_forum.asp in Logoshows BBS 2.0 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Published: 10 May 2010
    7.5
    High

    CVE-2009-4872

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields.

    Published: 10 May 2010
    7.5
    High

    CVE-2009-4862

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) show.php and (2) xml.php.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4864

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Script allow remote attackers to inject arbitrary web script or HTML via the (1) search_name and (2) languages parameters. NOTE: some of these details are obtained from third party information.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4866

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.cgi in Matt's Script Archive (MSA) Simple Search 1.0 allows remote attackers to inject arbitrary web script or HTML via the terms parameter. NOTE: some of these details are obtained from third party information.

    Published: 10 May 2010
    7.5
    High

    CVE-2009-4870

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the (1) req_username (aka Username) and (2) req_password (aka Password) parameters. NOTE: some of these details are obtained from third party information.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4856

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to inject arbitrary web script or HTML via the name parameter.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4861

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in shownews.php in SupportPRO SupportDesk 3.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 10 May 2010
    4.3
    Medium

    CVE-2009-4869

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Published: 10 May 2010
    7.5
    High

    CVE-2010-1450

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function.

    Published: 10 May 2010
    4
    Medium

    CVE-2010-3839

    Last Modified: 11 Apr 2025

    MySQL 5.1 before 5.1.51 and 5.5 before 5.5.6 allows remote authenticated users to cause a denial of service (infinite loop) via multiple invocations of a (1) prepared statement or (2) stored procedure that creates a query with nested JOIN statements.

    Published: 10 May 2010
    5
    Medium

    CVE-2009-4134

    Last Modified: 11 Apr 2025

    Buffer underflow in the rgbimg module in Python 2.5 allows remote attackers to cause a denial of service (application crash) via a large ZSIZE value in a black-and-white (aka B/W) RGB image that triggers an invalid pointer dereference.

    Published: 10 May 2010
    7.5
    High

    CVE-2010-1449

    Last Modified: 11 Apr 2025

    Integer overflow in rgbimgmodule.c in the rgbimg module in Python 2.5 allows remote attackers to have an unspecified impact via a large image that triggers a buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-3143.12.

    Published: 10 May 2010
    5
    Medium

    CVE-2010-1634

    Last Modified: 11 Apr 2025

    Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-3143.5.

    Published: 10 May 2010
    5
    Medium

    CVE-2010-1915

    Last Modified: 11 Apr 2025

    The preg_quote function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature, modification of ZVALs whose values are not updated in the associated local variables, and access of previously-freed memory.

    Published: 9 May 2010
    5
    Medium

    CVE-2010-1914

    Last Modified: 11 Apr 2025

    The Zend Engine in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information by interrupting the handler for the (1) ZEND_BW_XOR opcode (shift_left_function), (2) ZEND_SL opcode (bitwise_xor_function), or (3) ZEND_SR opcode (shift_right_function), related to the convert_to_long_base function.

    Published: 8 May 2010
    5.8
    Medium

    CVE-2010-1974

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1168. Reason: This candidate is a duplicate of CVE-2010-1168. Notes: All CVE users should reference CVE-2010-1168 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 8 May 2010
    7.5
    High

    CVE-2009-4854

    Last Modified: 11 Apr 2025

    addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.

    Published: 7 May 2010
    6.8
    Medium

    CVE-2010-1859

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.

    Published: 7 May 2010
    7.5
    High

    CVE-2010-1863

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the shoutbox module (modules/shoutbox.php) in ClanTiger 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the s_email parameter.

    Published: 7 May 2010
    7.5
    High

    CVE-2010-1867

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/attachments.php in Campsite 3.3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the article_id parameter.

    Published: 7 May 2010
    7.5
    High

    CVE-2010-1865

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in ClanSphere 2009.0.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the IP address to the cs_getip function in generate.php in the Captcha module, or (2) the s_email parameter to the cs_sql_select function in the MySQL database driver (mysql.php).

    Published: 7 May 2010
    6.8
    Medium

    CVE-2010-1853

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2010-1854

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to inject arbitrary web script or HTML via the id_auk parameter, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this might be resultant from CVE-2010-1855.

    Published: 7 May 2010
    7.5
    High

    CVE-2010-1855

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.

    Published: 7 May 2010
    2.6
    Low

    CVE-2010-1856

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.

    Published: 7 May 2010
    6.8
    Medium

    CVE-2010-1857

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the prod parameter in a products.details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 May 2010
    5
    Medium

    CVE-2010-1858

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Published: 7 May 2010
    4
    Medium

    CVE-2009-4847

    Last Modified: 11 Apr 2025

    Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service (daemon crash) via vectors involving an empty treasure list.

    Published: 7 May 2010
    9.3
    Critical

    CVE-2009-4850

    Last Modified: 11 Apr 2025

    The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneURL property value with a URL for a .exe file.

    Published: 7 May 2010
    5
    Medium

    CVE-2009-4851

    Last Modified: 11 Apr 2025

    The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2009-4853

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in JumpBox before 1.1.2 for Foswiki Wiki System allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 May 2010
    6.8
    Medium

    CVE-2009-4846

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Deliantra Server before 2.82 allow remote attackers to execute arbitrary code via vectors related to (1) the command_gsay function in server/c_party.C and (2) the book implementation.

    Published: 7 May 2010
    6.8
    Medium

    CVE-2009-4849

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to hijack the authentication of administrators for requests that (1) create a new user account via a save action to tvserver/user/user.do, (2) shutdown a virtual machine, (3) start a virtual machine, (4) restart a virtual machine, or (5) schedule an activity.

    Published: 7 May 2010
    2.1
    Low

    CVE-2010-1451

    Last Modified: 11 Apr 2025

    The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application.

    Published: 7 May 2010
    6.4
    Medium

    CVE-2010-1690

    Last Modified: 11 Apr 2025

    The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction IDs of responses match transaction IDs of queries, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2009-4848

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.2 build 7882 and 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) userId parameter to tvserver/server/user/setPermissions.jsp, (2) deptName parameter to tvserver/server/user/addDepartment.jsp, (3) ID parameter to tvserver/server/inventory/inventoryTabs.jsp, (4) reportName parameter to tvserver/reports/virtualIQAdminReports.do, or (5) middleName parameter in a save action to tvserver/user/user.do.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2009-4852

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SemanticScuttle before 0.94.1 allow remote attackers to inject arbitrary web script or HTML via the sort parameter to index.php, and other unspecified vectors, a different issue than CVE-2008-6113. NOTE: some of these details are obtained from third party information.

    Published: 7 May 2010
    6.4
    Medium

    CVE-2010-1689

    Last Modified: 11 Apr 2025

    The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs that are formed by incrementing a previous ID by 1, which makes it easier for man-in-the-middle attackers to spoof DNS responses, a different vulnerability than CVE-2010-0024 and CVE-2010-0025.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2009-4842

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ToutVirtual VirtualIQ Pro 3.5 build 8691 allow remote attackers to inject arbitrary web script or HTML via the (1) addNewDept, (2) deptId, or (3) deptDesc parameter to tvserver/server/user/addDepartment.jsp; or the (4) firstName, (5) lastName, or (6) email parameter in a save action to tvserver/user/user.do. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 7 May 2010
    7.5
    High

    CVE-2009-4843

    Last Modified: 11 Apr 2025

    ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console.

    Published: 7 May 2010
    5
    Medium

    CVE-2009-4844

    Last Modified: 11 Apr 2025

    ToutVirtual VirtualIQ Pro 3.2 build 7882 does not restrict access to the /status URI on port 9080, which allows remote attackers to obtain sensitive Tomcat information via a direct request.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2010-1453

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to inject arbitrary web script or HTML via the form_url parameter.

    Published: 7 May 2010
    10
    Critical

    CVE-2010-1549

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2010-1852

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request logging, related to a "cross-site data leakage" issue.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2010-1143

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in VMware View (formerly Virtual Desktop Manager or VDM) 3.1.x before 3.1.3 build 252693 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 May 2010
    4.3
    Medium

    CVE-2010-1851

    Last Modified: 11 Apr 2025

    Google Chrome, when the Invisible Hand extension is enabled, uses cookies during background HTTP requests in a possibly unexpected manner, which might allow remote web servers to identify specific persons and their product searches via HTTP request logging, related to a "cross-site data leakage" issue.

    Published: 7 May 2010
    5
    Medium

    CVE-2009-4845

    Last Modified: 11 Apr 2025

    The configuration page in ToutVirtual VirtualIQ Pro 3.2 build 7882 contains cleartext SSH credentials, which allows remote attackers to obtain sensitive information by reading the username and password fields.

    Published: 7 May 2010