CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2010-4653

    Last Modified: 21 Nov 2024

    An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.

    Published: 21 Jan 2010
    7.8
    High

    CVE-2010-4654

    Last Modified: 21 Nov 2024

    poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.

    Published: 21 Jan 2010
    10
    Critical

    CVE-2009-3999

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2009-4000

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code, via directory traversal sequences in the fileName parameter.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2010-0359

    Last Modified: 23 Apr 2026

    Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.

    Published: 20 Jan 2010
    4.3
    Medium

    CVE-2010-0357

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before iFix 24; for WebSphere Portal allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 20 Jan 2010
    8.8
    High

    CVE-2010-0037

    Last Modified: 23 Apr 2026

    Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted DNG image.

    Published: 20 Jan 2010
    7.8
    High

    CVE-2010-0036

    Last Modified: 23 Apr 2026

    Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP4 audio file.

    Published: 20 Jan 2010
    2.6
    Low

    CVE-2010-0363

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in Zeus Web Server before 4.3r5, when SSL is enabled for the admin server, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2002-1785.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2010-0358

    Last Modified: 23 Apr 2026

    Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2010-0360

    Last Modified: 23 Apr 2026

    Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malformed HTTP TRACE request that includes a long URI and many empty headers, related to an "overflow." NOTE: this might overlap CVE-2010-0272 and CVE-2010-0273.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2010-0361

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.

    Published: 20 Jan 2010
    5
    Medium

    CVE-2010-0362

    Last Modified: 23 Apr 2026

    Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.

    Published: 20 Jan 2010
    6.8
    Medium

    CVE-2009-2624

    Last Modified: 11 Apr 2025

    The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334 regression.

    Published: 20 Jan 2010
    6.8
    Medium

    CVE-2010-0001

    Last Modified: 11 Apr 2025

    Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index error.

    Published: 20 Jan 2010
    10
    Critical

    CVE-2009-3739

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors.

    Published: 19 Jan 2010
    1.9
    Low

    CVE-2009-3556

    Last Modified: 11 Apr 2025

    A certain Red Hat configuration step for the qla2xxx driver in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5, when N_Port ID Virtualization (NPIV) hardware is used, sets world-writable permissions for the (1) vport_create and (2) vport_delete files under /sys/class/scsi_host/, which allows local users to make arbitrary changes to SCSI host attributes by modifying these files.

    Published: 19 Jan 2010
    9.3
    Critical

    CVE-2009-4246

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows user-assisted remote attackers to execute arbitrary code via a malformed .RJS skin file that contains a web.xmb file with crafted length values.

    Published: 19 Jan 2010
    4.3
    Medium

    CVE-2010-0097

    Last Modified: 11 Apr 2025

    ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta does not properly validate DNSSEC (1) NSEC and (2) NSEC3 records, which allows remote attackers to add the Authenticated Data (AD) flag to a forged NXDOMAIN response for an existing domain.

    Published: 19 Jan 2010
    4
    Medium

    CVE-2010-0290

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains (1) CNAME or (2) DNAME records, which do not have the intended validation before caching, aka Bug 20737. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-4022.

    Published: 19 Jan 2010
    7.6
    High

    CVE-2010-0382

    Last Modified: 11 Apr 2025

    ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P5, 9.5 before 9.5.2-P2, 9.6 before 9.6.1-P3, and 9.7.0 beta handles out-of-bailiwick data accompanying a secure response without re-fetching from the original source, which allows remote attackers to have an unspecified impact via a crafted response, aka Bug 20819. NOTE: this vulnerability exists because of a regression during the fix for CVE-2009-4022.

    Published: 19 Jan 2010
    7.5
    High

    CVE-2010-0416

    Last Modified: 11 Apr 2025

    Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.

    Published: 19 Jan 2010
    4.3
    Medium

    CVE-2010-0433

    Last Modified: 11 Apr 2025

    The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via SSL cipher negotiation, as demonstrated by a chroot installation of Dovecot or stunnel without Kerberos configuration files inside the chroot.

    Published: 19 Jan 2010
    5
    Medium

    CVE-2010-0667

    Last Modified: 11 Apr 2025

    MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 19 Jan 2010
    9.3
    Critical

    CVE-2009-4241

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux RealPlayer 10, and Helix Player 10.x allows remote attackers to execute arbitrary code via a file with invalid ASMRuleBook structures that trigger heap memory corruption.

    Published: 19 Jan 2010
    9.3
    Critical

    CVE-2009-4244

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows remote attackers to execute arbitrary code via an SIPR codec field with a small length value that triggers incorrect memory allocation.

    Published: 19 Jan 2010
    7.5
    High

    CVE-2009-4272

    Last Modified: 11 Apr 2025

    A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long. NOTE: this is related to an issue in the Linux kernel before 2.6.31, when the kernel routing cache is disabled, involving an uninitialized pointer and a panic.

    Published: 19 Jan 2010
    7.5
    High

    CVE-2009-4628

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TemplatePlaza.com TPDugg (com_tpdugg) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a tags action to index.php.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4620

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Joomloc (com_joomloc) component 1.0 for Joomla allows remote attackers to execute arbitrary SQL commands via the id parameter in an edit task to index.php.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4619

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Lucy Games (com_lucygames) component 1.5.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the gameid parameter in a game action to index.php. NOTE: some of these details are obtained from third party information.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4614

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Moa Gallery 1.2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the MOA_PATH parameter to (1) _error_funcs.php, (2) _integrity_funcs.php, (3) _template_component_admin.php, (4) _template_component_gallery.php, (5) _template_parser.php, (6) mod_gallery_funcs.php, (7) mod_image_funcs.php, (8) mod_tag_funcs.php, (9) mod_tag_view.php, (10) mod_upgrade_funcs.php, (11) mod_user_funcs.php, (12) page_admin.php, (13) page_gallery_add.php, (14) page_gallery_view.php, (15) page_image_add.php, (16) page_image_view_full.php, (17) page_login.php, and (18) page_sitemap.php in sources/.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4626

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in menu.php in phpNagios 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the conf[lang] parameter.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4618

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.

    Published: 18 Jan 2010
    5
    Medium

    CVE-2009-4627

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in sources/_template_parser.php in Moa Gallery 1.2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the p_filename parameter, a different issue than CVE-2009-4614.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4621

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to forummission.php.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4622

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_news_bot.php in Drunken:Golem Gaming Portal 0.5.1 alpha 2 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter, a different vector than CVE-2007-0572.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4623

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Advanced Comment System 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the ACS_path parameter to (1) index.php and (2) admin.php in advanced_comment_system/. NOTE: this might only be a vulnerability when the administrator has not followed installation instructions in install.php. NOTE: this might be the same as CVE-2020-35598.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4624

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands via the cat_id parameter, a different vector than CVE-2005-3843.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4625

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the updateOnePage function in components/com_bfsurvey_pro/controller.php in BF Survey Pro Free (com_bfsurvey_profree) 1.2.4, and other versions before 1.2.6, a component for Joomla!, allows remote attackers to execute arbitrary SQL commands via the table parameter in an updateOnePage action to index.php.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4617

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Tourism Script Accommodation Hotel Booking Portal Script allow remote attackers to execute arbitrary SQL commands via the hotel_id parameter to (1) hotel.php, (2) details.php, (3) roomtypes.php, (4) photos.php, (5) map.php, (6) weather.php, (7) reviews.php, and (8) book.php.

    Published: 18 Jan 2010
    4.3
    Medium

    CVE-2009-4616

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.

    Published: 18 Jan 2010
    7.5
    High

    CVE-2009-4615

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in review.php in MYRE Holiday Rental Manager allows remote attackers to execute arbitrary SQL commands via the link_id parameter in a show_review action.

    Published: 18 Jan 2010
    9.3
    Critical

    CVE-2010-0356

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method.

    Published: 18 Jan 2010
    5
    Medium

    CVE-2010-0287

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.

    Published: 17 Jan 2010
    7.5
    High

    CVE-2010-0288

    Last Modified: 11 Apr 2025

    A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

    Published: 17 Jan 2010
    6.8
    Medium

    CVE-2010-0289

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25c allow remote attackers to hijack the authentication of administrators for requests that modify access control rules, and other unspecified requests, via unknown vectors.

    Published: 17 Jan 2010
    4.3
    Medium

    CVE-2010-0349

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: this issue could not be reproduced by the vendor, but a patch was provided anyway. The original researcher is reliable.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0350

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Photo Book (goof_fotoboek) extension 1.7.14 and earlier for TYPO3 has unknown impact and remote attack vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0345

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Majordomo extension 1.1.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0344

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the zak_store_management extension 1.0.0 and earlier TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010