CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-0673

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Published: 22 Feb 2010
    5
    Medium

    CVE-2010-0674

    Last Modified: 11 Apr 2025

    StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.

    Published: 22 Feb 2010
    4.3
    Medium

    CVE-2010-0675

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in index.php in BGSvetionik BGS CMS 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the search parameter in a search action. NOTE: some of these details are obtained from third party information.

    Published: 22 Feb 2010
    5
    Medium

    CVE-2010-0670

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path for Joomla! via unknown vectors.

    Published: 22 Feb 2010
    3.3
    Low

    CVE-2010-0118

    Last Modified: 11 Apr 2025

    Bournal before 1.4.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified temporary files associated with a --hack_the_gibson update check.

    Published: 22 Feb 2010
    2.1
    Low

    CVE-2010-0119

    Last Modified: 11 Apr 2025

    Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the process and its arguments, related to "echoing."

    Published: 22 Feb 2010
    6.9
    Medium

    CVE-2010-0729

    Last Modified: 11 Apr 2025

    A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call.

    Published: 22 Feb 2010
    5.1
    Medium

    CVE-2010-0286

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the OpenID Identity Authentication extension in TYPO3 4.3.0 allows remote attackers to bypass authentication and gain access to a backend user account via unknown attack vectors in which both the attacker and victim have an OpenID provider that discards identities during authentication.

    Published: 21 Feb 2010
    6.9
    Medium

    CVE-2010-0426

    Last Modified: 11 Apr 2025

    sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

    Published: 21 Feb 2010
    9
    Critical

    CVE-2009-4646

    Last Modified: 11 Apr 2025

    Static code injection vulnerability in the administrative web interface in Accellion Secure File Transfer Appliance allows remote authenticated administrators to inject arbitrary shell commands by appending them to a request to update the SNMP public community string.

    Published: 19 Feb 2010
    4.3
    Medium

    CVE-2009-4647

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Accellion Secure File Transfer Appliance before 7_0_296 allows remote attackers to inject arbitrary web script or HTML via the username parameter, which is not properly handled when the administrator views audit logs.

    Published: 19 Feb 2010
    1.9
    Low

    CVE-2010-0106

    Last Modified: 11 Apr 2025

    The on-demand scanning in Symantec AntiVirus 10.0.x and 10.1.x before MR9, AntiVirus 10.2.x, and Client Security 3.0.x and 3.1.x before MR9, when Tamper protection is disabled, allows remote attackers to cause a denial of service (prevention of on-demand scanning) via "specific events" that prevent the user from having read access to unspecified resources.

    Published: 19 Feb 2010
    10
    Critical

    CVE-2010-0108

    Last Modified: 11 Apr 2025

    Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-0149

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.46), 8.0 before 8.0(4.38), 8.1 before 8.1(2.29), and 8.2 before 8.2(1.5); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (prevention of new connections) via crafted TCP segments during termination of the TCP connection that cause the connection to remain in CLOSEWAIT status, aka "TCP Connection Exhaustion Denial of Service Vulnerability."

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-0150

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCsy91157.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-0565

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10), allows remote attackers to cause a denial of service (page fault and device reload) via a malformed DTLS message, aka Bug ID CSCtb64913 and "WebVPN DTLS Denial of Service Vulnerability."

    Published: 19 Feb 2010
    7.1
    High

    CVE-2010-0566

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(4.44), 8.1 before 8.1(2.35), and 8.2 before 8.2(1.10) allows remote attackers to cause a denial of service (device reload) via a malformed TCP segment when certain NAT translation and Cisco AIP-SSM configurations are used, aka Bug ID CSCtb37219.

    Published: 19 Feb 2010
    9
    Critical

    CVE-2009-4644

    Last Modified: 11 Apr 2025

    Accellion Secure File Transfer Appliance before 8_0_105 allows remote authenticated administrators to bypass the restricted shell and execute arbitrary commands via shell metacharacters to the ping command, as demonstrated by modifying the cli program.

    Published: 19 Feb 2010
    7.2
    High

    CVE-2009-4648

    Last Modified: 11 Apr 2025

    Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sudo privileges, which allows local administrators to gain privileges via (1) arbitrary arguments in the --file_move action in /usr/local/bin/admin.pl, or a hard link attack in (2) chmod or (3) a certain cp command.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-0151

    Last Modified: 11 Apr 2025

    The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Client Control Protocol (SCCP) message.

    Published: 19 Feb 2010
    7.1
    High

    CVE-2010-0568

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.7), 8.1 before 8.1(2.40), and 8.2 before 8.2(2.1); and Cisco PIX 500 Series Security Appliance; allows remote attackers to bypass NTLMv1 authentication via a crafted username, aka Bug ID CSCte21953.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-0569

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.2), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.16); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCtc96018.

    Published: 19 Feb 2010
    5
    Medium

    CVE-2010-0665

    Last Modified: 11 Apr 2025

    JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for jag/database.sql.

    Published: 19 Feb 2010
    5
    Medium

    CVE-2010-0666

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in eMBox in Novell eDirectory 8.8 SP5 Patch 2 and earlier allows remote attackers to cause a denial of service (crash) via unknown a crafted SOAP request, a different issue than CVE-2008-0926.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2009-4645

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in web_client_user_guide.html in Accellion Secure File Transfer Appliance before 8_0_105 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Published: 19 Feb 2010
    5
    Medium

    CVE-2010-0567

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Cisco ASA 5500 Series Adaptive Security Appliance 7.0 before 7.0(8.10), 7.2 before 7.2(4.45), 8.0 before 8.0(5.1), 8.1 before 8.1(2.37), and 8.2 before 8.2(1.15); and Cisco PIX 500 Series Security Appliance; allows remote attackers to cause a denial of service (active IPsec tunnel loss and prevention of new tunnels) via a malformed IKE message through an existing tunnel to UDP port 4500, aka Bug ID CSCtc47782.

    Published: 19 Feb 2010
    7.8
    High

    CVE-2010-1087

    Last Modified: 11 Apr 2025

    The nfs_wait_on_request function in fs/nfs/pagelist.c in Linux kernel 2.6.x through 2.6.33-rc5 allows attackers to cause a denial of service (Oops) via unknown vectors related to truncating a file and an operation that is not interruptible.

    Published: 19 Feb 2010
    5.4
    Medium

    CVE-2010-1088

    Last Modified: 11 Apr 2025

    fs/namei.c in Linux kernel 2.6.18 through 2.6.34 does not always follow NFS automount "symlinks," which allows attackers to have an unknown impact, related to LOOKUP_FOLLOW.

    Published: 19 Feb 2010
    4.9
    Medium

    CVE-2010-1187

    Last Modified: 11 Apr 2025

    The Transparent Inter-Process Communication (TIPC) functionality in Linux kernel 2.6.16-rc1 through 2.6.33, and possibly other versions, allows local users to cause a denial of service (kernel OOPS) by sending datagrams through AF_TIPC before entering network mode, which triggers a NULL pointer dereference.

    Published: 19 Feb 2010
    4.3
    Medium

    CVE-2010-0643

    Last Modified: 11 Apr 2025

    Google Chrome before 4.0.249.89 attempts to make direct connections to web sites when all configured proxy servers are unavailable, which allows remote HTTP servers to obtain potentially sensitive information about the identity of a client user via standard HTTP logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0644

    Last Modified: 11 Apr 2025

    Google Chrome before 4.0.249.89, when a SOCKS 5 proxy server is configured, sends DNS queries directly, which allows remote DNS servers to obtain potentially sensitive information about the identity of a client user via request logging, as demonstrated by a proxy server that was configured for the purpose of anonymity.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0645

    Last Modified: 11 Apr 2025

    Multiple integer overflows in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.

    Published: 18 Feb 2010
    10
    Critical

    CVE-2010-0646

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0649

    Last Modified: 11 Apr 2025

    Integer overflow in the CrossCallParamsEx::CreateFromBuffer function in sandbox/src/crosscall_server.cc in Google Chrome before 4.0.249.89 allows attackers to leverage renderer access to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a malformed message, related to deserializing of sandbox messages.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0652

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0653

    Last Modified: 11 Apr 2025

    Opera before 10.10 permits cross-origin loading of CSS stylesheets even when the stylesheet download has an incorrect MIME type and the stylesheet document is malformed, which allows remote attackers to obtain sensitive information via a crafted document.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0655

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 4.0.249.78 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving the display of a blocked popup window during navigation to a different web site.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0657

    Last Modified: 11 Apr 2025

    Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive information by tricking a user into creating a crafted shortcut.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0658

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elements.

    Published: 18 Feb 2010
    9.3
    Critical

    CVE-2010-0659

    Last Modified: 11 Apr 2025

    The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size.

    Published: 18 Feb 2010
    5
    Medium

    CVE-2010-0660

    Last Modified: 11 Apr 2025

    Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP servers to obtain potentially sensitive information via standard HTTP logging.

    Published: 18 Feb 2010
    5
    Medium

    CVE-2010-0662

    Last Modified: 11 Apr 2025

    The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not use the correct variables in calculations designed to prevent integer overflows, which allows attackers to leverage renderer access to cause a denial of service or possibly have unspecified other impact via bitmap data, related to deserialization.

    Published: 18 Feb 2010
    5
    Medium

    CVE-2010-0663

    Last Modified: 11 Apr 2025

    The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, which might allow remote attackers to obtain potentially sensitive information from process memory by providing insufficient data, related to use of a (1) thumbnail database or (2) HTML canvas.

    Published: 18 Feb 2010
    5
    Medium

    CVE-2010-0664

    Last Modified: 11 Apr 2025

    Stack consumption vulnerability in the ChildProcessSecurityPolicy::CanRequestURL function in browser/child_process_security_policy.cc in Google Chrome before 4.0.249.78 allows remote attackers to cause a denial of service (memory consumption and application crash) via a URL that specifies multiple protocols, as demonstrated by a URL that begins with many repetitions of the view-source: substring.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0556

    Last Modified: 11 Apr 2025

    browser/login/login_prompt.cc in Google Chrome before 4.0.249.89 populates an authentication dialog with credentials that were stored by Password Manager for a different web site, which allows user-assisted remote HTTP servers to obtain sensitive information via a URL that requires authentication, as demonstrated by a URL in the SRC attribute of an IMG element.

    Published: 18 Feb 2010
    5
    Medium

    CVE-2010-0423

    Last Modified: 11 Apr 2025

    gtkimhtml.c in Pidgin before 2.6.6 allows remote attackers to cause a denial of service (CPU consumption and application hang) by sending many smileys in a (1) IM or (2) chat.

    Published: 18 Feb 2010
    3.3
    Low

    CVE-2010-0424

    Last Modified: 11 Apr 2025

    The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0420

    Last Modified: 11 Apr 2025

    libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.

    Published: 18 Feb 2010
    4.3
    Medium

    CVE-2010-0641

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webline/html/admin/wcs/LoginPage.jhtml in Cisco Collaboration Server (CCS) 5 allows remote attackers to inject arbitrary web script or HTML via the dest parameter.

    Published: 17 Feb 2010
    5
    Medium

    CVE-2010-0642

    Last Modified: 11 Apr 2025

    Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded characters in the filename extension, as demonstrated by (1) changing .jhtml to %2Ejhtml, (2) changing .jhtml to .jhtm%6C, (3) appending %00 after .jhtml, and (4) appending %c0%80 after .jhtml, related to the (a) doc/docindex.jhtml, (b) browserId/wizardForm.jhtml, (c) webline/html/forms/callback.jhtml, (d) webline/html/forms/callbackICM.jhtml, (e) webline/html/agent/AgentFrame.jhtml, (f) webline/html/agent/default/badlogin.jhtml, (g) callme/callForm.jhtml, (h) webline/html/multichatui/nowDefunctWindow.jhtml, (i) browserId/wizard.jhtml, (j) admin/CiscoAdmin.jhtml, (k) msccallme/mscCallForm.jhtml, and (l) webline/html/admin/wcs/LoginPage.jhtml components.

    Published: 17 Feb 2010