CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-1504

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Google Chrome before 4.1.249.1059 allows remote attackers to inject arbitrary web script or HTML via vectors related to a chrome://downloads URI.

    Published: 23 Apr 2010
    10
    Critical

    CVE-2010-1505

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.

    Published: 23 Apr 2010
    7.8
    High

    CVE-2010-1506

    Last Modified: 11 Apr 2025

    The Google V8 bindings in Google Chrome before 4.1.249.1059 allow attackers to cause a denial of service (memory corruption) via unknown vectors.

    Published: 23 Apr 2010
    5
    Medium

    CVE-2009-4809

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter.

    Published: 23 Apr 2010
    4.6
    Medium

    CVE-2010-1034

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP System Management Homepage (SMH) 6.0 before 6.0.0-95 on Linux, and 6.0 before 6.0.0.96 on Windows, allows remote authenticated users to obtain sensitive information, modify data, and cause a denial of service via unknown vectors.

    Published: 23 Apr 2010
    9
    Critical

    CVE-2010-1035

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in HP Virtual Machine Manager (VMM) before 6.0 allow remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 23 Apr 2010
    5
    Medium

    CVE-2010-1492

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in help/frameRight.php in Elastix 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id_nodo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1500

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1059 does not properly support forms, which has unknown impact and attack vectors, related to a "type confusion error."

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4801

    Last Modified: 11 Apr 2025

    EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2009-4807

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php.

    Published: 23 Apr 2010
    5
    Medium

    CVE-2010-1491

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the MMS Blog (com_mmsblog) component 2.3.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1493

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the AWDwall (com_awdwall) component before 1.5.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cbuser parameter in an awdwall action to index.php.

    Published: 23 Apr 2010
    7.5
    High

    CVE-2010-1499

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 23 Apr 2010
    7
    High

    CVE-2010-1437

    Last Modified: 11 Apr 2025

    Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl session commands that trigger access to a dead keyring that is undergoing deletion by the key_cleanup function.

    Published: 23 Apr 2010
    9
    Critical

    CVE-2009-4790

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modify arbitrary files via crafted FTP commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4792

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4794

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to view.php and the (2) a parameter in an event action to calendar.php, reachable through index.php.

    Published: 22 Apr 2010
    6.8
    Medium

    CVE-2009-4795

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow remote attackers to execute arbitrary SQL commands via the (1) USER (aka username) or (2) PASS (aka password) command.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4796

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in glFusion 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) order and (2) direction parameters to search.php.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4797

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the pk parameter.

    Published: 22 Apr 2010
    5
    Medium

    CVE-2009-4799

    Last Modified: 11 Apr 2025

    Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb.

    Published: 22 Apr 2010
    4
    Medium

    CVE-2009-4800

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrary files via a ..// (dot dot slash slash) in a DELE command.

    Published: 22 Apr 2010
    4.3
    Medium

    CVE-2010-1486

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in _invoice.asp in CactuShop before 6.155 allow remote attackers to inject arbitrary web script or HTML via the (1) billing address or (2) shipping address.

    Published: 22 Apr 2010
    6
    Medium

    CVE-2009-4793

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authenticated administrators to execute arbitrary PHP code by uploading a file with an executable extension via an addphotos action to adminpanel/index.php, and then accessing the file via a direct request with an images/gallery/ directory name. NOTE: some of these details are obtained from third party information.

    Published: 22 Apr 2010
    6.8
    Medium

    CVE-2010-0991

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in imlib2 1.4.3 allow context-dependent attackers to execute arbitrary code via a crafted (1) ARGB, (2) XPM, or (3) BMP file, related to the IMAGE_DIMENSIONS_OK macro in lib/image.h.

    Published: 22 Apr 2010
    9.3
    Critical

    CVE-2010-1278

    Last Modified: 11 Apr 2025

    Buffer overflow in the Atlcom.get_atlcom ActiveX control in gp.ocx in Adobe Download Manager, as used in Adobe Reader and Acrobat 8.x before 8.2 and 9.x before 9.3, allows remote attackers to execute arbitrary code via unspecified parameters.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4791

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to addressbook.php, (2) id parameter to recipes.php, (3) year parameter to register.php, (4) poll_id parameter to home.php, and (5) email parameter to lostpw.php.

    Published: 22 Apr 2010
    7.5
    High

    CVE-2009-4798

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.

    Published: 22 Apr 2010
    9
    Critical

    CVE-2010-0593

    Last Modified: 11 Apr 2025

    The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Internet Video Camera before 1.1.1.15, WVC210 Wireless-G PTZ Internet Video Camera before 1.1.1.15, and WVC2300 Wireless-G Business Internet Video Camera before 1.1.2.6 do not properly restrict read access to passwords, which allows context-dependent attackers to obtain sensitive information, related to (1) access by remote authenticated users to a PVC2300 or WVC2300 via a crafted URL, (2) leveraging setup privileges on a WVC200 or WVC210, and (3) leveraging administrative privileges on an RVS4000, aka Bug ID CSCte64726.

    Published: 22 Apr 2010
    4
    Medium

    CVE-2009-4774

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Sun Solaris 10 and OpenSolaris snv_49 through snv_117, when 64bit mode is used on the Intel x86 platform and a Linux (lx) branded zone is configured, allows local users to cause a denial of service (panic) via unspecified vectors, a different vulnerability than CVE-2007-6225.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2009-4779

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter to (1) blocks.php, (2) messages.php, and (3) stories.php in admin/modules/.

    Published: 21 Apr 2010
    7.2
    High

    CVE-2009-4781

    Last Modified: 11 Apr 2025

    TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover credentials via a DBI connection.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4782

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbitrary web script or HTML via the (1) start, (2) forum, and (3) cat parameters to community/thread.php; (4) start and (5) cat parameters to community/forum.php; and (6) start parameter to blog/index.php.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2009-4784

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2009-4785

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a view_item action to index.php.

    Published: 21 Apr 2010
    6.8
    Medium

    CVE-2009-4787

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Pligg before 1.0.3 allow remote attackers to hijack the authentication of administrators for requests that create user accounts or have unspecified other impact.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4788

    Last Modified: 11 Apr 2025

    Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2009-4789

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in the MojoBlog component RC 0.15 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) wp-comments-post.php and (2) wp-trackback.php.

    Published: 21 Apr 2010
    4.9
    Medium

    CVE-2010-1032

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP HP-UX B.11.11 allows local users to cause a denial of service via unknown vectors.

    Published: 21 Apr 2010
    10
    Critical

    CVE-2010-1490

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Cognos 8 Business Intelligence before 8.4.1 FP1 has unknown impact and attack vectors.

    Published: 21 Apr 2010
    9.3
    Critical

    CVE-2009-4776

    Last Modified: 11 Apr 2025

    Buffer overflow in Hitachi Cosminexus V4 through V8, Processing Kit for XML, and Developer's Kit for Java, as used in products such as uCosminexus, Electronic Form Workflow, Groupmax, and IBM XL C/C++ Enterprise Edition 7 and 8, allows remote attackers to have an unknown impact via vectors related to the use of GIF image processing APIs by a Java application, and a different issue from CVE-2007-3794.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4777

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in multiple versions of Hitachi JP1/Automatic Job Management System 2 - View, JP1/Integrated Management - View, and JP1/Cm2/SNMP System Observer, allows remote attackers to cause a denial of service ("abnormal" termination) via vectors related to the display of an "invalid GIF file."

    Published: 21 Apr 2010
    9.3
    Critical

    CVE-2009-4778

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 4.1.7 and 5.0.0, and BlackBerry Professional Software 4.1.4, allow user-assisted remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .pdf file attachment, a different vulnerability than CVE-2008-3246, CVE-2009-0176, CVE-2009-0219, CVE-2009-2643, and CVE-2009-2646.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4780

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in phpMyFAQ before 2.5.5 allow remote attackers to inject arbitrary web script or HTML via (1) the lang parameter in a sitemap action, (2) the search parameter in a search action, (3) the tagging_id parameter in a search action, (4) the highlight parameter in an artikel action, (5) the artlang parameter in an artikel action, (6) the letter parameter in a sitemap action, (7) the lang parameter in a show action, (8) the cat parameter in a show action, (9) the newslang parameter in a news action, (10) the artlang parameter in a send2friend action, (11) the cat parameter in a send2friend action, (12) the id parameter in a send2friend action, (13) the srclang parameter in a translate action, (14) the id parameter in a translate action, (15) the cat parameter in a translate action, (16) the cat parameter in an add action, or (17) the question parameter in an add action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4786

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/admin_config.php, (2) admin/admin_modules.php, (3) delete.php, (4) editlink.php, (5) submit.php, (6) submit_groups.php, (7) user_add_remove_links.php, and (8) user_settings.php.

    Published: 21 Apr 2010
    9.3
    Critical

    CVE-2010-1033

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in a certain Tetradyne ActiveX control in HP Operations Manager 7.5, 8.10, and 8.16 might allow remote attackers to execute arbitrary code via a long string argument to the (1) LoadFile or (2) SaveFile method, related to srcvw32.dll and srcvw4.dll.

    Published: 21 Apr 2010
    4.3
    Medium

    CVE-2009-4775

    Last Modified: 11 Apr 2025

    Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2009-4783

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php.

    Published: 21 Apr 2010
    7.5
    High

    CVE-2010-1431

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbitrary SQL commands via the export_item_id parameter.

    Published: 21 Apr 2010
    7.1
    High

    CVE-2013-5745

    Last Modified: 11 Apr 2025

    The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.

    Published: 21 Apr 2010