CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2009-4509

    Last Modified: 11 Apr 2025

    The administrative web console on the TANDBERG Video Communication Server (VCS) before X4.3 uses predictable session cookies in (1) tandberg/web/lib/secure.php and (2) tandberg/web/user/lib/secure.php, which makes it easier for remote attackers to bypass authentication, and execute arbitrary code by loading a custom software update, via a crafted "Cookie: tandberg_login=" HTTP header.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-1355

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Reference ID 66316.

    Published: 13 Apr 2010
    10
    Critical

    CVE-2010-1356

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the TANDBERG Video Communication Server (VCS) before X5.0 allows remote attackers to execute arbitrary code via unknown vectors, aka Reference ID 69773.

    Published: 13 Apr 2010
    4.3
    Medium

    CVE-2010-0190

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0194

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-2010-0201, and CVE-2010-0204.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0195

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, do not properly handle fonts, which allows attackers to execute arbitrary code via unspecified vectors.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0196

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0193.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0197

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0201, and CVE-2010-0204.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0198

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0199, CVE-2010-0202, and CVE-2010-0203.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0201

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0204.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0202

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0203.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0203

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202.

    Published: 13 Apr 2010
    6.9
    Medium

    CVE-2010-0436

    Last Modified: 11 Apr 2025

    Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0193

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0192 and CVE-2010-0196.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0199

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0202, and CVE-2010-0203.

    Published: 13 Apr 2010
    6.9
    Medium

    CVE-2010-1163

    Last Modified: 11 Apr 2025

    The command matching functionality in sudo 1.6.8 through 1.7.2p5 does not properly handle when a file in the current working directory has the same name as a pseudo-command in the sudoers file and the PATH contains an entry for ".", which allows local users to execute arbitrary commands via a Trojan horse executable, as demonstrated using sudoedit, a different vulnerability than CVE-2010-0426.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0191

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0192

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-2010-0193 and CVE-2010-0196.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2010-0204

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0194, CVE-2010-0197, and CVE-2010-0201.

    Published: 13 Apr 2010
    9.3
    Critical

    CVE-2009-1565

    Last Modified: 11 Apr 2025

    vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted HexTile-encoded video chunks that trigger heap-based buffer overflows, related to "integer truncation errors."

    Published: 12 Apr 2010
    10
    Critical

    CVE-2009-3732

    Last Modified: 11 Apr 2025

    Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 12 Apr 2010
    5
    Medium

    CVE-2010-1138

    Last Modified: 11 Apr 2025

    The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware Server 2.x, and VMware Fusion 3.0 before 3.0.1 build 232708 and 2.x before 2.0.7 build 246742 allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets, related to interaction between the guest OS and the host vmware-vmx process.

    Published: 12 Apr 2010
    7.2
    High

    CVE-2010-1139

    Last Modified: 11 Apr 2025

    Format string vulnerability in vmrun in VMware VIX API 1.6.x, VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Linux, and VMware Fusion 2.x before 2.0.7 build 246742, allows local users to gain privileges via format string specifiers in process metadata.

    Published: 12 Apr 2010
    6.9
    Medium

    CVE-2010-1140

    Last Modified: 11 Apr 2025

    The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS users to gain privileges by placing a Trojan horse program at an unspecified location on the host OS disk.

    Published: 12 Apr 2010
    8.5
    High

    CVE-2010-1141

    Last Modified: 11 Apr 2025

    VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly access libraries, which allows user-assisted remote attackers to execute arbitrary code by tricking a Windows guest OS user into clicking on a file that is stored on a network share.

    Published: 12 Apr 2010
    8.5
    High

    CVE-2010-1142

    Last Modified: 11 Apr 2025

    VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 build 246459; VMware Server 2.x before 2.0.2 build 203138; VMware Fusion 2.x before 2.0.6 build 246742; VMware ESXi 3.5 and 4.0; and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0 does not properly load VMware programs, which might allow Windows guest OS users to gain privileges by placing a Trojan horse program at an unspecified location on the guest OS disk.

    Published: 12 Apr 2010
    6.9
    Medium

    CVE-2010-1146

    Last Modified: 11 Apr 2025

    The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, which allows local users to gain privileges by modifying (1) extended attributes or (2) ACLs, as demonstrated by deleting a file under .reiserfs_priv/xattrs/.

    Published: 12 Apr 2010
    10
    Critical

    CVE-2010-1349

    Last Modified: 11 Apr 2025

    Integer overflow in Opera 10.10 through 10.50 allows remote attackers to execute arbitrary code via a large Content-Length value, which triggers a heap overflow.

    Published: 12 Apr 2010
    7.5
    High

    CVE-2010-1350

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JP Jobs (com_jp_jobs) component 1.4.1 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 12 Apr 2010
    6.8
    Medium

    CVE-2010-1351

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Nodesforum 1.033 and 1.045, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) _nodesforum_path_from_here_to_nodesforum_folder parameter to erase_user_data.php and the (2) _nodesforum_code_path parameter to pre_output.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Apr 2010
    5
    Medium

    CVE-2010-1352

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Apr 2010
    5
    Medium

    CVE-2010-1353

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php.

    Published: 12 Apr 2010
    5
    Medium

    CVE-2010-1354

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Apr 2010
    9.3
    Critical

    CVE-2009-1564

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in vmnc.dll in the VMnc media codec in VMware Movie Decoder before 6.5.4 Build 246459 on Windows, and the movie decoder in VMware Workstation 6.5.x before 6.5.4 build 246459, VMware Player 2.5.x before 2.5.4 build 246459, and VMware Server 2.x on Windows, allows remote attackers to execute arbitrary code via an AVI file with crafted video chunks that use HexTile encoding.

    Published: 12 Apr 2010
    7.2
    High

    CVE-2010-1347

    Last Modified: 11 Apr 2025

    Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.

    Published: 12 Apr 2010
    7.5
    High

    CVE-2010-1348

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the login process in IBM WebSphere Portal 6.0.1.1, and 6.1.0.x before 6.1.0.3 Cumulative Fix 03, has unknown impact and remote attack vectors.

    Published: 12 Apr 2010
    6.8
    Medium

    CVE-2010-0739

    Last Modified: 11 Apr 2025

    Integer overflow in the predospecial function in dospecial.c in dvips in (1) TeX Live and (2) teTeX might allow user-assisted remote attackers to execute arbitrary code via a crafted DVI file that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

    Published: 12 Apr 2010
    6.8
    Medium

    CVE-2010-1335

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php, (2) city.get/index.php, (3) message2.send/message.send.php, (4) message.send/message.send.php, and (5) pages.add/pages.add.php in insky/modules/. NOTE: some of these details are obtained from third party information.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1336

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) newlanguage parameters to site.php, (3) search parameter to manuals.php, and (4) unspecified vectors to faq.php. NOTE: some of these details are obtained from third party information.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1337

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in definitions.php in Lussumo Vanilla 1.1.10, and possibly 0.9.2 and other versions, allow remote attackers to execute arbitrary PHP code via a URL in the (1) include and (2) Configuration['LANGUAGE'] parameters.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1338

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to execute arbitrary SQL commands via the userid parameter in a modboard action.

    Published: 9 Apr 2010
    4.3
    Medium

    CVE-2010-1339

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ts_other.php in the Teamsite Hack plugin 3.0 and earlier for WoltLab Burning Board allows remote attackers to inject arbitrary web script or HTML via the userid parameter in a modboard action, which is not properly handled in a forced SQL error message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 9 Apr 2010
    5
    Medium

    CVE-2010-1340

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1341

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Systemsoftware Community Black Forum allows remote attackers to execute arbitrary SQL commands via the s_flaeche parameter.

    Published: 9 Apr 2010
    6.8
    Medium

    CVE-2010-1342

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter to (1) admin/menu.php and (2) library/lib.menu.php; and the adminroot parameter to (3) admin/media/update_content.php and (4) library/class.backup.php. NOTE: some of these details are obtained from third party information.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1343

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands via the albumid parameter.

    Published: 9 Apr 2010
    7.5
    High

    CVE-2010-1344

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the fid parameter in a detail action to index.php.

    Published: 9 Apr 2010
    5
    Medium

    CVE-2010-1345

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 9 Apr 2010
    6.8
    Medium

    CVE-2010-1346

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admin/login.php in Mini CMS RibaFS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Apr 2010
    6.8
    Medium

    CVE-2010-0992

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Pulse CMS Basic 1.2.2 and 1.2.3, and possibly Pulse Pro before 1.3.2, allow remote attackers to hijack the authentication of users for requests that (1) upload image files, (2) delete image files, or (3) create blocks.

    Published: 9 Apr 2010