CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2010-0391

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Embarcadero Technologies InterBase SMP 2009 9.0.3.437 allow remote attackers to execute arbitrary code via unknown vectors involving crafted packets. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 26 Jan 2010
    9.3
    Critical

    CVE-2010-0392

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in vpnconf.exe in TheGreenBow IPSec VPN Client 4.51.001, 4.65.003, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via a long OpenScriptAfterUp parameter in a policy (.tgb) file, related to "phase 2."

    Published: 26 Jan 2010
    3.3
    Low

    CVE-2010-0789

    Last Modified: 11 Apr 2025

    fusermount in FUSE before 2.7.5, and 2.8.x before 2.8.2, allows local users to unmount an arbitrary FUSE filesystem share via a symlink attack on a mountpoint.

    Published: 26 Jan 2010
    2.1
    Low

    CVE-2010-0547

    Last Modified: 11 Apr 2025

    client/mount.cifs.c in mount.cifs in smbfs in Samba 3.4.5 and earlier does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service (mtab corruption) via a crafted string.

    Published: 26 Jan 2010
    6.5
    Medium

    CVE-2010-0629

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in kadmin/server/server_stubs.c in kadmind in MIT Kerberos 5 (aka krb5) 1.5 through 1.6.3 allows remote authenticated users to cause a denial of service (daemon crash) via a request from a kadmin client that sends an invalid API version number.

    Published: 26 Jan 2010
    4.4
    Medium

    CVE-2010-0787

    Last Modified: 11 Apr 2025

    client/mount.cifs.c in mount.cifs in smbfs in Samba 3.0.22, 3.0.28a, 3.2.3, 3.3.2, 3.4.0, and 3.4.5 allows local users to mount a CIFS share on an arbitrary mountpoint, and gain privileges, via a symlink attack on the mountpoint directory file.

    Published: 26 Jan 2010
    4.4
    Medium

    CVE-2010-0788

    Last Modified: 11 Apr 2025

    ncpfs 2.2.6 allows local users to cause a denial of service, obtain sensitive information, or possibly gain privileges via symlink attacks involving the (1) ncpmount and (2) ncpumount programs.

    Published: 26 Jan 2010
    6.8
    Medium

    CVE-2005-4884

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 10.1.0.4 (10g) allows remote authenticated attackers to affect availability via unknown vectors, aka DB02.

    Published: 25 Jan 2010
    8.1
    High

    CVE-2010-0386

    Last Modified: 28 May 2026

    The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

    Published: 25 Jan 2010
    4.3
    Medium

    CVE-2008-7253

    Last Modified: 11 Apr 2025

    The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

    Published: 25 Jan 2010
    5
    Medium

    CVE-2010-0383

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, uses deprecated identity keys for certain directory authorities, which makes it easier for man-in-the-middle attackers to compromise the anonymity of traffic sources and destinations.

    Published: 25 Jan 2010
    7.5
    High

    CVE-2010-0387

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.

    Published: 25 Jan 2010
    7.5
    High

    CVE-2010-0388

    Last Modified: 11 Apr 2025

    Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.

    Published: 25 Jan 2010
    5
    Medium

    CVE-2010-0389

    Last Modified: 11 Apr 2025

    The admin server in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an HTTP request that lacks a method token.

    Published: 25 Jan 2010
    5
    Medium

    CVE-2010-0385

    Last Modified: 11 Apr 2025

    Tor before 0.2.1.22, and 0.2.2.x before 0.2.2.7-alpha, when functioning as a bridge directory authority, allows remote attackers to obtain sensitive information about bridge identities and bridge descriptors via a dbg-stability.txt directory query.

    Published: 25 Jan 2010
    2.1
    Low

    CVE-2010-0384

    Last Modified: 11 Apr 2025

    Tor 0.2.2.x before 0.2.2.7-alpha, when functioning as a directory mirror, does not prevent logging of the client IP address upon detection of erroneous client behavior, which might make it easier for local users to discover the identities of clients in opportunistic circumstances by reading log files.

    Published: 25 Jan 2010
    5.8
    Medium

    CVE-2009-2693

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.

    Published: 24 Jan 2010
    4.3
    Medium

    CVE-2009-2901

    Last Modified: 11 Apr 2025

    The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.

    Published: 24 Jan 2010
    4.3
    Medium

    CVE-2009-2902

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.

    Published: 24 Jan 2010
    5
    Medium

    CVE-2010-0463

    Last Modified: 11 Apr 2025

    Horde IMP 4.3.6 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

    Published: 23 Jan 2010
    5
    Medium

    CVE-2010-0464

    Last Modified: 11 Apr 2025

    Roundcube 0.3.1 and earlier does not request that the web browser avoid DNS prefetching of domain names contained in e-mail messages, which makes it easier for remote attackers to determine the network location of the webmail user by logging DNS requests.

    Published: 23 Jan 2010
    4.4
    Medium

    CVE-2011-1773

    Last Modified: 11 Apr 2025

    virt-v2v before 0.8.4 does not preserve the VNC console password when converting a guest, which allows local users to bypass the intended VNC authentication by connecting without a password.

    Published: 23 Jan 2010
    9.3
    Critical

    CVE-2010-0244

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-2530 and CVE-2009-2531.

    Published: 22 Jan 2010
    9.3
    Critical

    CVE-2010-0247

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability."

    Published: 22 Jan 2010
    5
    Medium

    CVE-2010-0380

    Last Modified: 11 Apr 2025

    install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

    Published: 22 Jan 2010
    7.5
    High

    CVE-2010-0381

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a show_stats action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 22 Jan 2010
    9.3
    Critical

    CVE-2010-0027

    Last Modified: 11 Apr 2025

    The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."

    Published: 22 Jan 2010
    9.3
    Critical

    CVE-2010-0246

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0245.

    Published: 22 Jan 2010
    9.3
    Critical

    CVE-2010-0245

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671, CVE-2009-3674, and CVE-2010-0246.

    Published: 22 Jan 2010
    8.1
    High

    CVE-2010-0248

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

    Published: 22 Jan 2010
    7.5
    High

    CVE-2010-0230

    Last Modified: 11 Apr 2025

    SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers to bypass intended access restrictions.

    Published: 22 Jan 2010
    9.3
    Critical

    CVE-2010-0379

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and SP3, might allow remote attackers to execute arbitrary code via unspecified vectors that are not related to the use-after-free "Movie Unloading Vulnerability" (CVE-2010-0378). NOTE: due to lack of details, it is not clear whether this overlaps any other CVE item.

    Published: 21 Jan 2010
    8.8
    High

    CVE-2010-0378

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."

    Published: 21 Jan 2010
    7.8
    High

    CVE-2010-0137

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the sshd_child_handler process in the SSH server in Cisco IOS XR 3.4.1 through 3.7.0 allows remote attackers to cause a denial of service (process crash and memory consumption) via a crafted SSH2 packet, aka Bug ID CSCsu10574.

    Published: 21 Jan 2010
    10
    Critical

    CVE-2010-0138

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party component," aka Bug ID CSCsv62350.

    Published: 21 Jan 2010
    4.3
    Medium

    CVE-2010-0371

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gall and (2) levela parameters.

    Published: 21 Jan 2010
    7.5
    High

    CVE-2010-0372

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.

    Published: 21 Jan 2010
    7.5
    High

    CVE-2010-0373

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Published: 21 Jan 2010
    4.3
    Medium

    CVE-2010-0374

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.

    Published: 21 Jan 2010
    7.5
    High

    CVE-2010-0375

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 21 Jan 2010
    4.3
    Medium

    CVE-2010-0376

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: this issue is reportedly resultant from a forced SQL error message that occurs from exploitation of CVE-2010-0375.

    Published: 21 Jan 2010
    3.5
    Low

    CVE-2010-0370

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Node Blocks module 5.x-1.1 and earlier, and 6.x-1.3 and earlier, a module for Drupal, allows remote authenticated users, with permissions to create or edit content and administer blocks, to inject arbitrary web script or HTML via the edit-title parameter (aka block title).

    Published: 21 Jan 2010
    7.5
    High

    CVE-2010-0377

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in modules/arcade/index.php in PHP MySpace Gold Edition 8.0 and 8.10 allows remote attackers to execute arbitrary SQL commands via the gid parameter in a play_game action. NOTE: some of these details are obtained from third party information.

    Published: 21 Jan 2010
    9.3
    Critical

    CVE-2010-0364

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.

    Published: 21 Jan 2010
    4.3
    Medium

    CVE-2010-0365

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via the order parameter.

    Published: 21 Jan 2010
    6.8
    Medium

    CVE-2010-0366

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 21 Jan 2010
    7.5
    High

    CVE-2010-0367

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[template] parameter to (1) showcasesearch.php and (2) showcase2search.php.

    Published: 21 Jan 2010
    9.3
    Critical

    CVE-2009-4002

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.

    Published: 21 Jan 2010
    9.3
    Critical

    CVE-2009-4003

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, leading to a heap-based buffer overflow; and might allow remote attackers to execute arbitrary code via (2) an unspecified 3D block in a Shockwave file, leading to memory corruption; or (3) a crafted 3D model in a Shockwave file, leading to heap memory corruption.

    Published: 21 Jan 2010
    7.8
    High

    CVE-2010-0232

    Last Modified: 22 Apr 2026

    The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."

    Published: 21 Jan 2010