CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-0863

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Retail - Oracle Retail Plan In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0864

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Retail - Oracle Retail Place In-Season component in Oracle Industry Product Suite 12.2 allows remote attackers to affect integrity via unknown vectors related to Online Help.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0865

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 13 Apr 2010
    6.5
    Medium

    CVE-2010-0866

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaVM component in Oracle Database 11.1.0.7 and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 13 Apr 2010
    4
    Medium

    CVE-2010-0867

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaVM component in Oracle Database 10.2.0.4, 11.1.0.7, and 11.2.0.1.0 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 13 Apr 2010
    5.8
    Medium

    CVE-2010-0868

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0869

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Transportation Management component in Oracle E-Business Suite 5.5.05.07, 5.5.06.00, and 6.0.03 allows remote attackers to affect confidentiality via unknown vectors.

    Published: 13 Apr 2010
    3.6
    Low

    CVE-2010-0870

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Change Data Capture component in Oracle Database 9.2.0.8 and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity, related to SYS.DBMS_CDC_PUBLISH.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0871

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Apr 2010
    5
    Medium

    CVE-2010-0872

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Internet Directory component in Oracle Fusion Middleware 10.1.2.3 and 10.1.4.3 allows remote attackers to affect availability via unknown vectors.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0874

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Communications - Oracle Communications Unified Inventory Management component in Oracle Industry Product Suite 7.1 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0875

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Life Sciences - Oracle Thesaurus Management System component in Oracle Industry Product Suite 4.5.2, 4.6, and 4.6.1 allows remote attackers to affect integrity, related to TMS Browser.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0876

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Life Sciences - Oracle Clinical Remote Data Capture Option component in Oracle Industry Product Suite 4.5.3 and 4.6 allows remote attackers to affect integrity, related to RDC Onsite.

    Published: 13 Apr 2010
    5
    Medium

    CVE-2010-0877

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect integrity via unknown vectors.

    Published: 13 Apr 2010
    4
    Medium

    CVE-2010-0878

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect integrity via unknown vectors.

    Published: 13 Apr 2010
    4
    Medium

    CVE-2010-0879

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote authenticated users to affect confidentiality via unknown vectors.

    Published: 13 Apr 2010
    4
    Medium

    CVE-2010-0880

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.49.26 and 8.50.07 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 13 Apr 2010
    7.2
    High

    CVE-2010-0882

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_134 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Trusted Extensions.

    Published: 13 Apr 2010
    2.1
    Low

    CVE-2010-0883

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite, a different vulnerability than CVE-2010-0884.

    Published: 13 Apr 2010
    2.1
    Low

    CVE-2010-0884

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Cluster component in Oracle Sun Product Suite 3.1 and 3.2 allows local users to affect confidentiality via unknown vectors related to Data Service for Oracle E-Business Suite, a different vulnerability than CVE-2010-0883.

    Published: 13 Apr 2010
    6.8
    Medium

    CVE-2010-0885

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Java System Communications Express component in Oracle Sun Product Suite 6 2005Q4 (6.2) and and 6.3 allows remote authenticated users to affect confidentiality via unknown vectors related to Address Book.

    Published: 13 Apr 2010
    10
    Critical

    CVE-2010-0888

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Ray Server Software component in Oracle Sun Product Suite 4.0, 4.1, and 4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Device Services.

    Published: 13 Apr 2010
    4.9
    Medium

    CVE-2010-0889

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_68 through snv_128 allows local users to affect confidentiality via unknown vectors related to the Kernel.

    Published: 13 Apr 2010
    2.1
    Low

    CVE-2010-0890

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite 10 and OpenSolaris snv_01 through snv_98 allows local users to affect availability via unknown vectors related to the Kernel.

    Published: 13 Apr 2010
    5.8
    Medium

    CVE-2010-0891

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Management Center component in Oracle Sun Product Suite 3.6.1 and 4.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Solaris Container Manager.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0893

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Mail.

    Published: 13 Apr 2010
    5.8
    Medium

    CVE-2010-0894

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Java System Access Manager component in Oracle Sun Product Suite 7.1, 7 2005Q4, and OpenSSO Enterprise 8.0 allows remote attackers to affect confidentiality and integrity via unknown vectors.

    Published: 13 Apr 2010
    3.6
    Low

    CVE-2010-0895

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Solaris component in Oracle Sun Product Suite OpenSolaris snv_119 allows local users to affect integrity and availability via unknown vectors related to IP Filter.

    Published: 13 Apr 2010
    7.1
    High

    CVE-2010-0896

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Convergence component in Oracle Sun Product Suite 1.0 allows remote attackers to affect confidentiality via unknown vectors related to Address Book and Mail Filter.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-0897

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Sun Java System Directory Server component in Oracle Sun Product Suite 5.2, 6.0, 6.1, 6.2, 6.3, and 6.3.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Directory Service Markup Language.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1364

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1365

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Uiga Fan Club, as downloaded on 20100310, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1366

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in admin/admin_login.php in Uiga Fan Club 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin_name and (2) admin_password parameters.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-1367

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/admin_login.php in Uiga Fan Club, as downloaded on 20100310, allow remote attackers to inject arbitrary web script or HTML via the (1) admin_name and (2) admin_password parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1368

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in GameScript (GS) 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a category action.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1369

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1370

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-1371

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1372

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the HD FLV Player (com_hdflvplayer) component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 13 Apr 2010
    5
    Medium

    CVE-2009-4765

    Last Modified: 11 Apr 2025

    CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/hikaye.mdb.

    Published: 13 Apr 2010
    5
    Medium

    CVE-2009-4766

    Last Modified: 11 Apr 2025

    YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for galeri/database/db.mdb.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-1357

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in editors/logindialogue.php in SBD Directory Software 4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 13 Apr 2010
    2.1
    Low

    CVE-2010-1358

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Bibliography (Biblio) module 5.x through 5.x-1.17 and 6.x through 6.x-1.9 for Drupal allows remote authenticated users, with "administer biblio" privileges, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Apr 2010
    6.8
    Medium

    CVE-2010-1359

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in bluegate_seo.inc.php in the Direct URL module for xt:Commerce, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the coID parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1360

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in FAQEngine 4.24.00 allow remote attackers to execute arbitrary PHP code via a URL in the path_faqe parameter to (1) attachs.php, (2) backup.php, (3) badwords.php, (4) categories.php, (5) changepw.php, (6) colorchooser.php, (7) colorwheel.php, (8) dbfiles.php, (9) diraccess.php, (10) faq.php, (11) index.php, (12) kb.php, and (13) stats.php.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-1361

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in shop/USER_ARTIKEL_HANDLING_AUFRUF.php in PHPepperShop 2.5 allows remote attackers to inject arbitrary web script or HTML via the darstellen parameter.

    Published: 13 Apr 2010
    2.1
    Low

    CVE-2010-1362

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Own Term module 6.x-1.0 for Drupal allows remote authenticated users, with "create additional terms" privileges, to inject arbitrary web script or HTML via the term description field in a term listing page.

    Published: 13 Apr 2010
    7.5
    High

    CVE-2010-1363

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JProjects (com_j-projects) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the project parameter in a projects action to index.php.

    Published: 13 Apr 2010
    8.5
    High

    CVE-2009-4510

    Last Modified: 11 Apr 2025

    The SSH service on the TANDBERG Video Communication Server (VCS) before X5.1 uses a fixed DSA key, which makes it easier for remote attackers to conduct man-in-the-middle attacks and spoof arbitrary servers via crafted SSH packets.

    Published: 13 Apr 2010
    4
    Medium

    CVE-2009-4511

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the web administration interface on the TANDBERG Video Communication Server (VCS) before X5.1 allow remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to (1) helppage.php or (2) user/helppage.php.

    Published: 13 Apr 2010