CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2010-1686

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in (1) Urgent Backup 3.20, and (2) ABC Backup Pro 5.20 and ABC Backup 5.50, allows user-assisted remote attackers to execute arbitrary code via a crafted ZIP archive.

    Published: 4 May 2010
    9.3
    Critical

    CVE-2010-1279

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1 allow user-assisted remote attackers to execute arbitrary code via a crafted TIFF file.

    Published: 4 May 2010
    6.5
    Medium

    CVE-2010-0401

    Last Modified: 11 Apr 2025

    OpenTTD before 1.0.1 accepts a company password for authentication in response to a request for the server password, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (daemon crash) by sending a company password packet.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2009-4834

    Last Modified: 11 Apr 2025

    lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibly related to now_connect.php.

    Published: 4 May 2010
    5
    Medium

    CVE-2010-1687

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in lpd.exe in Mocha W32 LPD 1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted "recieve jobs" request. NOTE: some of these details are obtained from third party information.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1701

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.html in PHP Video Battle Script allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1702

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in submitticket.php in WHMCompleteSolution (WHMCS) 4.2 allows remote attackers to execute arbitrary SQL commands via the deptid parameter.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1705

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in casting_view.php in Modelbook allows remote attackers to execute arbitrary SQL commands via the adnum parameter.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1706

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php. NOTE: some of these details are obtained from third party information.

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-1707

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1708

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter).

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-1709

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in upload.cgi in G5-Scripts Auto-Img-Gallery 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pass parameters.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1710

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in login.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the idioma parameter.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1716

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Agenda Address Book (com_agenda) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1723

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-0594

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Router and Security Device Manager (SDM) allows remote attackers to inject arbitrary web script or HTML via unknown vectors, aka Bug ID CSCtb38467.

    Published: 4 May 2010
    9.3
    Critical

    CVE-2010-1685

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in CursorArts ZipWrangler 1.20 allows user-assisted remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename.

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-1703

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1713

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action.

    Published: 4 May 2010
    5
    Medium

    CVE-2010-1714

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1720

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the katid parameter in a qpListele action to index.php.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1721

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1722

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    7.8
    High

    CVE-2010-0101

    Last Modified: 11 Apr 2025

    The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1704

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to execute arbitrary SQL commands via (1) the password field to login.php, (2) the login field (aka email parameter) to login.php, (3) the password field (aka pass parameter) to the default URI under admin/, and possibly (4) the login field to the default URI under admin/. NOTE: some of these details are obtained from third party information.

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-1711

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in carga_foto_al.php in Siestta 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the usuario parameter.

    Published: 4 May 2010
    4.3
    Medium

    CVE-2010-1712

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in base/Comments.php in Webmobo WB News 2.3.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name and possibly (2) message parameters. NOTE: some of these details are obtained from third party information.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1715

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 4 May 2010
    7.5
    High

    CVE-2010-1717

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1718

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in archeryscores.php in the Archery Scores (com_archeryscores) component 1.0.6 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    6.8
    Medium

    CVE-2010-1719

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 4 May 2010
    5
    Medium

    CVE-2010-1862

    Last Modified: 11 Apr 2025

    The chunk_split function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.

    Published: 4 May 2010
    5
    Medium

    CVE-2010-1864

    Last Modified: 11 Apr 2025

    The addcslashes function in PHP 5.2 through 5.2.13 and 5.3 through 5.3.2 allows context-dependent attackers to obtain sensitive information (memory contents) by causing a userspace interruption of an internal function, related to the call time pass by reference feature.

    Published: 3 May 2010
    6.8
    Medium

    CVE-2010-1440

    Last Modified: 11 Apr 2025

    Multiple integer overflows in dvipsk/dospecial.c in dvips in TeX Live 2009 and earlier, and teTeX, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a special command in a DVI file, related to the (1) predospecial and (2) bbdospecial functions, a different vulnerability than CVE-2010-0739.

    Published: 3 May 2010
    9.8
    Critical

    CVE-2010-1866

    Last Modified: 11 Apr 2025

    The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.

    Published: 2 May 2010
    1.9
    Low

    CVE-2010-1650

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.0.x before 6.0.2.41, 6.1.x before 6.1.0.31, and 7.0.x before 7.0.0.11, when the -trace option (aka debugging mode) is enabled, executes debugging statements that print string representations of unspecified objects, which allows attackers to obtain sensitive information by reading the trace output.

    Published: 30 Apr 2010
    1.9
    Low

    CVE-2010-1651

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.31 and 7.0.x before 7.0.0.11, when Basic authentication and SIP tracing (aka full trace logging for SIP) are enabled, logs the entirety of all inbound and outbound SIP messages, which allows local users to obtain sensitive information by reading the trace log.

    Published: 30 Apr 2010
    5
    Medium

    CVE-2010-1652

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the HelpCenter module in Help Center Live (HCL) 2.0.6 and 2.1.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the file parameter to module.php. NOTE: some of these details are obtained from third party information.

    Published: 30 Apr 2010
    4.3
    Medium

    CVE-2010-1655

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in User/User_ChkLogin.asp in PowerEasy 2006 and PowerEasy SiteWeaver 6.8 allows remote attackers to inject arbitrary web script or HTML via the ComeUrl parameter.

    Published: 30 Apr 2010
    7.5
    High

    CVE-2010-1656

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Airiny ABC (com_abc) component 1.1.7 for Joomla! allows remote attackers to execute arbitrary SQL commands via the sectionid parameter in an abc action to index.php.

    Published: 30 Apr 2010
    5
    Medium

    CVE-2010-1657

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 30 Apr 2010
    5
    Medium

    CVE-2010-1658

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 30 Apr 2010
    7.5
    High

    CVE-2010-1660

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in help-details.php in CLScript Classifieds Script allows remote attackers to execute arbitrary SQL commands via the hpId parameter.

    Published: 30 Apr 2010
    4.3
    Medium

    CVE-2010-1662

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in acpmoderate.php in PHP-Quick-Arcade (PHPQA) 3.0.21 allows remote attackers to inject arbitrary web script or HTML via the serv parameter.

    Published: 30 Apr 2010
    10
    Critical

    CVE-2010-1663

    Last Modified: 11 Apr 2025

    The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 30 Apr 2010
    5
    Medium

    CVE-2010-1664

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1064 does not properly handle HTML5 media, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.

    Published: 30 Apr 2010
    7.5
    High

    CVE-2010-1665

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1064 does not properly handle fonts, which allows remote attackers to cause a denial of service (memory corruption) and possibly have unspecified other impact via unknown vectors.

    Published: 30 Apr 2010
    7.5
    High

    CVE-2010-1654

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information.

    Published: 30 Apr 2010
    5
    Medium

    CVE-2010-1659

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 30 Apr 2010
    7.5
    High

    CVE-2010-1661

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQL commands via the (1) phpqa_user_c parameter to Arcade.php and the (2) id parameter to acpmoderate.php.

    Published: 30 Apr 2010