CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2010-0967

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php in themes/. NOTE: some of these details are obtained from third party information.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0968

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in bannershow.php in Geekhelps ADMP 1.01 allows remote attackers to execute arbitrary SQL commands via the click parameter.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0970

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in phpmylogon.php in PhpMyLogon 2 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.

    Published: 16 Mar 2010
    2.1
    Low

    CVE-2010-0971

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor 1.6.4 allow remote authenticated users, with Instructor privileges, to inject arbitrary web script or HTML via the (1) Question and (2) Choice fields in tools/polls/add.php, the (3) Type and (4) Title fields in tools/groups/create_manual.php, and the (5) Title field in assignments/add_assignment.php. NOTE: some of these details are obtained from third party information.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0972

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the GCalendar (com_gcalendar) component 2.1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0973

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in phppool media Domain Verkaus and Auktions Portal allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0974

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHPCityPortal allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) video_show.php, (2) spotlight_detail.php, (3) real_estate_details.php, and (4) auto_details.php.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2010-0975

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PHP code via a URL in the url parameter.

    Published: 16 Mar 2010
    7.8
    High

    CVE-2010-0008

    Last Modified: 11 Apr 2025

    The sctp_rcv_ootb function in the SCTP implementation in the Linux kernel before 2.6.23 allows remote attackers to cause a denial of service (infinite loop) via (1) an Out Of The Blue (OOTB) chunk or (2) a chunk of zero length.

    Published: 16 Mar 2010
    4.3
    Medium

    CVE-2010-0163

    Last Modified: 11 Apr 2025

    Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 process e-mail attachments with a parser that performs casts and line termination incorrectly, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted message, related to message indexing.

    Published: 16 Mar 2010
    6.9
    Medium

    CVE-2009-1299

    Last Modified: 11 Apr 2025

    The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on a /tmp/.esd-##### temporary file.

    Published: 16 Mar 2010
    4.7
    Medium

    CVE-2009-4271

    Last Modified: 11 Apr 2025

    The Linux kernel 2.6.9 through 2.6.17 on the x86_64 and amd64 platforms allows local users to cause a denial of service (panic) via a 32-bit application that calls mprotect on its Virtual Dynamic Shared Object (VDSO) page and then triggers a segmentation fault.

    Published: 16 Mar 2010
    10
    Critical

    CVE-2010-2495

    Last Modified: 11 Apr 2025

    The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via vectors related to a routing change.

    Published: 16 Mar 2010
    7.5
    High

    CVE-2009-4709

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the datamints Newsticker (datamints_newsticker) extension before 0.7.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4698

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.

    Published: 15 Mar 2010
    5
    Medium

    CVE-2009-4700

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in SkaDate Dating allows remote attackers to read arbitrary files via a .. (dot dot) in the layout parameter.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4701

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Myth download (myth_download) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4702

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Tour Extension (pm_tour) extension before 0.0.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4703

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Webesse Image Gallery (ws_gallery) extension 1.0.4 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    5
    Medium

    CVE-2009-4704

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Webesse E-Card (ws_ecard) extension 1.0.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4707

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4710

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Reset backend password (cwt_resetbepassword) extension 1.20 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4711

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the CoolURI (cooluri) extension before 1.0.16 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2008-6686.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4712

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Tukanas Classifieds (aka EasyClassifieds) Script 1.0 allows remote attackers to execute arbitrary SQL commands via the b parameter.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4713

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to inject arbitrary web script or HTML via (1) the cod_categoria parameter to categoria.php, (2) the opcao parameter to index.php, and the PATH_INFO to (3) categoria.php and (4) index.php.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4714

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the quiz module for XOOPS Celepar allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to cadastro_usuario.php.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4718

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in visitorduration.php in Gonafish WebStatCaffe allows remote attackers to execute arbitrary SQL commands via the nodayshow parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4706

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mailform (mailform) extension before 0.9.24 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4716

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in results.php in EDGEPHP EZWebSearch allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4699

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) admin/auth.php and (2) file_uploader.php.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4705

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Twitter Search (twittersearch) extension before 0.1.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2010
    7.5
    High

    CVE-2009-4708

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the [Gobernalia] Front End News Submitter (gb_fenewssubmit) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4715

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in rates.php in Real Time Currency Exchange allows remote attackers to inject arbitrary web script or HTML via the Amount parameter.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2009-4717

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Gonafish WebStatCaffe allow remote attackers to inject arbitrary web script or HTML via the (1) host parameter to stat/host.php, nodayshow parameter to (2) mostvisitpage.php and (3) visitorduration.php in stat/, (4) nopagesmost parameter to stat/mostvisitpagechart.php, and date parameter to (5) pageviewers.php, (6) pageviewerschart.php, and (7) referer.php in stat/.

    Published: 15 Mar 2010
    4.3
    Medium

    CVE-2010-0421

    Last Modified: 11 Apr 2025

    Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font's charmap and the Unicode property database.

    Published: 15 Mar 2010
    6.4
    Medium

    CVE-2010-1191

    Last Modified: 11 Apr 2025

    Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.

    Published: 15 Mar 2010
    9.8
    Critical

    CVE-2010-0748

    Last Modified: 21 Nov 2024

    Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.

    Published: 14 Mar 2010
    5.3
    Medium

    CVE-2010-0749

    Last Modified: 21 Nov 2024

    Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.

    Published: 14 Mar 2010
    4.3
    Medium

    CVE-2014-8155

    Last Modified: 12 Apr 2025

    GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.

    Published: 14 Mar 2010
    4.3
    Medium

    CVE-2010-2441

    Last Modified: 11 Apr 2025

    WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.

    Published: 14 Mar 2010
    5.8
    Medium

    CVE-2010-1125

    Last Modified: 11 Apr 2025

    The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.

    Published: 13 Mar 2010
    5.8
    Medium

    CVE-2010-1126

    Last Modified: 11 Apr 2025

    The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible frame, via certain calls to the focus method.

    Published: 13 Mar 2010
    9.3
    Critical

    CVE-2009-4001

    Last Modified: 11 Apr 2025

    Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.

    Published: 12 Mar 2010
    9.3
    Critical

    CVE-2010-0040

    Last Modified: 11 Apr 2025

    Integer overflow in ColorSync in Apple Safari before 4.0.5 on Windows, and iTunes before 9.1, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with a crafted color profile that triggers a heap-based buffer overflow.

    Published: 12 Mar 2010
    4.3
    Medium

    CVE-2010-0041

    Last Modified: 11 Apr 2025

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted BMP image.

    Published: 12 Mar 2010
    9.3
    Critical

    CVE-2010-0043

    Last Modified: 11 Apr 2025

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted TIFF image.

    Published: 12 Mar 2010
    4.3
    Medium

    CVE-2010-0044

    Last Modified: 11 Apr 2025

    PubSub in Apple Safari before 4.0.5 does not properly implement use of the Accept Cookies preference to block cookies, which makes it easier for remote web servers to track users by setting a cookie in a (1) RSS or (2) Atom feed.

    Published: 12 Mar 2010
    9.3
    Critical

    CVE-2010-0045

    Last Modified: 11 Apr 2025

    Apple Safari before 4.0.5 on Windows does not properly validate external URL schemes, which allows remote attackers to open local files and execute arbitrary code via a crafted HTML document.

    Published: 12 Mar 2010
    7.5
    High

    CVE-2010-0122

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.

    Published: 12 Mar 2010
    5
    Medium

    CVE-2010-0123

    Last Modified: 11 Apr 2025

    The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for a "semi-predictable file name."

    Published: 12 Mar 2010