CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2010-0472

    Last Modified: 11 Apr 2025

    kuddb2 in Tivoli Monitoring for DB2, as distributed in IBM DB2 9.7 FP1 on Linux, allows remote attackers to cause a denial of service (daemon crash) via a certain byte sequence.

    Published: 2 Feb 2010
    7.5
    High

    CVE-2010-0469

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Files2Links F2L 3000 appliance 4.0.0, and possibly other versions and models, allows remote attackers to execute arbitrary SQL commands via unspecified parameters to the login page.

    Published: 2 Feb 2010
    4.3
    Medium

    CVE-2010-0470

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in scvrtsrv.cmd in Comtrend CT-507IT ADSL Router allows remote attackers to inject arbitrary web script or HTML via the srvName parameter.

    Published: 2 Feb 2010
    7.5
    High

    CVE-2010-0471

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the comment submission interface (includes/comment.php) in Enano CMS before 1.0.6pl1 allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

    Published: 2 Feb 2010
    4.3
    Medium

    CVE-2010-0468

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.

    Published: 2 Feb 2010
    5.8
    Medium

    CVE-2010-0467

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the ccNewsletter (com_ccnewsletter) component 1.0.5 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter in a ccnewsletter action to index.php.

    Published: 2 Feb 2010
    4.3
    Medium

    CVE-2009-3035

    Last Modified: 11 Apr 2025

    The web console in Symantec Altiris Notification Server 6.0.x before 6.0 SP3 R12 uses a hardcoded key that can decrypt SQL Server credentials and certain discovery credentials, and stores this key on the Notification Server machine, which allows local users to obtain sensitive information and possibly execute arbitrary code by decrypting and using these credentials.

    Published: 2 Feb 2010
    9.8
    Critical

    CVE-2009-4013

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.

    Published: 2 Feb 2010
    7.5
    High

    CVE-2009-4014

    Last Modified: 11 Apr 2025

    Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.

    Published: 2 Feb 2010
    7.5
    High

    CVE-2009-4015

    Last Modified: 11 Apr 2025

    Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.

    Published: 2 Feb 2010
    4.9
    Medium

    CVE-2010-0410

    Last Modified: 11 Apr 2025

    drivers/connector/connector.c in the Linux kernel before 2.6.32.8 allows local users to cause a denial of service (memory consumption and system crash) by sending the kernel many NETLINK_CONNECTOR messages.

    Published: 2 Feb 2010
    5
    Medium

    CVE-2010-0441

    Last Modified: 11 Apr 2025

    Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.

    Published: 2 Feb 2010
    2.1
    Low

    CVE-2010-0622

    Last Modified: 11 Apr 2025

    The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local users to cause a denial of service (OOPS) and possibly have unspecified other impact via vectors involving modification of the futex value from user space.

    Published: 2 Feb 2010
    6.8
    Medium

    CVE-2010-0668

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.

    Published: 1 Feb 2010
    7.5
    High

    CVE-2010-0669

    Last Modified: 11 Apr 2025

    MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.

    Published: 1 Feb 2010
    7.5
    High

    CVE-2010-0717

    Last Modified: 11 Apr 2025

    The default configuration of cfg.packagepages_actions_excluded in MoinMoin before 1.8.7 does not prevent unsafe package actions, which has unspecified impact and attack vectors.

    Published: 1 Feb 2010
    9.3
    Critical

    CVE-2010-1028

    Last Modified: 11 Apr 2025

    Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

    Published: 1 Feb 2010
    7.5
    High

    CVE-2010-0409

    Last Modified: 11 Apr 2025

    Buffer overflow in the GMIME_UUENCODE_LEN macro in gmime/gmime-encodings.h in GMime before 2.4.15 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via input data for a uuencode operation.

    Published: 31 Jan 2010
    5
    Medium

    CVE-2010-0004

    Last Modified: 11 Apr 2025

    ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.

    Published: 29 Jan 2010
    7.5
    High

    CVE-2010-0005

    Last Modified: 11 Apr 2025

    query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.

    Published: 29 Jan 2010
    4.9
    Medium

    CVE-2010-0411

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

    Published: 29 Jan 2010
    7.5
    High

    CVE-2010-0634

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Fast Lexical Analyzer Generator (flex) before 2.5.35 has unknown impact and attack vectors.

    Published: 29 Jan 2010
    7.5
    High

    CVE-2005-4885

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on certain Sun StorEdge 6130 (SE6130) Controller Arrays allows remote attackers to delete data via unknown vectors.

    Published: 28 Jan 2010
    4.6
    Medium

    CVE-2009-4183

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP OpenView Storage Data Protector 6.00 and 6.10 allows local users to obtain unspecified "access" via unknown vectors.

    Published: 28 Jan 2010
    9
    Critical

    CVE-2010-0139

    Last Modified: 11 Apr 2025

    Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.2, and possibly 5 does not properly validate SQL commands, which allows remote attackers to create, modify, or delete data in a database via unspecified vectors, aka Bug ID CSCtc39691.

    Published: 28 Jan 2010
    10
    Critical

    CVE-2010-0140

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the web server in Cisco Unified MeetingPlace 7 before 7.0(2.3) hotfix 5F, 6 before 6.0.639.3, and possibly 5 allow remote attackers to create (1) user or (2) administrator accounts via a crafted URL in a request to the internal interface, aka Bug IDs CSCtc59231 and CSCtd40661.

    Published: 28 Jan 2010
    6.4
    Medium

    CVE-2010-0141

    Last Modified: 11 Apr 2025

    MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote attackers to discover usernames, passwords, and unspecified other data from the user database via a modified authentication sequence to the Audio Server, aka Bug ID CSCsv76935.

    Published: 28 Jan 2010
    8.5
    High

    CVE-2010-0142

    Last Modified: 11 Apr 2025

    MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentication sequence, aka Bug ID CSCsv66530.

    Published: 28 Jan 2010
    7.5
    High

    CVE-2010-0454

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cgi/cgilua.exe/sys/start.htm in Publique! 2.3 allows remote attackers to execute arbitrary SQL commands via the sid parameter.

    Published: 28 Jan 2010
    4.3
    Medium

    CVE-2010-0455

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in forum/viewtopic.php in PunBB 1.3 allows remote attackers to inject arbitrary web script or HTML via the pid parameter.

    Published: 28 Jan 2010
    7.5
    High

    CVE-2010-0456

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php.

    Published: 28 Jan 2010
    6.5
    Medium

    CVE-2010-0461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php.

    Published: 28 Jan 2010
    4.3
    Medium

    CVE-2004-2765

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via a crafted e-mail message, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

    Published: 28 Jan 2010
    7.5
    High

    CVE-2010-0459

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Published: 28 Jan 2010
    4.3
    Medium

    CVE-2004-2766

    Last Modified: 11 Apr 2025

    Webmail in Sun ONE Messaging Server 6.1 and iPlanet Messaging Server 5.2 before 5.2hf2.02 allows remote attackers to obtain unspecified "access" to e-mail via a crafted e-mail message, related to a "session hijacking" issue, a different vulnerability than CVE-2005-2022 and CVE-2006-5486.

    Published: 28 Jan 2010
    4.6
    Medium

    CVE-2003-1575

    Last Modified: 11 Apr 2025

    VERITAS File System (VxFS) 3.3.3, 3.4, and 3.5 before MP1 Rolling Patch 02 for Sun Solaris 2.5.1 through 9 does not properly implement inheritance of default ACLs in certain circumstances related to the characteristics of a directory inode, which allows local users to bypass intended file permissions by accessing a file on a VxFS filesystem.

    Published: 28 Jan 2010
    10
    Critical

    CVE-2003-1576

    Last Modified: 11 Apr 2025

    Buffer overflow in pamverifier in Change Manager (CM) 1.0 for Sun Management Center (SunMC) 3.0 on Solaris 8 and 9 on the sparc platform allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 28 Jan 2010
    3.5
    Low

    CVE-2010-0460

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in staff/index.php in Kayako SupportSuite 3.60.04 and earlier allow remote authenticated users to inject arbitrary web script or HTML via the (1) subject parameter and (2) contents parameter (aka body) in an insertquestion action. NOTE: some of these details are obtained from third party information.

    Published: 28 Jan 2010
    6.5
    Medium

    CVE-2010-0462

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows remote authenticated users to have an unspecified impact via a SELECT statement that has a long column name generated with the REPEAT function.

    Published: 28 Jan 2010
    7.5
    High

    CVE-2010-0457

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 28 Jan 2010
    7.5
    High

    CVE-2010-0458

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to index.php and the (2) note parameter to blog.php.

    Published: 28 Jan 2010
    5
    Medium

    CVE-2010-0305

    Last Modified: 11 Apr 2025

    ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service (daemon crash) via a large number of c2s (aka client2server) messages that trigger a queue overload.

    Published: 28 Jan 2010
    4.7
    Medium

    CVE-2010-0307

    Last Modified: 11 Apr 2025

    The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.

    Published: 28 Jan 2010
    6.8
    Medium

    CVE-2010-0010

    Last Modified: 11 Apr 2025

    Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow.

    Published: 27 Jan 2010
    7.5
    High

    CVE-2010-0304

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.

    Published: 27 Jan 2010
    6.5
    Medium

    CVE-2010-0442

    Last Modified: 11 Apr 2025

    The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

    Published: 27 Jan 2010
    4.3
    Medium

    CVE-2010-5110

    Last Modified: 12 Apr 2025

    DCTStream.cc in Poppler before 0.13.3 allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

    Published: 27 Jan 2010
    6.8
    Medium

    CVE-2009-4016

    Last Modified: 11 Apr 2025

    Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.

    Published: 27 Jan 2010
    5
    Medium

    CVE-2010-0300

    Last Modified: 11 Apr 2025

    cache.c in ircd-ratbox before 2.2.9 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a HELP command.

    Published: 27 Jan 2010
    6.8
    Medium

    CVE-2010-0390

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.

    Published: 26 Jan 2010