CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2010-1031

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Insight Control for Linux (aka IC-Linux or ICE-LX) 2.11 and earlier allows local users to gain privileges via unknown vectors.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1193

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebAccess in VMware Server 2.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON error messages.

    Published: 1 Apr 2010
    7.5
    High

    CVE-2010-0686

    Last Modified: 11 Apr 2025

    WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability."

    Published: 1 Apr 2010
    1.9
    Low

    CVE-2010-0769

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 does not properly define wsadmin scripting J2CConnectionFactory objects, which allows local users to discover a KeyRingPassword password by reading a cleartext field in the resources.xml file.

    Published: 1 Apr 2010
    4
    Medium

    CVE-2010-0770

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.9 allows remote authenticated users to cause a denial of service (ORB ListenerThread hang) by aborting an SSL handshake.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2010-1137

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5, and the Server Console in VMware Server 1.0, allows remote attackers to inject arbitrary web script or HTML via the name of a virtual machine.

    Published: 1 Apr 2010
    4.3
    Medium

    CVE-2009-2277

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebAccess in VMware VirtualCenter 2.0.2 and 2.5 and VMware ESX 3.0.3 and 3.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "context data."

    Published: 1 Apr 2010
    7.5
    High

    CVE-2010-0850

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 1.3.1_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 1 Apr 2010
    1.9
    Low

    CVE-2010-0826

    Last Modified: 11 Apr 2025

    The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain sensitive information via a symlink attack involving a setgid or setuid application that uses this module.

    Published: 1 Apr 2010
    9.3
    Critical

    CVE-2010-0267

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    6.5
    Medium

    CVE-2010-0488

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Information Disclosure Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0491

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    4.3
    Medium

    CVE-2010-0494

    Last Modified: 11 Apr 2025

    Cross-domain vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted HTML document in a situation where the client user drags one browser window across another browser window, aka "HTML Element Cross-Domain Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0805

    Last Modified: 11 Apr 2025

    The Tabular Data Control (TDC) ActiveX control in Microsoft Internet Explorer 5.01 SP4, 6 on Windows XP SP2 and SP3, and 6 SP1 allows remote attackers to execute arbitrary code via a long URL (DataURL parameter) that triggers memory corruption in the CTDCCtl::SecurityCHeckDataURL function, aka "Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0807

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0489

    Last Modified: 11 Apr 2025

    Race condition in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, aka "Race Condition Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0490

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    8.1
    High

    CVE-2010-0492

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0527

    Last Modified: 11 Apr 2025

    Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.

    Published: 31 Mar 2010
    4.3
    Medium

    CVE-2010-0531

    Last Modified: 11 Apr 2025

    Apple iTunes before 9.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted MP4 podcast file.

    Published: 31 Mar 2010
    6.9
    Medium

    CVE-2010-0532

    Last Modified: 11 Apr 2025

    Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse.

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0528

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted color tables in a movie file, related to malformed MediaVideo data, a sample description atom (STSD), and a crafted length value.

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0529

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted values that are used in a calculation for memory allocation.

    Published: 31 Mar 2010
    9.3
    Critical

    CVE-2010-0536

    Last Modified: 11 Apr 2025

    Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image.

    Published: 31 Mar 2010
    2.6
    Low

    CVE-2010-0132

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input," a different vulnerability than CVE-2010-0736.

    Published: 31 Mar 2010
    8.5
    High

    CVE-2010-0450

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote authenticated users to gain privileges via unknown vectors.

    Published: 31 Mar 2010
    4.3
    Medium

    CVE-2010-0449

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

    Published: 31 Mar 2010
    4.4
    Medium

    CVE-2010-1030

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP-UX B.11.31, with AudFilter rules enabled, allows local users to cause a denial of service via unknown vectors.

    Published: 31 Mar 2010
    5
    Medium

    CVE-2010-0448

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP SOA Registry Foundation 6.63 and 6.64 allows remote attackers to obtain "unauthorized access to data" via unknown vectors.

    Published: 31 Mar 2010
    4.3
    Medium

    CVE-2010-0009

    Last Modified: 11 Apr 2025

    Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

    Published: 31 Mar 2010
    6
    Medium

    CVE-2010-1147

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated users to execute arbitrary code via a long MyINFO message.

    Published: 31 Mar 2010
    7.8
    High

    CVE-2010-2248

    Last Modified: 11 Apr 2025

    fs/cifs/cifssmb.c in the CIFS implementation in the Linux kernel before 2.6.34-rc4 allows remote attackers to cause a denial of service (panic) via an SMB response packet with an invalid CountHigh value, as demonstrated by a response from an OS/2 server, related to the CIFSSMBWrite and CIFSSMBWrite2 functions.

    Published: 31 Mar 2010
    6.8
    Medium

    CVE-2009-4763

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ClickHeat plugin, as used in phpMyVisites before 2.4, has unknown impact and attack vectors. NOTE: due to lack of details from the vendor, it is not clear whether this is related to CVE-2008-5793.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-1216

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in templates/template.php in notsoPureEdit 1.4.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the content parameter. NOTE: some of these details are obtained from third party information.

    Published: 30 Mar 2010
    4.3
    Medium

    CVE-2010-1217

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter to index.php. NOTE: the original researcher states that the affected product is JE Tooltip, not Form Creator; however, the exploit URL suggests that Form Creator is affected.

    Published: 30 Mar 2010
    4.3
    Medium

    CVE-2010-1218

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mm_forum extension 1.8.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-1219

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JA News (com_janews) component 1.0 for Joomla! allows remote attackers to read arbitrary local files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0060

    Last Modified: 11 Apr 2025

    CoreAudio in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted audio content with QDMC encoding.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0062

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in quicktime.qts in CoreMedia and QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed .3g2 movie file with H.263 encoding that triggers an incorrect buffer length calculation.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0063

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.6.3 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari, as demonstrated by the values for the (1) .ibplugin and (2) .url extensions.

    Published: 30 Mar 2010
    6.9
    Medium

    CVE-2010-0064

    Last Modified: 11 Apr 2025

    DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to bypass intended disk-quota restrictions and have unspecified other impact by copying files owned by other users.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0065

    Last Modified: 11 Apr 2025

    Disk Images in Apple Mac OS X before 10.6.3 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted disk image with bzip2 compression.

    Published: 30 Mar 2010
    7.2
    High

    CVE-2010-0498

    Last Modified: 11 Apr 2025

    Directory Services in Apple Mac OS X before 10.6.3 does not properly perform authorization during processing of record names, which allows local users to gain privileges via unspecified vectors.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0501

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in FTP Server in Apple Mac OS X Server before 10.6.3 allows remote authenticated users to read arbitrary files via crafted filenames.

    Published: 30 Mar 2010
    4.3
    Medium

    CVE-2010-0502

    Last Modified: 11 Apr 2025

    iChat Server in Apple Mac OS X Server before 10.6.3, when group chat is used, does not perform logging for all types of messages, which might allow remote attackers to avoid message auditing via an unspecified selection of message type.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0506

    Last Modified: 11 Apr 2025

    Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted NEF image.

    Published: 30 Mar 2010
    6.8
    Medium

    CVE-2010-0507

    Last Modified: 11 Apr 2025

    Buffer overflow in Image RAW in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PEF image.

    Published: 30 Mar 2010
    10
    Critical

    CVE-2010-0508

    Last Modified: 11 Apr 2025

    Mail in Apple Mac OS X before 10.6.3 does not disable the filter rules associated with a deleted mail account, which has unspecified impact and attack vectors.

    Published: 30 Mar 2010
    7.2
    High

    CVE-2010-0509

    Last Modified: 11 Apr 2025

    SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership during access to the home directories of user accounts.

    Published: 30 Mar 2010
    9
    Critical

    CVE-2010-0510

    Last Modified: 11 Apr 2025

    Password Server in Apple Mac OS X Server before 10.6.3 does not properly perform password replication, which might allow remote authenticated users to obtain login access via an expired password.

    Published: 30 Mar 2010