CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2010-0124

    Last Modified: 11 Apr 2025

    Employee Timeclock Software 0.99 places the database password on the mysqldump command line, which allows local users to obtain sensitive information by listing the process.

    Published: 12 Mar 2010
    4.3
    Medium

    CVE-2010-0042

    Last Modified: 11 Apr 2025

    ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to obtain potentially sensitive information from process memory via a crafted TIFF image.

    Published: 12 Mar 2010
    5
    Medium

    CVE-2010-0397

    Last Modified: 11 Apr 2025

    The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

    Published: 12 Mar 2010
    4.3
    Medium

    CVE-2010-1195

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.

    Published: 12 Mar 2010
    9.3
    Critical

    CVE-2010-0046

    Last Modified: 11 Apr 2025

    The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted format arguments.

    Published: 11 Mar 2010
    8.8
    High

    CVE-2010-0047

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "HTML object element fallback content."

    Published: 11 Mar 2010
    8.8
    High

    CVE-2010-0048

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XML document.

    Published: 11 Mar 2010
    9.3
    Critical

    CVE-2010-0049

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.

    Published: 11 Mar 2010
    9.3
    Critical

    CVE-2010-0052

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to "callbacks for HTML elements."

    Published: 11 Mar 2010
    9.3
    Critical

    CVE-2010-0053

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the run-in Cascading Style Sheets (CSS) display property.

    Published: 11 Mar 2010
    9.3
    Critical

    CVE-2010-0054

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving HTML IMG elements.

    Published: 11 Mar 2010
    4.9
    Medium

    CVE-2010-0727

    Last Modified: 11 Apr 2025

    The gfs2_lock function in the Linux kernel before 2.6.34-rc1-next-20100312, and the gfs_lock function in the Linux kernel on Red Hat Enterprise Linux (RHEL) 5 and 6, does not properly remove POSIX locks on files that are setgid without group-execute permission, which allows local users to cause a denial of service (BUG and system crash) by locking a file on a (1) GFS or (2) GFS2 filesystem, and then changing this file's permissions.

    Published: 11 Mar 2010
    5
    Medium

    CVE-2010-0969

    Last Modified: 11 Apr 2025

    Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 11 Mar 2010
    8.8
    High

    CVE-2010-0050

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

    Published: 11 Mar 2010
    8.8
    High

    CVE-2010-0806

    Last Modified: 21 May 2026

    Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4680

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4681

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to inject arbitrary web script or HTML via the st parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4684

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in EZodiak allows remote attackers to inject arbitrary web script or HTML via the sign parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4685

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in celebrities.php in PHP Scripts Now Astrology allows remote attackers to inject arbitrary web script or HTML via the day parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4686

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in account.php in phplemon AdQuick 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the red_url parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4690

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rate.php and (2) postcomments.php.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4691

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in addlink.php in Classified Linktrader Script allows remote attackers to execute arbitrary SQL commands via the slctCategories parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4692

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the pr parameter in a ulist action.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4693

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PHP code via a URL in the LANG parameter to (1) en.inc.php, (2) hu.inc.php, (3) no.inc.php, (4) ro.inc.php, and (5) ru.inc.php in language/.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4695

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4697

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in RadNICS Gold 5 allow remote attackers to inject arbitrary web script or HTML via the (1) order parameter in a ulist action and the (2) fid parameter in a view_forum action.

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0257

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."

    Published: 10 Mar 2010
    10
    Critical

    CVE-2010-0447

    Last Modified: 11 Apr 2025

    The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4683

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in vote.php in Good/Bad Vote allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter in a dovote action. NOTE: some of these details are obtained from third party information.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4688

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Shopping Cart Selling Website Script allow remote attackers to inject arbitrary web script or HTML via the (1) txtkeywords and (2) cid parameters.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4689

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0262

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Microsoft Office Excel FNGROUPNAME Record Uninitialized Memory Vulnerability."

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0263

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2007 SP1 and SP2; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; and Office SharePoint Server 2007 SP1 and SP2 do not validate ZIP headers during decompression of Open XML (.XLSX) documents, which allows remote attackers to execute arbitrary code via a crafted document that triggers access to uninitialized memory locations, aka "Microsoft Office Excel XLSX File Parsing Code Execution Vulnerability."

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0264

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability."

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2010-0959

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.

    Published: 10 Mar 2010
    7.2
    High

    CVE-2010-0960

    Last Modified: 11 Apr 2025

    Buffer overflow in qosmod in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

    Published: 10 Mar 2010
    7.2
    High

    CVE-2010-0961

    Last Modified: 11 Apr 2025

    Buffer overflow in qoslist in bos.net.tcp.server in IBM AIX 6.1 and VIOS 2.1 allows local users to gain privileges via unspecified vectors.

    Published: 10 Mar 2010
    5
    Medium

    CVE-2010-0962

    Last Modified: 11 Apr 2025

    The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4687

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in silentum_guestbook.php in Silentum Guestbook 2.0.2 allows remote attackers to execute arbitrary SQL commands via the messageid parameter.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4682

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vote.php in Good/Bad Vote allows remote attackers to inject arbitrary web script or HTML via the id parameter in a vote action.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2009-4694

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in RadScripts RadLance Gold 7.5 allows remote attackers to inject arbitrary web script or HTML via the fid parameter in a view_forum action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 10 Mar 2010
    7.5
    High

    CVE-2009-4696

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in RadNICS Gold 5 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a view_forum action.

    Published: 10 Mar 2010
    7.8
    High

    CVE-2010-0258

    Last Modified: 11 Apr 2025

    Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0260

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXTUPLE record is broken up into several records," aka "Microsoft Office Excel MDXTUPLE Record Heap Overflow Vulnerability."

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0261

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSET record is broken up into several records," aka "Microsoft Office Excel MDXSET Record Heap Overflow Vulnerability."

    Published: 10 Mar 2010
    9.3
    Critical

    CVE-2010-0265

    Last Modified: 11 Apr 2025

    Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."

    Published: 10 Mar 2010
    5.8
    Medium

    CVE-2010-0396

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the dpkg-source component in dpkg before 1.14.29 allows remote attackers to modify arbitrary files via a crafted Debian source archive.

    Published: 10 Mar 2010
    6.8
    Medium

    CVE-2010-0624

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the rmt_read__ function in lib/rtapelib.c in the rmt client functionality in GNU tar before 1.23 and GNU cpio before 2.11 allows remote rmt servers to cause a denial of service (memory corruption) or possibly execute arbitrary code by sending more data than was requested, related to archive filenames that contain a : (colon) character.

    Published: 10 Mar 2010
    4.3
    Medium

    CVE-2010-0947

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in post.aspx in Max Network Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 9 Mar 2010
    6.8
    Medium

    CVE-2010-0948

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Mar 2010