CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2010-0292

    Last Modified: 11 Apr 2025

    The read_from_cmd_socket function in cmdmon.c in chronyd in Chrony before 1.23.1, and 1.24-pre1, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by sending a spoofed cmdmon packet that triggers a continuous exchange of NOHOSTACCESS messages between two daemons, a related issue to CVE-2009-3563.

    Published: 8 Feb 2010
    7.2
    High

    CVE-2010-0414

    Last Modified: 11 Apr 2025

    gnome-screensaver before 2.28.2 allows physically proximate attackers to bypass screen locking and access an unattended workstation by moving the mouse position to an external monitor and then disconnecting that monitor.

    Published: 8 Feb 2010
    6.5
    Medium

    CVE-2010-0438

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Feb 2010
    4.3
    Medium

    CVE-2010-2087

    Last Modified: 11 Apr 2025

    Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.

    Published: 8 Feb 2010
    4
    Medium

    CVE-2010-2086

    Last Modified: 11 Apr 2025

    Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.

    Published: 8 Feb 2010
    7.5
    High

    CVE-2011-3600

    Last Modified: 21 Nov 2024

    The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with executable payloads that discloses the contents of files in the filesystem. In addition, it can also be used to probe for open network ports, and figure out from returned error messages whether a file exists or not. This affects OFBiz 16.11.01 to 16.11.04.

    Published: 6 Feb 2010
    1.5
    Low

    CVE-2009-2752

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2009-4185

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in proxy/smhui/getuiinfo in HP System Management Homepage (SMH) before 6.0 allows remote attackers to inject arbitrary web script or HTML via the servercert parameter.

    Published: 5 Feb 2010
    7.5
    High

    CVE-2010-0557

    Last Modified: 11 Apr 2025

    IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial of service, by leveraging hardcoded credentials.

    Published: 5 Feb 2010
    7.5
    High

    CVE-2010-0558

    Last Modified: 11 Apr 2025

    The default configuration of Oracle OpenSolaris snv_77 through snv_131 allows attackers to have an unspecified impact via vectors related to using smbadm to join a Windows Active Directory domain.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1580

    Last Modified: 11 Apr 2025

    The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1585

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebLogExpert allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    5
    Medium

    CVE-2003-1587

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in LoganPro allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2009-2751

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.

    Published: 5 Feb 2010
    7.5
    High

    CVE-2010-0559

    Last Modified: 11 Apr 2025

    The default configuration of Oracle OpenSolaris snv_91 through snv_131 allows attackers to have an unspecified impact via vectors related to using kclient to join a Windows Active Directory domain.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1586

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebExpert allows remote attackers to inject arbitrary web script or HTML via a crafted User-Agent HTTP header.

    Published: 5 Feb 2010
    2.6
    Low

    CVE-2003-1577

    Last Modified: 11 Apr 2025

    Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files, and conduct cross-site scripting (XSS) attacks involving the iPlanet Log Analyzer, via an HTTP request in conjunction with a crafted DNS response, related to an "Inverse Lookup Log Corruption (ILLC)" issue, a different vulnerability than CVE-2002-1315 and CVE-2002-1316.

    Published: 5 Feb 2010
    2.6
    Low

    CVE-2003-1582

    Last Modified: 11 Apr 2025

    Microsoft Internet Information Services (IIS) 6.0, when DNS resolution is enabled for client IP addresses, allows remote attackers to inject arbitrary text into log files via an HTTP request in conjunction with a crafted DNS response, as demonstrated by injecting XSS sequences, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1583

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebTrends allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1584

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SurfStats allows remote attackers to inject arbitrary web script or HTML via a crafted client domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1578

    Last Modified: 11 Apr 2025

    Sun ONE (aka iPlanet) Web Server 4.1 through SP12 and 6.0 through SP5, when DNS resolution is enabled for client IP addresses, allows remote attackers to hide HTTP requests from the log-preview functionality by accompanying the requests with crafted DNS responses specifying a domain name beginning with a "format=" substring, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    4.3
    Medium

    CVE-2003-1579

    Last Modified: 11 Apr 2025

    Sun ONE (aka iPlanet) Web Server 6 on Windows, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.

    Published: 5 Feb 2010
    3.5
    Low

    CVE-2010-0926

    Last Modified: 11 Apr 2025

    The default configuration of smbd in Samba before 3.3.11, 3.4.x before 3.4.6, and 3.5.x before 3.5.0rc3, when a writable share exists, allows remote authenticated users to leverage a directory traversal vulnerability, and access arbitrary files, by using the symlink command in smbclient to create a symlink containing .. (dot dot) sequences, related to the combination of the unix extensions and wide links options.

    Published: 5 Feb 2010
    7.1
    High

    CVE-2010-1085

    Last Modified: 11 Apr 2025

    The azx_position_ok function in hda_intel.c in Linux kernel 2.6.33-rc4 and earlier, when running on the AMD780V chip set, allows context-dependent attackers to cause a denial of service (crash) via unknown manipulations that trigger a divide-by-zero error.

    Published: 5 Feb 2010
    9.3
    Critical

    CVE-2010-2546

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, possibly 3.1.12, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file, related to panpts, pitpts, and IT_ProcessEnvelope. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3995.

    Published: 5 Feb 2010
    9.3
    Critical

    CVE-2010-2971

    Last Modified: 11 Apr 2025

    loaders/load_it.c in libmikmod, possibly 3.1.12, does not properly account for the larger size of name##env relative to name##tick and name##node, which allows remote attackers to trigger a buffer over-read and possibly have unspecified other impact via a crafted Impulse Tracker file, a related issue to CVE-2010-2546. NOTE: this issue exists because of an incomplete fix for CVE-2009-3995.

    Published: 5 Feb 2010
    4.6
    Medium

    CVE-2010-0415

    Last Modified: 11 Apr 2025

    The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.

    Published: 5 Feb 2010
    9.3
    Critical

    CVE-2010-0555

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product's use of text/html as the default content type for files that are encountered after a redirection, aka the URLMON sniffing vulnerability, a variant of CVE-2009-1140 and related to CVE-2008-1448.

    Published: 4 Feb 2010
    5
    Medium

    CVE-2010-0549

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Network Controller in Xerox WorkCentre 6400 System Software 060.070.109.11407 through 060.070.109.29510, and Net Controller 060.079.11410 through 060.079.29310, allows remote attackers to access "directory structure" via a crafted PostScript file, aka "Unauthorized Directory Structure Access Vulnerability."

    Published: 4 Feb 2010
    4
    Medium

    CVE-2010-0550

    Last Modified: 11 Apr 2025

    admin.htm in Geo++ GNCASTER 1.4.0.7 and earlier does not properly enforce HTTP Digest Authentication, which allows remote authenticated users to use HTTP Basic Authentication, bypassing intended server policy.

    Published: 4 Feb 2010
    6.5
    Medium

    CVE-2010-0553

    Last Modified: 11 Apr 2025

    Geo++ GNCASTER 1.4.0.7 and earlier allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long NMEA data sentence.

    Published: 4 Feb 2010
    7.5
    High

    CVE-2010-0554

    Last Modified: 11 Apr 2025

    The HTTP Authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier uses the same nonce for all authentication, which allows remote attackers to hijack web sessions or bypass authentication via a replay attack.

    Published: 4 Feb 2010
    7.5
    High

    CVE-2010-0552

    Last Modified: 11 Apr 2025

    Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via multiple requests for a non-existent file using a long URI.

    Published: 4 Feb 2010
    4.3
    Medium

    CVE-2010-0255

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploit code that constructs a reference to a file://127.0.0.1 URL, aka the dynamic OBJECT tag vulnerability, as demonstrated by obtaining the data from an index.dat file, a variant of CVE-2009-1140 and related to CVE-2008-1448.

    Published: 4 Feb 2010
    5
    Medium

    CVE-2010-0548

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the Network Controller and Web Server in Xerox WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, and 5687 allow remote attackers to (1) access mailboxes via unknown vectors that bypass Scan to Mailbox authorization or (2) read device configuration information via via unknown vectors that bypass web server authorization.

    Published: 4 Feb 2010
    5
    Medium

    CVE-2010-0551

    Last Modified: 11 Apr 2025

    HTTP authentication implementation in Geo++ GNCASTER 1.4.0.7 and earlier allows remote attackers to read authentication headers of other users via a large request with an incorrect authentication attempt, which includes sensitive memory in the response. NOTE: this is referred to as a "memory leak" by some sources, but is better characterized as "memory disclosure."

    Published: 4 Feb 2010
    5
    Medium

    CVE-2010-0303

    Last Modified: 11 Apr 2025

    mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash) via a ":help \t" private message to the MemoServ service.

    Published: 4 Feb 2010
    6.8
    Medium

    CVE-2010-0443

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain privileges via unknown vectors.

    Published: 4 Feb 2010
    5.5
    Medium

    CVE-2009-2750

    Last Modified: 11 Apr 2025

    IBM WebSphere Service Registry and Repository (WSRR) 6.3.0 before FP2 does not have the intended configuration properties, which allows remote authenticated users to obtain unspecified data access via a property query.

    Published: 4 Feb 2010
    6.8
    Medium

    CVE-2010-0562

    Last Modified: 11 Apr 2025

    The sdump function in sdump.c in fetchmail 6.3.11, 6.3.12, and 6.3.13, when running in verbose mode on platforms for which char is signed, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an SSL X.509 certificate containing non-printable characters with the high bit set, which triggers a heap-based buffer overflow during escaping.

    Published: 4 Feb 2010
    4.6
    Medium

    CVE-2010-0038

    Last Modified: 11 Apr 2025

    Recovery Mode in Apple iPhone OS 1.0 through 3.1.2, and iPhone OS for iPod touch 1.1 through 3.1.2, allows physically proximate attackers to bypass device locking, and read or modify arbitrary data, via a USB control message that triggers memory corruption.

    Published: 3 Feb 2010
    5
    Medium

    CVE-2010-0295

    Last Modified: 11 Apr 2025

    lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.

    Published: 3 Feb 2010
    5
    Medium

    CVE-2010-0496

    Last Modified: 11 Apr 2025

    FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.

    Published: 3 Feb 2010
    6.2
    Medium

    CVE-2009-4184

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Enterprise Cluster Master Toolkit (ECMT) B.05.00 on HP-UX B.11.23 (11i v2) and HP-UX B.11.31 (11i v3) allows local users to gain access to an Oracle or Sybase database via unknown vectors.

    Published: 3 Feb 2010
    5
    Medium

    CVE-2010-0185

    Last Modified: 11 Apr 2025

    The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.

    Published: 3 Feb 2010
    4.3
    Medium

    CVE-2010-0440

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.

    Published: 3 Feb 2010
    4.9
    Medium

    CVE-2010-0453

    Last Modified: 11 Apr 2025

    The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.

    Published: 3 Feb 2010
    Unknown

    CVE-2010-0499

    Last Modified: 7 Nov 2023

    This candidate is unused by its CNA.

    Published: 3 Feb 2010
    4.9
    Medium

    CVE-2010-0623

    Last Modified: 11 Apr 2025

    The futex_lock_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly manage a certain reference count, which allows local users to cause a denial of service (OOPS) via vectors involving an unmount of an ext3 filesystem.

    Published: 3 Feb 2010
    6.8
    Medium

    CVE-2010-0661

    Last Modified: 11 Apr 2025

    WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.

    Published: 3 Feb 2010