CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-1868

    Last Modified: 11 Apr 2025

    The (1) sqlite_single_query and (2) sqlite_array_query functions in ext/sqlite/sqlite.c in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allow context-dependent attackers to execute arbitrary code by calling these functions with an empty SQL query, which triggers access of uninitialized memory.

    Published: 7 May 2010
    6.8
    Medium

    CVE-2010-1737

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter.

    Published: 6 May 2010
    Unknown

    CVE-2010-1738

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1448. Reason: This candidate is a duplicate of CVE-2010-1448. Notes: All CVE users should reference CVE-2010-1448 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 May 2010
    7.5
    High

    CVE-2010-1739

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Newsfeeds (com_newsfeeds) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the feedid parameter in a categories action to index.php.

    Published: 6 May 2010
    7.5
    High

    CVE-2010-1740

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter.

    Published: 6 May 2010
    7.5
    High

    CVE-2010-1741

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in request_account.php in Billwerx RC 5.2.2 PL2 allows remote attackers to execute arbitrary SQL commands via the primary_number parameter.

    Published: 6 May 2010
    4.3
    Medium

    CVE-2010-1742

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in projects.php in Scratcher allows remote attackers to inject arbitrary web script or HTML via the show parameter.

    Published: 6 May 2010
    7.5
    High

    CVE-2010-1743

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2010
    Unknown

    CVE-2010-1745

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1867. Reason: This candidate is a duplicate of CVE-2010-1867. Notes: All CVE users should reference CVE-2010-1867 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 May 2010
    5
    Medium

    CVE-2010-1736

    Last Modified: 11 Apr 2025

    KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for d_atabase/Krmdb.mdb.

    Published: 6 May 2010
    7.5
    High

    CVE-2010-1744

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 6 May 2010
    4.3
    Medium

    CVE-2010-1746

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Table JX (com_grid) component for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) data_search and (2) rpp parameters to index.php.

    Published: 6 May 2010
    Unknown

    CVE-2010-1765

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    Unknown

    CVE-2010-1779

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    Unknown

    CVE-2010-1826

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    Unknown

    CVE-2010-1827

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    Unknown

    CVE-2010-1835

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    2.6
    Low

    CVE-2010-0730

    Last Modified: 11 Apr 2025

    The MMIO instruction decoder in the Xen hypervisor in the Linux kernel 2.6.18 in Red Hat Enterprise Linux (RHEL) 5 allows guest OS users to cause a denial of service (32-bit guest OS crash) via vectors that trigger an unspecified instruction emulation.

    Published: 6 May 2010
    Unknown

    CVE-2010-1798

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    7.8
    High

    CVE-2013-2017

    Last Modified: 11 Apr 2025

    The veth (aka virtual Ethernet) driver in the Linux kernel before 2.6.34 does not properly manage skbs during congestion, which allows remote attackers to cause a denial of service (system crash) by leveraging lack of skb consumption in conjunction with a double-free error.

    Published: 6 May 2010
    Unknown

    CVE-2010-1839

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 6 May 2010
    5
    Medium

    CVE-2010-1860

    Last Modified: 11 Apr 2025

    The html_entity_decode function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) or trigger memory corruption by causing a userspace interruption of an internal call, related to the call time pass by reference feature.

    Published: 6 May 2010
    7.1
    High

    CVE-2010-4526

    Last Modified: 11 Apr 2025

    Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list corruption, related to the sctp_wait_for_connect function.

    Published: 6 May 2010
    4.3
    Medium

    CVE-2009-4835

    Last Modified: 11 Apr 2025

    The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file.

    Published: 5 May 2010
    7.5
    High

    CVE-2009-4836

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbitrary PHP code via the anticode parameter.

    Published: 5 May 2010
    9.3
    Critical

    CVE-2009-4840

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method.

    Published: 5 May 2010
    9.3
    Critical

    CVE-2009-4841

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this might overlap CVE-2007-1559.

    Published: 5 May 2010
    6.8
    Medium

    CVE-2010-1732

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the users module in Zikula Application Framework before 1.2.3 allows remote attackers to hijack the authentication of administrators for requests that change the administrator email address (updateemail action).

    Published: 5 May 2010
    4.9
    Medium

    CVE-2010-1734

    Last Modified: 11 Apr 2025

    The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.

    Published: 5 May 2010
    4.9
    Medium

    CVE-2010-1735

    Last Modified: 11 Apr 2025

    The SfnLOGONNOTIFY function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x4c value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.

    Published: 5 May 2010
    7.5
    High

    CVE-2009-4838

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in base_ag_common.php in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters. NOTE: some of these details are obtained from third party information.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2009-4839

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE), possibly 1.4.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/base_roleadmin.php, (2) admin/base_useradmin.php, (3) base_conf_contents.php, (4) base_qry_sqlcalls.php, and (5) base_ag_main.php.

    Published: 5 May 2010
    6.8
    Medium

    CVE-2010-1733

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in OCS Inventory NG before 1.02.3 allow remote attackers to execute arbitrary SQL commands via (1) multiple inventory fields to the search form, reachable through index.php; or (2) the "Software name" field to the "All softwares" search form, reachable through index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2009-4837

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Basic Analysis and Security Engine (BASE) before 1.4.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) sig[1] parameter to base/base_qry_main.php, or the time[0][1] parameter to (2) base/base_stat_alerts.php or (3) base/base_stat_uaddr.php. NOTE: some of these details are obtained from third party information.

    Published: 5 May 2010
    7.5
    High

    CVE-2010-1583

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the loadByKey function in the TznDbConnection class in tzn_mysql.php in Tirzen (aka TZN) Framework 1.5, as used in TaskFreak! before 0.6.3, allows remote attackers to execute arbitrary SQL commands via the username field in a login action.

    Published: 5 May 2010
    7.6
    High

    CVE-2010-1681

    Last Modified: 11 Apr 2025

    Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.

    Published: 5 May 2010
    4.4
    Medium

    CVE-2010-1438

    Last Modified: 11 Apr 2025

    Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2010-1724

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Zikula Application Framework 1.2.2, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) func parameter to index.php, or the (2) lang parameter to index.php, which is not properly handled by ZLanguage.php.

    Published: 5 May 2010
    7.5
    High

    CVE-2010-1725

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 May 2010
    7.5
    High

    CVE-2010-1726

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 5 May 2010
    7.5
    High

    CVE-2010-1727

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.

    Published: 5 May 2010
    9.3
    Critical

    CVE-2010-1728

    Last Modified: 11 Apr 2025

    Opera before 10.53 on Windows and Mac OS X does not properly handle a series of document modifications that occur asynchronously, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop, leading to attempted use of uninitialized memory. NOTE: this might overlap CVE-2006-6955.

    Published: 5 May 2010
    5
    Medium

    CVE-2010-1730

    Last Modified: 11 Apr 2025

    Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2010-1731

    Last Modified: 11 Apr 2025

    Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

    Published: 5 May 2010
    9.3
    Critical

    CVE-2010-0995

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2010-1729

    Last Modified: 11 Apr 2025

    WebKit.dll in WebKit, as used in Safari.exe 4.531.9.1 in Apple Safari, allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop.

    Published: 5 May 2010
    4.3
    Medium

    CVE-2010-1455

    Last Modified: 11 Apr 2025

    The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed packet trace file.

    Published: 5 May 2010
    6.4
    Medium

    CVE-2010-1861

    Last Modified: 11 Apr 2025

    The sysvshm extension for PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to write to arbitrary memory addresses by using an object's __sleep function to interrupt an internal call to the shm_put_var function, which triggers access of a freed resource.

    Published: 5 May 2010
    6.5
    Medium

    CVE-2010-0402

    Last Modified: 11 Apr 2025

    OpenTTD before 1.0.1 does not properly validate index values of certain items, which allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted in-game command.

    Published: 4 May 2010
    4
    Medium

    CVE-2010-0406

    Last Modified: 11 Apr 2025

    OpenTTD before 1.0.1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and daemon crash) by performing incomplete downloads of the map.

    Published: 4 May 2010