CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-1135

    Last Modified: 11 Apr 2025

    The user_logout function in TikiWiki CMS/Groupware 4.x before 4.2 does not properly delete user login cookies, which allows remote attackers to gain access via cookie reuse.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2010-1136

    Last Modified: 11 Apr 2025

    The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent login," probably due to the generation of predictable cookies based on the IP address and User agent in userslib.php.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4740

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 has unspecified impact and remote attack vectors.

    Published: 26 Mar 2010
    10
    Critical

    CVE-2009-4741

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Extras Manager before 2.0.0.67 in Skype before 4.1.0.179 on Windows has unknown impact and attack vectors.

    Published: 26 Mar 2010
    4.3
    Medium

    CVE-2009-4743

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in history-storage.aspx in AfterLogic WebMail Pro 4.7.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) HistoryStorageObjectName and (2) HistoryKey parameters.

    Published: 26 Mar 2010
    4.3
    Medium

    CVE-2009-4744

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Contact module in Exponent CMS 0.97-GA20090213 allows remote attackers to inject arbitrary web script or HTML via the email parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Mar 2010
    4.3
    Medium

    CVE-2009-4746

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter in a poll_default login action.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4747

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in public/code/cp_html2xhtmlbasic.php in All In One Control Panel (AIOCP) 1.4.001 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter, a different vector than CVE-2009-3220.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4748

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4749

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHP Live! 3.2.1 and 3.2.2 allow remote attackers to execute arbitrary SQL commands via the x parameter to (1) message_box.php and (2) request.php.

    Published: 26 Mar 2010
    6.8
    Medium

    CVE-2009-4750

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in home.php in Top Paidmailer allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4751

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQL commands via the id parameter in a rubrik action.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4752

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary PHP code via a URL in the go parameter.

    Published: 26 Mar 2010
    6.8
    Medium

    CVE-2009-4739

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in index.php in SkaDate Dating allows remote attackers to execute arbitrary PHP code via a URL in the language_id parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4742

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Docebo 3.6.0.3 allow remote attackers to execute arbitrary SQL commands via (1) the word parameter in a play help action to the faq module, reachable through index.php; (2) the word parameter in a play keyw action to the link module, reachable through index.php; (3) the id_certificate parameter in an elemmetacertificate action to the meta_certificate module, reachable through index.php; or (4) the id_certificate parameter in an elemcertificate action to the certificate module, reachable through index.php.

    Published: 26 Mar 2010
    5
    Medium

    CVE-2010-1127

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 and 7 does not initialize certain data structures during execution of the createElement method, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via crafted JavaScript code, as demonstrated by setting the (1) outerHTML or (2) value property of an object returned by createElement.

    Published: 26 Mar 2010
    7.5
    High

    CVE-2009-4745

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3) pageNumber parameter in a login action.

    Published: 26 Mar 2010
    6.9
    Medium

    CVE-2010-0439

    Last Modified: 11 Apr 2025

    Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.

    Published: 26 Mar 2010
    6
    Medium

    CVE-2010-0988

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Pulse CMS before 1.2.3 allow (1) remote attackers to write to arbitrary files and execute arbitrary PHP code via vectors related to improper handling of login failures by includes/login.php; and allow remote authenticated users to write to arbitrary files and execute arbitrary PHP code via vectors involving the (2) filename and (3) block parameters to view.php.

    Published: 26 Mar 2010
    5.5
    Medium

    CVE-2010-0989

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in delete.php in Pulse CMS before 1.2.3 allows remote authenticated users to delete arbitrary files via directory traversal sequences in the f parameter.

    Published: 26 Mar 2010
    2.1
    Low

    CVE-2010-1123

    Last Modified: 11 Apr 2025

    Chip Salzenberg Deliver does not properly associate a lockfile with the user who created the file, which allows local users to cause a denial of service (blockage of incoming e-mail) by creating lockfiles for arbitrary mailboxes.

    Published: 26 Mar 2010
    7.8
    High

    CVE-2010-1124

    Last Modified: 11 Apr 2025

    bos.rte.libc 5.3.9.4 on IBM AIX 5.3 does not properly support reading a certain address field after a successful getaddrinfo function call, which allows context-dependent attackers to cause a denial of service (application crash) via unspecified vectors, as demonstrated by IBM DB2 crashes on "systems with databases cataloged with alternate servers using IP addresses."

    Published: 26 Mar 2010
    4.3
    Medium

    CVE-2009-4505

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OpenCMS OAMP Comments Module 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the name field in a comment, and other unspecified vectors.

    Published: 26 Mar 2010
    10
    Critical

    CVE-2010-1122

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a different vulnerability than CVE-2010-1028.

    Published: 25 Mar 2010
    7.1
    High

    CVE-2010-0577

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 through 12.4, when certain PMTUD, SNAT, or window-size configurations are used, allows remote attackers to cause a denial of service (infinite loop, and device reload or hang) via a TCP segment with crafted options, aka Bug ID CSCsz75186.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0578

    Last Modified: 11 Apr 2025

    The IKE implementation in Cisco IOS 12.2 through 12.4 on Cisco 7200 and 7301 routers with VAM2+ allows remote attackers to cause a denial of service (device reload) via a malformed IKE packet, aka Bug ID CSCtb13491.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0579

    Last Modified: 11 Apr 2025

    The SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device reload) via a malformed SIP message, aka Bug ID CSCtb93416, the "SIP Message Handling Denial of Service Vulnerability."

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-0580

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-0581

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz89904, the "SIP Packet Parsing Arbitrary Code Execution Vulnerability."

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0582

    Last Modified: 11 Apr 2025

    Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (interface queue wedge) via malformed H.323 packets, aka Bug ID CSCta19962.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0583

    Last Modified: 11 Apr 2025

    Memory leak in the H.323 implementation in Cisco IOS 12.1 through 12.4, and 15.0M before 15.0(1)M1, allows remote attackers to cause a denial of service (memory consumption and device reload) via malformed H.323 packets, aka Bug ID CSCtb93855.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0585

    Last Modified: 11 Apr 2025

    Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz48614, the "SCCP Packet Processing Denial of Service Vulnerability."

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0586

    Last Modified: 11 Apr 2025

    Cisco IOS 12.1 through 12.4, when Cisco Unified Communications Manager Express (CME) or Cisco Unified Survivable Remote Site Telephony (SRST) is enabled, allows remote attackers to cause a denial of service (device reload) via a malformed Skinny Client Control Protocol (SCCP) message, aka Bug ID CSCsz49741, the "SCCP Request Handling Denial of Service Vulnerability."

    Published: 25 Mar 2010
    9.3
    Critical

    CVE-2010-0164

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.

    Published: 25 Mar 2010
    9.3
    Critical

    CVE-2010-0165

    Last Modified: 11 Apr 2025

    The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.

    Published: 25 Mar 2010
    7.6
    High

    CVE-2010-0168

    Last Modified: 11 Apr 2025

    The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

    Published: 25 Mar 2010
    4.3
    Medium

    CVE-2010-0172

    Last Modified: 11 Apr 2025

    toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.

    Published: 25 Mar 2010
    7.6
    High

    CVE-2010-1117

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to discover the base address of a Windows .dll file, and possibly have unspecified other impact, via unknown vectors, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-1118

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanSecWest 2010.

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-1119

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari before 4.1 on Mac OS X 10.4, and Safari on Apple iPhone OS allows remote attackers to execute arbitrary code or cause a denial of service (application crash), or read the SMS database or other data, via vectors related to "attribute manipulation," as demonstrated by Vincenzo Iozzo and Ralf Philipp Weinmann during a Pwn2Own competition at CanSecWest 2010.

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-1120

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Charlie Miller during a Pwn2Own competition at CanSecWest 2010.

    Published: 25 Mar 2010
    10
    Critical

    CVE-2010-1121

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.

    Published: 25 Mar 2010
    5.1
    Medium

    CVE-2010-0166

    Last Modified: 11 Apr 2025

    The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

    Published: 25 Mar 2010
    4.3
    Medium

    CVE-2010-0170

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0576

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.0 through 12.4, IOS XE 2.1.x through 2.3.x before 2.3.2, and IOS XR 3.2.x through 3.4.3, when Multiprotocol Label Switching (MPLS) and Label Distribution Protocol (LDP) are enabled, allows remote attackers to cause a denial of service (device reload or process restart) via a crafted LDP packet, aka Bug IDs CSCsz45567 and CSCsj25893.

    Published: 25 Mar 2010
    7.8
    High

    CVE-2010-0584

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco IOS 12.4, when NAT SCCP fragmentation support is enabled, allows remote attackers to cause a denial of service (device reload) via crafted Skinny Client Control Protocol (SCCP) packets, aka Bug ID CSCsy09250.

    Published: 25 Mar 2010
    4.3
    Medium

    CVE-2010-1105

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in cgi/index.php in AdvertisementManager 3.1.0 and 3.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter.

    Published: 25 Mar 2010
    7.5
    High

    CVE-2010-1106

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in cgi/index.php in AdvertisementManager 3.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the req parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Published: 25 Mar 2010
    3.5
    Low

    CVE-2010-1107

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Recent Comments module 5.x through 5.x-1.2 and 6.x through 6.x-1.0 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a "custom block title interface."

    Published: 25 Mar 2010
    3.5
    Low

    CVE-2010-1108

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Control Panel module 5.x through 5.x-1.5 and 6.x through 6.x-1.2 for Drupal allows remote authenticated users, with "administer blocks" privileges, to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Mar 2010