CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2010-0160

    Last Modified: 11 Apr 2025

    The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 17 Feb 2010
    4.3
    Medium

    CVE-2010-0162

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.

    Published: 17 Feb 2010
    10
    Critical

    CVE-2009-1571

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt to access freed objects in low-memory situations.

    Published: 17 Feb 2010
    5
    Medium

    CVE-2009-3988

    Last Modified: 11 Apr 2025

    Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties in showModalDialog, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via crafted dialogArguments values.

    Published: 17 Feb 2010
    10
    Critical

    CVE-2010-0159

    Last Modified: 11 Apr 2025

    The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the nsBlockFrame::StealFrame function in layout/generic/nsBlockFrame.cpp, and unspecified other vectors.

    Published: 17 Feb 2010
    3.5
    Low

    CVE-2010-0684

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.

    Published: 17 Feb 2010
    4.7
    Medium

    CVE-2010-1083

    Last Modified: 11 Apr 2025

    The processcompl_compat function in drivers/usb/core/devio.c in Linux kernel 2.6.x through 2.6.32, and possibly other versions, does not clear the transfer buffer before returning to userspace when a USB command fails, which might make it easier for physically proximate attackers to obtain sensitive information (kernel memory).

    Published: 17 Feb 2010
    7.8
    High

    CVE-2010-0283

    Last Modified: 11 Apr 2025

    The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 before 1.7.2, and 1.8 alpha, allows remote attackers to cause a denial of service (assertion failure and daemon crash) via an invalid (1) AS-REQ or (2) TGS-REQ request.

    Published: 16 Feb 2010
    5.4
    Medium

    CVE-2011-1767

    Last Modified: 11 Apr 2025

    net/ipv4/ip_gre.c in the Linux kernel before 2.6.34, when ip_gre is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

    Published: 16 Feb 2010
    7.8
    High

    CVE-2010-0188

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 16 Feb 2010
    5.4
    Medium

    CVE-2011-1768

    Last Modified: 11 Apr 2025

    The tunnels implementation in the Linux kernel before 2.6.34, when tunnel functionality is configured as a module, allows remote attackers to cause a denial of service (OOPS) by sending a packet during module loading.

    Published: 16 Feb 2010
    6.8
    Medium

    CVE-2010-0638

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in WebCalendar 1.2.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password via unknown vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 15 Feb 2010
    10
    Critical

    CVE-2009-4643

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Access Client 4.72.11421.0 and other products, allows remote attackers to execute arbitrary code via a long string in a malformed DSSETUPSERVICE_CMD_UNINSTALL command to the NeoterisSetupService named pipe.

    Published: 15 Feb 2010
    6.5
    Medium

    CVE-2009-3960

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.

    Published: 15 Feb 2010
    10
    Critical

    CVE-2010-0098

    Last Modified: 11 Apr 2025

    ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities.

    Published: 15 Feb 2010
    7.5
    High

    CVE-2010-0630

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in viewjokes.php in Evernew Free Joke Script 1.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 12 Feb 2010
    7.5
    High

    CVE-2010-0631

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow remote attackers to execute arbitrary SQL commands via the (1) users (username) and (2) passwords parameters.

    Published: 12 Feb 2010
    7.5
    High

    CVE-2010-0632

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in a display action to index.php.

    Published: 12 Feb 2010
    4.6
    Medium

    CVE-2010-0633

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix XenServer 5.0 Update 3 and earlier, and 5.5, allows local users to bypass authentication and execute unspecified Xen API (XAPI) calls via unknown vectors.

    Published: 12 Feb 2010
    7.5
    High

    CVE-2010-0635

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the plgSearchEventsearch::onSearch method in eventsearch.php in the JEvents Search plugin 1.5 through 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vectors. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2010
    4.3
    Medium

    CVE-2010-0636

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to inject arbitrary web script or HTML via the (1) tab parameter to users.php and the PATH_INFO to (2) day.php, (3) month.php, and (4) week.php. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2010
    6.8
    Medium

    CVE-2010-0637

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in WebCalendar 1.2.0, and other versions before 1.2.5, allow remote attackers to hijack the authentication of administrators for requests that (1) delete an event or (2) ban an IP address from posting via unknown vectors. NOTE: some of these details are obtained from third party information.

    Published: 12 Feb 2010
    10
    Critical

    CVE-2001-1586

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary programs via encoded ../ ("%2E%2E%2F%") sequences in a request to the cgi-bin/ directory, a different vulnerability than CVE-2000-0664.

    Published: 12 Feb 2010
    4.3
    Medium

    CVE-2010-0446

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP DreamScreen 100 and 130 with firmware before 1.6.0.0, when using a web-connected configuration, allows remote attackers to obtain sensitive information via unknown vectors.

    Published: 12 Feb 2010
    4
    Medium

    CVE-2010-0422

    Last Modified: 11 Apr 2025

    gnome-screensaver 2.28.x before 2.28.3 does not properly synchronize the state of screen locking and the unlock dialog in situations involving a change to the number of monitors, which allows physically proximate attackers to bypass screen locking and access an unattended workstation by connecting and disconnecting monitors multiple times, a related issue to CVE-2010-0414.

    Published: 12 Feb 2010
    9.3
    Critical

    CVE-2009-2949

    Last Modified: 11 Apr 2025

    Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow.

    Published: 12 Feb 2010
    9.3
    Critical

    CVE-2009-3302

    Last Modified: 11 Apr 2025

    filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTSetBrc table property modifier in a Word document, related to a "boundary error flaw."

    Published: 12 Feb 2010
    9.3
    Critical

    CVE-2010-0136

    Last Modified: 11 Apr 2025

    OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.

    Published: 12 Feb 2010
    5
    Medium

    CVE-2010-0639

    Last Modified: 11 Apr 2025

    The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.

    Published: 12 Feb 2010
    6.9
    Medium

    CVE-2010-0923

    Last Modified: 11 Apr 2025

    Race condition in workspace/krunner/lock/lockdlg.cc in the KRunner lock module in kdebase in KDE SC 4.4.0 allows physically proximate attackers to bypass KScreenSaver screen locking and access an unattended workstation by pressing the Enter key at a certain time, related to multiple forked processes.

    Published: 12 Feb 2010
    9.3
    Critical

    CVE-2009-2950

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the GIFLZWDecompressor::GIFLZWDecompressor function in filter.vcl/lgif/decode.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file, related to LZW decompression.

    Published: 12 Feb 2010
    9.3
    Critical

    CVE-2009-3301

    Last Modified: 11 Apr 2025

    Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.

    Published: 12 Feb 2010
    7.2
    High

    CVE-2009-4642

    Last Modified: 11 Apr 2025

    gnome-screensaver 2.26.1 relies on the gnome-session D-Bus interface to determine session idle time, even when an Xfce desktop such as Xubuntu or Mythbuntu is used, which allows physically proximate attackers to access an unattended workstation on which screen locking had been intended.

    Published: 11 Feb 2010
    9.3
    Critical

    CVE-2009-3735

    Last Modified: 11 Apr 2025

    The ActiveScan Installer ActiveX control in as2stubie.dll before 1.3.3.0 in PandaActiveScan Installer 2.0 in Panda ActiveScan downloads software in an as2guiie.cab archive located at an arbitrary URL, and does not verify the archive's digital signature before installation, which allows remote attackers to execute arbitrary code via a URL argument to an unspecified method.

    Published: 11 Feb 2010
    10
    Critical

    CVE-2010-0145

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors, aka IronPort Bug 65923.

    Published: 11 Feb 2010
    10
    Critical

    CVE-2010-0445

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0605

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

    Published: 11 Feb 2010
    3.5
    Low

    CVE-2010-0606

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.

    Published: 11 Feb 2010
    4.3
    Medium

    CVE-2010-0607

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote attackers to inject arbitrary web script or HTML via the Stat_Radio parameter.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0608

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the forums[] parameter in a search action.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0609

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in header.php in NovaBoard 1.1.2 allows remote attackers to execute arbitrary SQL commands via the nova_name cookie parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0610

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in the Photoblog (com_photoblog) component for Joomla! allow remote attackers to execute arbitrary SQL commands via the blog parameter in an images action to index.php. NOTE: a separate vector for the id parameter to detail.php may also exist.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0611

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in adminlogin.php in Baal Systems 3.8 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0612

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in DocumentManager before 4.0 has unknown impact and attack vectors, related to file rights.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0616

    Last Modified: 11 Apr 2025

    evalSMSI 2.1.03 stores passwords in cleartext in the database, which allows attackers with database access to gain privileges. NOTE: remote attack vectors are possible by leveraging a separate SQL injection vulnerability.

    Published: 11 Feb 2010
    7.8
    High

    CVE-2010-0144

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the WebSafe DistributorServlet in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65922.

    Published: 11 Feb 2010
    7.5
    High

    CVE-2010-0614

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to execute arbitrary SQL commands via the query parameter in the (1) question action, and possibly the (2) sub_par or (3) num_quest actions.

    Published: 11 Feb 2010
    4.3
    Medium

    CVE-2010-0615

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in assess.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the reports comment box in a continue_assess action. NOTE: some of these details are obtained from third party information.

    Published: 11 Feb 2010
    4.3
    Medium

    CVE-2010-0617

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ajax.php in evalSMSI 2.1.03 allows remote attackers to inject arbitrary web script or HTML via the return parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 11 Feb 2010
    7.8
    High

    CVE-2010-0143

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the administrative interface in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to read arbitrary files via unknown vectors, aka IronPort Bug 65921.

    Published: 11 Feb 2010