CVE Feed

    Dashboard / CVE

    2.6
    Low

    CVE-2010-1157

    Last Modified: 11 Apr 2025

    Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.

    Published: 21 Apr 2010
    6.8
    Medium

    CVE-2010-1153

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in the autoloader in TYPO3 4.3.x before 4.3.3 allows remote attackers to execute arbitrary PHP code via a URL in an input field associated with the className variable.

    Published: 20 Apr 2010
    4.6
    Medium

    CVE-2008-7255

    Last Modified: 11 Apr 2025

    login_screen.tcl in aMSN (aka Alvaro's Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.

    Published: 20 Apr 2010
    6.8
    Medium

    CVE-2010-1458

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Create and Extract Zips TweakFS Zip Utility 1.0 for Flight Simulator X (FSX) allows remote attackers to execute arbitrary code via a long filename in a ZIP archive.

    Published: 20 Apr 2010
    4.3
    Medium

    CVE-2010-1489

    Last Modified: 11 Apr 2025

    The XSS Filter in Microsoft Internet Explorer 8 does not properly perform neutering for the SCRIPT tag, which allows remote attackers to conduct cross-site scripting (XSS) attacks against web sites that have no inherent XSS vulnerabilities, a different issue than CVE-2009-4074.

    Published: 20 Apr 2010
    6
    Medium

    CVE-2010-0996

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in e107 before 0.7.20 allows remote authenticated users to execute arbitrary code by uploading a .php.filetypesphp file. NOTE: the vendor disputes the significance of this issue, noting that "an odd set of preferences and a missing file" are required.

    Published: 20 Apr 2010
    3.5
    Low

    CVE-2010-0997

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in 107_plugins/content/content_manager.php in the Content Management plugin in e107 before 0.7.20, when the personal content manager is enabled, allows user-assisted remote authenticated users to inject arbitrary web script or HTML via the content_heading parameter.

    Published: 20 Apr 2010
    7.5
    High

    CVE-2010-1317

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the NTLM authentication functionality in RealNetworks Helix Server and Helix Mobile Server 11.x, 12.x, and 13.x allows remote attackers to have an unspecified impact via invalid base64-encoded data.

    Published: 20 Apr 2010
    2.1
    Low

    CVE-2010-1487

    Last Modified: 11 Apr 2025

    IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.

    Published: 20 Apr 2010
    2.1
    Low

    CVE-2010-1488

    Last Modified: 11 Apr 2025

    The proc_oom_score function in fs/proc/base.c in the Linux kernel before 2.6.34-rc4 uses inappropriate data structures during selection of a candidate for the OOM killer, which might allow local users to cause a denial of service via unspecified patterns of task creation.

    Published: 20 Apr 2010
    4.3
    Medium

    CVE-2010-1164

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Atlassian JIRA 3.12 through 4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) element or (2) defaultColor parameter to the Colour Picker page; the (3) formName parameter, (4) element parameter, or (5) full name field to the User Picker page; the (6) formName parameter, (7) element parameter, or (8) group name field to the Group Picker page; the (9) announcement_preview_banner_st parameter to unspecified components, related to the Announcement Banner Preview page; unspecified vectors involving the (10) groupnames.jsp, (11) indexbrowser.jsp, (12) classpath-debug.jsp, (13) viewdocument.jsp, or (14) cleancommentspam.jsp page; the (15) portletKey parameter to runportleterror.jsp; the (16) URI to issuelinksmall.jsp; the (17) afterURL parameter to screenshot-redirecter.jsp; or the (18) HTTP Referrer header to 500page.jsp, as exploited in the wild in April 2010.

    Published: 20 Apr 2010
    9
    Critical

    CVE-2010-1165

    Last Modified: 11 Apr 2025

    Atlassian JIRA 3.12 through 4.1 allows remote authenticated administrators to execute arbitrary code by modifying the (1) attachment (aka attachments), (2) index (aka indexing), or (3) backup path and then uploading a file, as exploited in the wild in April 2010.

    Published: 20 Apr 2010
    10
    Critical

    CVE-2010-1318

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Apr 2010
    10
    Critical

    CVE-2010-1319

    Last Modified: 11 Apr 2025

    Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted payload length.

    Published: 20 Apr 2010
    4.3
    Medium

    CVE-2009-4767

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) input_name and (2) input_text parameters. NOTE: some of these details are obtained from third party information.

    Published: 20 Apr 2010
    9.3
    Critical

    CVE-2009-4769

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute arbitrary code via format string specifiers in a PWD command to the FTP server component.

    Published: 20 Apr 2010
    9.3
    Critical

    CVE-2009-4768

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JASS script interpreter in Warcraft III: The Frozen Throne 1.24b and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted custom map. NOTE: some of these details are obtained from third party information.

    Published: 20 Apr 2010
    4.3
    Medium

    CVE-2009-4772

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal, when a custom checkout completion message is enabled, allows attackers to obtain sensitive information via unknown vectors.

    Published: 20 Apr 2010
    7.5
    High

    CVE-2009-4770

    Last Modified: 11 Apr 2025

    The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to obtain privileged access.

    Published: 20 Apr 2010
    5
    Medium

    CVE-2009-4771

    Last Modified: 11 Apr 2025

    The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal does not properly validate orders, which allows remote attackers to trigger unspecified "duplicate actions" via unknown vectors.

    Published: 20 Apr 2010
    6.8
    Medium

    CVE-2009-4773

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the order-management functionality in the Ubercart module 5.x before 5.x-1.9 and 6.x before 6.x-2.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 20 Apr 2010
    5
    Medium

    CVE-2010-1587

    Last Modified: 11 Apr 2025

    The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics.jsp.

    Published: 20 Apr 2010
    5
    Medium

    CVE-2013-5211

    Last Modified: 11 Apr 2025

    The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

    Published: 20 Apr 2010
    4
    Medium

    CVE-2010-1320

    Last Modified: 11 Apr 2025

    Double free vulnerability in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x before 1.8.2 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a request associated with (1) renewal or (2) validation.

    Published: 20 Apr 2010
    10
    Critical

    CVE-2010-2521

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in fs/nfsd/nfs4xdr.c in the XDR implementation in the NFS server in the Linux kernel before 2.6.34-rc6 allow remote attackers to cause a denial of service (panic) or possibly execute arbitrary code via a crafted NFSv4 compound WRITE request, related to the read_buf and nfsd4_decode_compound functions.

    Published: 20 Apr 2010
    7.5
    High

    CVE-2010-1468

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Multi-Venue Restaurant Menu Manager (aka MVRMM or com_mv_restaurantmenumanager) component 1.5.2 Stable Update 3 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the mid parameter in a menu_display action to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1469

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Ternaria Informatica JProject Manager (com_jprojectmanager) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1470

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Web TV (com_webtv) component 1.0 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1471

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1474

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1475

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1476

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the view parameter to index.php.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1477

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SermonSpeaker (com_sermonspeaker) component before 3.2.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a latest_sermons action to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1478

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Ternaria Informatica Jfeedback! (com_jfeedback) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1479

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the moduleid parameter in a raw action to index.php.

    Published: 19 Apr 2010
    6.8
    Medium

    CVE-2010-1473

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1480

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the module parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 19 Apr 2010
    7.5
    High

    CVE-2010-1472

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Daily Horoscope (com_horoscope) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 19 Apr 2010
    4.3
    Medium

    CVE-2010-1167

    Last Modified: 11 Apr 2025

    fetchmail 4.6.3 through 6.3.16, when debug mode is enabled, does not properly handle invalid characters in a multi-character locale, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted (1) message header or (2) POP3 UIDL list.

    Published: 18 Apr 2010
    6.8
    Medium

    CVE-2010-1466

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrary files via the dsn[phptype] parameter.

    Published: 16 Apr 2010
    5
    Medium

    CVE-2010-1461

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.

    Published: 16 Apr 2010
    4.3
    Medium

    CVE-2010-1464

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebAsyst Shop-Script FREE allow remote attackers to inject arbitrary web script or HTML via the (1) currency_id_left, (2) currency_id_right, (3) darkcolor, (4) lightcolor, (5) middlecolor, and (6) w parameters.

    Published: 16 Apr 2010
    6.8
    Medium

    CVE-2010-1155

    Last Modified: 11 Apr 2025

    Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate.

    Published: 16 Apr 2010
    4.3
    Medium

    CVE-2010-1156

    Last Modified: 11 Apr 2025

    core/nicklist.c in Irssi before 0.8.15 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to an attempted fuzzy nick match at the instant that a victim leaves a channel.

    Published: 16 Apr 2010
    7.5
    High

    CVE-2010-1463

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in WebAsyst Shop-Script FREE allow attackers to execute arbitrary SQL commands via the (1) add2cart, (2) c_id, (3) categoryID, (4) list_price, (5) name, (6) new_offer, (7) price, (8) product_code, (9) productID, (10) rating, and (11) save_product parameters.

    Published: 16 Apr 2010
    7.5
    High

    CVE-2010-1467

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) collectivite.class.php, (2) injection.class.php, (3) utilisateur.class.php, (4) droit.class.php, (5) laboratoire.class.php, (6) vaccin.class.php, (7) effetsecondaire.class.php, (8) medecin.class.php, (9) individu.class.php, and (10) profil.class.php in gen/obj/.

    Published: 16 Apr 2010
    9.3
    Critical

    CVE-2010-1465

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Trellian FTP client 3.01, including 3.1.3.1789, allows remote attackers to execute arbitrary code via a long PASV response.

    Published: 16 Apr 2010
    10
    Critical

    CVE-2010-1462

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in WebAsyst Shop-Script FREE has unknown impact and attack vectors via the sub parameter.

    Published: 16 Apr 2010
    5
    Medium

    CVE-2010-1460

    Last Modified: 11 Apr 2025

    The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.

    Published: 16 Apr 2010
    4.3
    Medium

    CVE-2010-2596

    Last Modified: 11 Apr 2025

    The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as used in tiff2ps, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF image, related to "downsampled OJPEG input."

    Published: 16 Apr 2010