CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2010-0949

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Natychmiast CMS allow remote attackers to inject arbitrary web script or HTML via the id_str parameter to (1) index.php and (2) a_index.php.

    Published: 9 Mar 2010
    7.5
    High

    CVE-2010-0950

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Natychmiast CMS allow remote attackers to execute arbitrary SQL commands via the id_str parameter to (1) index.php and (2) a_index.php.

    Published: 9 Mar 2010
    7.5
    High

    CVE-2010-0951

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.

    Published: 9 Mar 2010
    6.8
    Medium

    CVE-2010-0952

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.

    Published: 9 Mar 2010
    6.8
    Medium

    CVE-2010-0953

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.

    Published: 9 Mar 2010
    7.5
    High

    CVE-2010-0954

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commands via the course_ID parameter.

    Published: 9 Mar 2010
    7.5
    High

    CVE-2010-0955

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Bild Flirt Community 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 9 Mar 2010
    7.5
    High

    CVE-2010-0956

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Published: 9 Mar 2010
    6.8
    Medium

    CVE-2010-0957

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in content.php in Saskia's Shopsystem beta1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the id parameter.

    Published: 9 Mar 2010
    6.8
    Medium

    CVE-2010-0958

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in modules/hayoo/index.php in Tribisur 2.1, 2.0, and earlier, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Mar 2010
    9.3
    Critical

    CVE-2010-0103

    Last Modified: 11 Apr 2025

    UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.

    Published: 9 Mar 2010
    10
    Critical

    CVE-2010-0418

    Last Modified: 11 Apr 2025

    The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request.

    Published: 9 Mar 2010
    8.5
    High

    CVE-2010-0728

    Last Modified: 11 Apr 2025

    smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated users to bypass intended file permissions via standard filesystem operations with any client.

    Published: 9 Mar 2010
    4
    Medium

    CVE-2010-3840

    Last Modified: 11 Apr 2025

    The Gis_line_string::init_from_wkb function in sql/spatial.cc in MySQL 5.1 before 5.1.51 allows remote authenticated users to cause a denial of service (server crash) by calling the PolyFromWKB function with Well-Known Binary (WKB) data containing a crafted number of (1) line strings or (2) line points.

    Published: 9 Mar 2010
    4.3
    Medium

    CVE-2009-4677

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in phpFK PHP Forum ohne 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 8 Mar 2010
    7.5
    High

    CVE-2010-0937

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Visualization Library before 2009.08.812 have unknown impact and attack vectors.

    Published: 8 Mar 2010
    7.5
    High

    CVE-2010-0946

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Keep It Simple Stupid (KISS) Software Advertiser (com_ksadvertiser) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showcats action to index.php.

    Published: 8 Mar 2010
    7.5
    High

    CVE-2009-4679

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.5 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2010-0936

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter.

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2010-0938

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-0939

    Last Modified: 11 Apr 2025

    Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb.

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2010-0940

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in guestbook.php in Simple PHP Guestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2010-0941

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in eTek Systems Hit Counter 2.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) inc/login.php, (3) admin/index.php, and (4) admin/forgot.php.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-0942

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the jVideoDirect (com_jvideodirect) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-0943

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JA Showcase (com_jashowcase) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a jashowcase action to index.php.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-0944

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the JCollection (com_jcollection) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Published: 8 Mar 2010
    7.5
    High

    CVE-2010-0945

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the HotBrackets Tournament Brackets (com_hotbrackets) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2009-4678

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in Winn Guestbook 2.4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-0745

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message.

    Published: 8 Mar 2010
    5
    Medium

    CVE-2010-1189

    Last Modified: 11 Apr 2025

    MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."

    Published: 8 Mar 2010
    4.3
    Medium

    CVE-2010-1190

    Last Modified: 11 Apr 2025

    thumb.php in MediaWiki before 1.15.2, when used with access-restriction mechanisms such as img_auth.php, does not check user permissions before providing scaled images, which allows remote attackers to bypass intended access restrictions and read private images via unspecified manipulations.

    Published: 8 Mar 2010
    9.3
    Critical

    CVE-2010-1132

    Last Modified: 11 Apr 2025

    The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message.

    Published: 7 Mar 2010
    10
    Critical

    CVE-2009-3032

    Last Modified: 11 Apr 2025

    Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.

    Published: 5 Mar 2010
    9.3
    Critical

    CVE-2009-4676

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long title in a FLAC file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 5 Mar 2010
    8.5
    High

    CVE-2010-0571

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vectors, and consequently execute arbitrary code via a crafted web application, aka Bug ID CSCtc46008.

    Published: 5 Mar 2010
    7.1
    High

    CVE-2010-0572

    Last Modified: 11 Apr 2025

    Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or (2) stack trace, aka Bug ID CSCtc46050.

    Published: 5 Mar 2010
    8.5
    High

    CVE-2010-0573

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the Cisco Digital Media Player before 5.2 allows remote attackers to hijack the source of (1) video or (2) data for a display via unknown vectors, related to a "content injection" issue, aka Bug ID CSCtc46024.

    Published: 5 Mar 2010
    5
    Medium

    CVE-2010-0929

    Last Modified: 11 Apr 2025

    The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff.

    Published: 5 Mar 2010
    10
    Critical

    CVE-2010-0425

    Last Modified: 24 Jul 2025

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

    Published: 5 Mar 2010
    10
    Critical

    CVE-2010-0570

    Last Modified: 11 Apr 2025

    Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x has a default password for the Tomcat administration account, which makes it easier for remote attackers to execute arbitrary code via a crafted web application, aka Bug ID CSCta03378.

    Published: 5 Mar 2010
    5
    Medium

    CVE-2010-0930

    Last Modified: 11 Apr 2025

    The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number.

    Published: 5 Mar 2010
    5
    Medium

    CVE-2010-0931

    Last Modified: 11 Apr 2025

    The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf value.

    Published: 5 Mar 2010
    5
    Medium

    CVE-2010-0932

    Last Modified: 11 Apr 2025

    The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command.

    Published: 5 Mar 2010
    6.8
    Medium

    CVE-2010-0933

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command.

    Published: 5 Mar 2010
    7.1
    High

    CVE-2010-0934

    Last Modified: 11 Apr 2025

    The triggers functionality in Perforce Server 2008.1 allows remote authenticated users with super privileges to execute arbitrary operating-system commands by using a "p4 client" command in conjunction with the form-in trigger script.

    Published: 5 Mar 2010
    4.6
    Medium

    CVE-2010-0935

    Last Modified: 11 Apr 2025

    Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command.

    Published: 5 Mar 2010
    5
    Medium

    CVE-2009-4665

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in CuteSoft_Client/CuteEditor/Load.ashx in CuteSoft Components Cute Editor for ASP.NET allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Published: 5 Mar 2010
    7.5
    High

    CVE-2009-4666

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in Webradev Download Protect 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[RootPath] parameter to (1) Framework/EmailTemplates.class.php, (2) Customers/PDPEmailReplaceConstants.class.php, and (3) Admin/ResellersManager.class.php in includes/DProtect/.

    Published: 5 Mar 2010
    6.5
    Medium

    CVE-2009-4667

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in form.php in WebMember 1.0 allows remote authenticated users to execute arbitrary SQL commands via the formID parameter.

    Published: 5 Mar 2010
    9.3
    Critical

    CVE-2009-4668

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long ID3 tag in an MP3 file. NOTE: some of these details are obtained from third party information.

    Published: 5 Mar 2010