CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-1559

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a speakerpopup action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2010
    6.8
    Medium

    CVE-2009-4817

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.

    Published: 27 Apr 2010
    5
    Medium

    CVE-2009-4821

    Last Modified: 11 Apr 2025

    The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors.

    Published: 27 Apr 2010
    4.9
    Medium

    CVE-2010-0105

    Last Modified: 11 Apr 2025

    The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.

    Published: 27 Apr 2010
    4
    Medium

    CVE-2010-0772

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the channel process in IBM WebSphere MQ 7.0 before 7.0.1.2 allows remote authenticated users to cause a denial of service (daemon crash) via "incorrect channel control data."

    Published: 27 Apr 2010
    5
    Medium

    CVE-2009-4816

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Published: 27 Apr 2010
    4.3
    Medium

    CVE-2009-4813

    Last Modified: 26 Sept 2025

    Cross-site scripting (XSS) vulnerability in myps.php in MyBB (aka MyBulletinBoard) 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the username parameter in a donate action.

    Published: 27 Apr 2010
    5
    Medium

    CVE-2009-4811

    Last Modified: 11 Apr 2025

    VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\x90 sequence in the USER and PASS commands, a related issue to CVE-2009-3707. NOTE: some of these details are obtained from third party information.

    Published: 27 Apr 2010
    4
    Medium

    CVE-2009-4815

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 27 Apr 2010
    4.3
    Medium

    CVE-2009-4823

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.

    Published: 27 Apr 2010
    7.5
    High

    CVE-2009-4824

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an "image upload form."

    Published: 27 Apr 2010
    4
    Medium

    CVE-2010-1560

    Last Modified: 11 Apr 2025

    Buffer overflow in the REPEAT function in IBM DB2 9.1 before FP9 allows remote authenticated users to cause a denial of service (trap) via unspecified vectors. NOTE: this might overlap CVE-2010-0462.

    Published: 27 Apr 2010
    7.1
    High

    CVE-2010-1166

    Last Modified: 11 Apr 2025

    The fbComposite function in fbpict.c in the Render extension in the X server in X.Org X11R7.1 allows remote authenticated users to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a crafted request, related to an incorrect macro definition.

    Published: 27 Apr 2010
    5
    Medium

    CVE-2010-3192

    Last Modified: 11 Apr 2025

    Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, related to the __fortify_fail function in debug/fortify_fail.c, and the __stack_chk_fail (aka stack protection) and __chk_fail (aka FORTIFY_SOURCE) implementations.

    Published: 27 Apr 2010
    7.5
    High

    CVE-2010-1538

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 26 Apr 2010
    2.1
    Low

    CVE-2010-1539

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Workflow module 5.x-2.x before 5.x-2.6 and 6.x-1.x before 6.x-1.4 for Drupal, when used with the Token module, might allow remote authenticated users to inject arbitrary web script or HTML via a certain Comment field.

    Published: 26 Apr 2010
    5
    Medium

    CVE-2010-1540

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in the MyBlog (com_myblog) component 3.0.329 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the task parameter. NOTE: some of these details are obtained from third party information.

    Published: 26 Apr 2010
    4.3
    Medium

    CVE-2010-1541

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in DFD Cart 1.198, 1.197, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) category and (2) list_quantity parameters to index.php, and the (3) category parameter to your.order.php.

    Published: 26 Apr 2010
    6.8
    Medium

    CVE-2010-1542

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in admin/configure.php in DFD Cart 1.198, 1.197, and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks or (2) change unspecified settings.

    Published: 26 Apr 2010
    2.1
    Low

    CVE-2010-1536

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the AddThis Button module 5.x before 5.x-2.2 and 6.x before 6.x-2.9 for Drupal allows remote authenticated users, with administer addthis privileges, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1537

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang_global parameter to (1) firstvisit.php, (2) newfolder.php, (3) showfolders.php, (4) newlang.php, (5) showinnerfolder.php, (6) writecode.php, and (7) showcode.php.

    Published: 26 Apr 2010
    5
    Medium

    CVE-2010-1544

    Last Modified: 11 Apr 2025

    micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.

    Published: 26 Apr 2010
    4.3
    Medium

    CVE-2010-1543

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the eTracker module before 6.x-1.2 for Drupal allows remote attackers to inject arbitrary web script or HTML by appending a crafted string to an arbitrary URL associated with the Drupal site.

    Published: 26 Apr 2010
    6.8
    Medium

    CVE-2010-1528

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in include/template.php in Uiga Proxy, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1529

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Freestyle FAQs Lite (com_fsf) component, possibly 1.3, for Joomla! allows remote attackers to execute arbitrary SQL commands via the faqid parameter in an faq action to index.php.

    Published: 26 Apr 2010
    2.1
    Low

    CVE-2010-1530

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Internationalization module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with translate interface or administer blocks privileges, to inject arbitrary web script or HTML via (1) strings used in block translation or (2) the untranslated input.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1531

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the redSHOP (com_redshop) component 1.0.x for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1533

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 26 Apr 2010
    5
    Medium

    CVE-2010-1534

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Shoutbox Pro (com_shoutbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 26 Apr 2010
    5
    Medium

    CVE-2010-1532

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the givesight PowerMail Pro (com_powermail) component 1.5.3 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1535

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the TRAVELbook (com_travelbook) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 26 Apr 2010
    5.3
    Medium

    CVE-2010-0738

    Last Modified: 22 Apr 2026

    The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

    Published: 26 Apr 2010
    5
    Medium

    CVE-2010-1429

    Last Modified: 11 Apr 2025

    Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2010-1428

    Last Modified: 22 Apr 2026

    The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

    Published: 26 Apr 2010
    4.3
    Medium

    CVE-2010-1330

    Last Modified: 11 Apr 2025

    The regular expression engine in JRuby before 1.4.1, when $KCODE is set to 'u', does not properly handle characters immediately after a UTF-8 character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string.

    Published: 26 Apr 2010
    7.5
    High

    CVE-2009-4802

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Flat Manager (flatmgr) extension before 1.9.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4803

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Apr 2010
    4.3
    Medium

    CVE-2009-4804

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via "search parameters."

    Published: 23 Apr 2010
    6.8
    Medium

    CVE-2009-4805

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the storyid parameter to public/view.php or (2) the kill parameter to admin/remove.php.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4806

    Last Modified: 11 Apr 2025

    admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator's credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4808

    Last Modified: 11 Apr 2025

    admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4810

    Last Modified: 11 Apr 2025

    The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input.

    Published: 23 Apr 2010
    5
    Medium

    CVE-2010-1494

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the AWDwall (com_awdwall) component 1.5.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1495

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Matamko (com_matamko) component 1.01 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1496

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cardID parameter in a view action to index.php.

    Published: 23 Apr 2010
    4.3
    Medium

    CVE-2010-1497

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1498

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in dl_stats before 2.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) download.php and (2) view_file.php.

    Published: 23 Apr 2010
    Unknown

    CVE-2010-1501

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1767. Reason: This candidate is a duplicate of CVE-2010-1767. Notes: All CVE users should reference CVE-2010-1767 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Apr 2010
    9.3
    Critical

    CVE-2010-1502

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to access local files via vectors related to "developer tools."

    Published: 23 Apr 2010
    4.3
    Medium

    CVE-2010-1503

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://net-internals URI.

    Published: 23 Apr 2010