CVE Feed

    Dashboard / CVE

    6
    Medium

    CVE-2010-0683

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related to leveraging administrative credentials.

    Published: 25 Feb 2010
    5
    Medium

    CVE-2010-0708

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in (1) ns-slapd and (2) slapd.exe in Sun Directory Server Enterprise Edition 7.0, Sun Java System Directory Server 5.2, and Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 allow remote attackers to cause a denial of service (daemon crash) via a crafted LDAP search request.

    Published: 25 Feb 2010
    5
    Medium

    CVE-2003-1589

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 4.1 before SP13 and 6.0 before SP6 on Windows allows attackers to cause a denial of service (daemon crash) via unknown vectors.

    Published: 25 Feb 2010
    7.2
    High

    CVE-2010-0705

    Last Modified: 11 Apr 2025

    Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain privileges via IOCTL requests using crafted kernel addresses that trigger memory corruption.

    Published: 25 Feb 2010
    4.3
    Medium

    CVE-2010-0706

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login/prompt component in Subex Nikira Fraud Management System allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 25 Feb 2010
    6.8
    Medium

    CVE-2010-0707

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attackers to hijack the authentication of an administrator for requests that create new administrative users. NOTE: some of these details are obtained from third party information.

    Published: 25 Feb 2010
    4.3
    Medium

    CVE-2010-0704

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Portlet Palette in IBM WebSphere Portal 6.0.1.5 wp6015_008_01 allows remote attackers to inject arbitrary web script or HTML via the search field.

    Published: 25 Feb 2010
    9.3
    Critical

    CVE-2010-0620

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an unspecified parameter.

    Published: 25 Feb 2010
    7.8
    High

    CVE-2010-1086

    Last Modified: 11 Apr 2025

    The ULE decapsulation functionality in drivers/media/dvb/dvb-core/dvb_net.c in dvb-core in Linux kernel 2.6.33 and earlier allows attackers to cause a denial of service (infinite loop) via a crafted MPEG2-TS frame, related to an invalid Payload Pointer ULE.

    Published: 25 Feb 2010
    6.4
    Medium

    CVE-2010-1128

    Last Modified: 11 Apr 2025

    The Linear Congruential Generator (LCG) in PHP before 5.2.13 does not provide the expected entropy, which makes it easier for context-dependent attackers to guess values that were intended to be unpredictable, as demonstrated by session cookies generated by using the uniqid function.

    Published: 25 Feb 2010
    7.5
    High

    CVE-2010-1129

    Last Modified: 11 Apr 2025

    The safe_mode implementation in PHP before 5.2.13 does not properly handle directory pathnames that lack a trailing / (slash) character, which allows context-dependent attackers to bypass intended access restrictions via vectors related to use of the tempnam function.

    Published: 25 Feb 2010
    5
    Medium

    CVE-2010-1130

    Last Modified: 11 Apr 2025

    session.c in the session extension in PHP before 5.2.13, and 5.3.1, does not properly interpret ; (semicolon) characters in the argument to the session_save_path function, which allows context-dependent attackers to bypass open_basedir and safe_mode restrictions via an argument that contains multiple ; characters in conjunction with a .. (dot dot).

    Published: 25 Feb 2010
    4.7
    Medium

    CVE-2011-3585

    Last Modified: 21 Nov 2024

    Multiple race conditions in the (1) mount.cifs and (2) umount.cifs programs in Samba 3.6 allow local users to cause a denial of service (mounting outage) via a SIGKILL signal during a time window when the /etc/mtab~ file exists.

    Published: 25 Feb 2010
    2.6
    Low

    CVE-2010-0640

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CA eHealth Performance Manager 6.0.x through 6.2.x, when malicious HTML detection is disabled, allows remote attackers to inject arbitrary web script or HTML via a crafted request.

    Published: 24 Feb 2010
    5
    Medium

    CVE-2010-1029

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the WebCore::CSSSelector function in WebKit, as used in Apple Safari 4.0.4, Apple Safari on iPhone OS and iPhone OS for iPod touch, and Google Chrome 4.0.249, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a STYLE element composed of a large number of *> sequences.

    Published: 24 Feb 2010
    6.8
    Medium

    CVE-2010-1244

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.

    Published: 24 Feb 2010
    9.3
    Critical

    CVE-2010-0107

    Last Modified: 11 Apr 2025

    Buffer overflow in an ActiveX control (SYMLTCOM.dll) in Symantec N360 1.0 and 2.0; Norton Internet Security, AntiVirus, SystemWorks, and Confidential 2006 through 2008; and Symantec Client Security 3.0.x before 3.1 MR9, and 3.1.x before MR9; allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors. NOTE: this is only a vulnerability if the attacker can "masquerade as an authorized site."

    Published: 23 Feb 2010
    6.8
    Medium

    CVE-2010-0146

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 23 Feb 2010
    6.5
    Medium

    CVE-2010-0147

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Feb 2010
    7.8
    High

    CVE-2010-0148

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco Security Agent 5.2 before 5.2.0.285, when running on Linux, allows remote attackers to cause a denial of service (kernel panic) via "a series of TCP packets."

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0698

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.

    Published: 23 Feb 2010
    4
    Medium

    CVE-2010-0682

    Last Modified: 11 Apr 2025

    WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter.

    Published: 23 Feb 2010
    5
    Medium

    CVE-2010-0685

    Last Modified: 11 Apr 2025

    The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstrated using the Dial application to process a crafted SIP INVITE message that adds an unintended outgoing channel leg. NOTE: it could be argued that this is not a vulnerability in Asterisk, but a class of vulnerabilities that can occur in any program that uses this feature without the associated filtering functionality that is already available.

    Published: 23 Feb 2010
    3.5
    Low

    CVE-2010-0697

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.

    Published: 23 Feb 2010
    4.3
    Medium

    CVE-2010-0699

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in VideoSearchScript Pro 3.5 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Published: 23 Feb 2010
    4.3
    Medium

    CVE-2010-0700

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in WampServer 2.0i allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0701

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0702

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Published: 23 Feb 2010
    4.3
    Medium

    CVE-2010-0703

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter.

    Published: 23 Feb 2010
    4.3
    Medium

    CVE-2009-3036

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the console in Symantec IM Manager 8.3 and 8.4 before 8.4.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Feb 2010
    9.3
    Critical

    CVE-2010-0189

    Last Modified: 11 Apr 2025

    A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0692

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0690

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0691

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0693

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2010-0694

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the PerchaGallery (com_perchagallery) component before 1.5b for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an editunidad action to index.php.

    Published: 23 Feb 2010
    4.3
    Medium

    CVE-2010-0695

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.

    Published: 23 Feb 2010
    5
    Medium

    CVE-2010-0696

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.

    Published: 23 Feb 2010
    10
    Critical

    CVE-2009-3245

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

    Published: 23 Feb 2010
    7.5
    High

    CVE-2009-4650

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a default action to index2.php. NOTE: some of these details are obtained from third party information.

    Published: 22 Feb 2010
    4.3
    Medium

    CVE-2009-4651

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.

    Published: 22 Feb 2010
    7.5
    High

    CVE-2010-0677

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.

    Published: 22 Feb 2010
    6.8
    Medium

    CVE-2010-0678

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in includes/moderation.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the includes_directory parameter.

    Published: 22 Feb 2010
    9.3
    Critical

    CVE-2010-0679

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument to the (1) SaveasMolFile and (2) ReadMolFile methods.

    Published: 22 Feb 2010
    7.5
    High

    CVE-2010-0680

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.

    Published: 22 Feb 2010
    5
    Medium

    CVE-2010-0681

    Last Modified: 11 Apr 2025

    ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.

    Published: 22 Feb 2010
    4.3
    Medium

    CVE-2009-4649

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in geccBBlite 0.1 allow remote attackers to inject arbitrary web script or HTML via the postatoda parameter to (1) rispondi.php and (2) scrivi.php, which is not properly handled in forum.php.

    Published: 22 Feb 2010
    5
    Medium

    CVE-2010-0676

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in the RWCards (com_rwcards) component 3.0.18 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter.

    Published: 22 Feb 2010
    7.5
    High

    CVE-2010-0671

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in KR MEDIA Pogodny CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a niusy action.

    Published: 22 Feb 2010
    7.5
    High

    CVE-2010-0672

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in WSN Guest 1.02 allows remote attackers to execute arbitrary SQL commands via the orderlinks parameter.

    Published: 22 Feb 2010