CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2010-1149

    Last Modified: 11 Apr 2025

    probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discover encryption keys by (1) running a certain udevadm command or (2) reading a certain file under /dev/.udev/db/.

    Published: 6 Apr 2010
    5
    Medium

    CVE-2010-1158

    Last Modified: 11 Apr 2025

    Integer overflow in the regular expression engine in Perl 5.8.x allows context-dependent attackers to cause a denial of service (stack consumption and application crash) by matching a crafted regular expression against a long string.

    Published: 6 Apr 2010
    9.3
    Critical

    CVE-2010-0173

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 5 Apr 2010
    4.3
    Medium

    CVE-2010-0181

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail application in situations where an IMG element has a SRC attribute that is a redirect to a mailto: URL, which allows remote attackers to cause a denial of service (excessive application launches) via an HTML document with many images.

    Published: 5 Apr 2010
    6.8
    Medium

    CVE-2009-2822

    Last Modified: 11 Apr 2025

    AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote attackers to bypass intended access restrictions via an 802.11 authentication frame.

    Published: 5 Apr 2010
    6.5
    Medium

    CVE-2010-0625

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in NWFTPD.nlm before 5.10.01 in the FTP server in Novell NetWare 5.1 through 6.5 SP8 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long (1) MKD, (2) RMD, (3) RNFR, or (4) DELE command.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2009-2936

    Last Modified: 11 Apr 2025

    The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy server in Varnish before 2.1.0 does not require authentication for commands received through a TCP port, which allows remote attackers to (1) execute arbitrary code via a vcl.inline directive that provides a VCL configuration file containing inline C code; (2) change the ownership of the master process via param.set, stop, and start directives; (3) read the initial line of an arbitrary file via a vcl.load directive; or (4) conduct cross-site request forgery (CSRF) attacks that leverage a victim's location on a trusted network and improper input validation of directives. NOTE: the vendor disputes this report, saying that it is "fundamentally misguided and pointless.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2005-4888

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.06.04 in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (excessive stale connections) by establishing many FTP sessions, which persist in the Not-Logged-In state after each session is completed.

    Published: 5 Apr 2010
    4
    Medium

    CVE-2007-6734

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home server via unspecified vectors.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2007-6735

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session.

    Published: 5 Apr 2010
    9.3
    Critical

    CVE-2009-4764

    Last Modified: 11 Apr 2025

    Adobe Reader 8.x and 9.x on Windows is able to execute EXE files that are embedded in a PDF document, which makes it easier for remote attackers to trick users into executing arbitrary code via a crafted document.

    Published: 5 Apr 2010
    3.5
    Low

    CVE-2000-1246

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allows remote authenticated users to cause a denial of service (abend) by sending an RNTO command after a failed RNFR command.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2002-2432

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via a crafted username.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2003-1596

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2010-1238

    Last Modified: 11 Apr 2025

    MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have empty values.

    Published: 5 Apr 2010
    9.3
    Critical

    CVE-2010-1239

    Last Modified: 11 Apr 2025

    Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, a related issue to CVE-2009-0836.

    Published: 5 Apr 2010
    9.3
    Critical

    CVE-2010-1240

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.

    Published: 5 Apr 2010
    4.3
    Medium

    CVE-2010-1242

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the IBM Web Interface for Content Management (aka WEBi) before 1.0.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2010-1243

    Last Modified: 11 Apr 2025

    The IBM Web Interface for Content Management (aka WEBi) before 1.0.4 creates persistent cookies on client workstations, which has unspecified impact and attack vectors.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2000-1245

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2001-1587

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.01w in the FTP server in Novell NetWare allows remote attackers to cause a denial of service (abend) via an anonymous STOU command.

    Published: 5 Apr 2010
    4.3
    Medium

    CVE-2004-2767

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session.

    Published: 5 Apr 2010
    4
    Medium

    CVE-2002-2433

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.03b in the FTP server in Novell NetWare allows remote authenticated users to cause a denial of service (abend) via a crafted ABOR command.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2002-2434

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.02i in the FTP server in Novell NetWare does not properly listen for data connections, which allows remote attackers to cause a denial of service (abend) via multiple FTP sessions.

    Published: 5 Apr 2010
    4.3
    Medium

    CVE-2003-1591

    Last Modified: 11 Apr 2025

    NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allows user-assisted remote attackers to cause a denial of service (console hang) via a large number of FTP sessions, which are not properly handled during an NLM unload.

    Published: 5 Apr 2010
    5
    Medium

    CVE-2003-1592

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 allow remote attackers to cause a denial of service (abend) via a long (1) username or (2) password.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2003-1593

    Last Modified: 11 Apr 2025

    NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2003-1594

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session.

    Published: 5 Apr 2010
    10
    Critical

    CVE-2003-1595

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors.

    Published: 5 Apr 2010
    7.5
    High

    CVE-2005-4887

    Last Modified: 11 Apr 2025

    NWFTPD.nlm before 5.06.05 in the FTP server in Novell NetWare 6.5 SP5 allows attackers to have an unspecified impact via vectors related to passwords.

    Published: 5 Apr 2010
    7.2
    High

    CVE-2010-1162

    Last Modified: 11 Apr 2025

    The release_one_tty function in drivers/char/tty_io.c in the Linux kernel before 2.6.34-rc4 omits certain required calls to the put_pid function, which has unspecified impact and local attack vectors.

    Published: 3 Apr 2010
    4.7
    Medium

    CVE-2010-1148

    Last Modified: 11 Apr 2025

    The cifs_create function in fs/cifs/dir.c in the Linux kernel 2.6.33.2 and earlier allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a NULL nameidata (aka nd) field in a POSIX file-creation request to a server that supports UNIX extensions.

    Published: 2 Apr 2010
    1.9
    Low

    CVE-2010-1160

    Last Modified: 11 Apr 2025

    GNU nano before 2.2.4 does not verify whether a file has been changed before it is overwritten in a file-save operation, which allows local user-assisted attackers to overwrite arbitrary files via a symlink attack on an attacker-owned file that is being edited by the victim.

    Published: 2 Apr 2010
    3.7
    Low

    CVE-2010-1161

    Last Modified: 11 Apr 2025

    Race condition in GNU nano before 2.2.4, when run by root to edit a file that is not owned by root, allows local user-assisted attackers to change the ownership of arbitrary files via vectors related to the creation of backup files.

    Published: 2 Apr 2010
    4.3
    Medium

    CVE-2010-1206

    Last Modified: 11 Apr 2025

    The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

    Published: 2 Apr 2010
    9.3
    Critical

    CVE-2010-1225

    Last Modified: 11 Apr 2025

    The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memory locations in the VMM work area, which allows context-dependent attackers to bypass certain anti-exploitation protection mechanisms on the guest OS via crafted input to a vulnerable application. NOTE: the vendor reportedly found that only systems with an otherwise vulnerable application are affected, because "the memory areas accessible from the guest cannot be leveraged to achieve either remote code execution or elevation of privilege and ... no data from the host is exposed to the guest OS."

    Published: 1 Apr 2010
    5
    Medium

    CVE-2010-1226

    Last Modified: 11 Apr 2025

    The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1227

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Sun Java System Communications Express 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via the subject field of a message, as demonstrated by a subject containing an IMG element with a SRC attribute that performs a cross-site request forgery (CSRF) attack involving the cmd and argv parameters to cmd.msc.

    Published: 1 Apr 2010
    10
    Critical

    CVE-2010-1228

    Last Modified: 11 Apr 2025

    Multiple race conditions in the sandbox infrastructure in Google Chrome before 4.1.249.1036 have unspecified impact and attack vectors.

    Published: 1 Apr 2010
    10
    Critical

    CVE-2010-1229

    Last Modified: 11 Apr 2025

    The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.

    Published: 1 Apr 2010
    10
    Critical

    CVE-2010-1230

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspecified impact and attack vectors.

    Published: 1 Apr 2010
    7.5
    High

    CVE-2010-1231

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1036 processes HTTP headers before invoking the SafeBrowsing feature, which allows remote attackers to have an unspecified impact via crafted headers.

    Published: 1 Apr 2010
    5
    Medium

    CVE-2010-1232

    Last Modified: 11 Apr 2025

    Google Chrome before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via a malformed SVG document.

    Published: 1 Apr 2010
    10
    Critical

    CVE-2010-1233

    Last Modified: 25 Jun 2025

    Multiple integer overflows in Google Chrome before 4.1.249.1036 allow remote attackers to have an unspecified impact via vectors involving WebKit JavaScript objects.

    Published: 1 Apr 2010
    7.5
    High

    CVE-2010-1234

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to truncate the URL shown in the HTTP Basic Authentication dialog via unknown vectors.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1235

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Google Chrome before 4.1.249.1036 allows remote attackers to trigger the omission of a download warning dialog via unknown vectors.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1236

    Last Modified: 11 Apr 2025

    The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted javascript: URL, as demonstrated by a \x00javascript:alert sequence.

    Published: 1 Apr 2010
    7.5
    High

    CVE-2010-1237

    Last Modified: 11 Apr 2025

    Google Chrome 4.1 BETA before 4.1.249.1036 allows remote attackers to cause a denial of service (memory error) or possibly have unspecified other impact via an empty SVG element.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1224

    Last Modified: 11 Apr 2025

    main/acl.c in Asterisk Open Source 1.6.0.x before 1.6.0.25, 1.6.1.x before 1.6.1.17, and 1.6.2.x before 1.6.2.5 does not properly enforce remote host access controls when CIDR notation "/0" is used in permit= and deny= configuration rules, which causes an improper arithmetic shift and might allow remote attackers to bypass ACL rules and access services from unauthorized hosts.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-0768

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 1 Apr 2010