CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2010-0336

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0320

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in submitlink.php in Glitter Central Script allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0319

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0343

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Clan Users List (pb_clanlist) extension 0.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0334

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0326

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Developer log (devlog) extension 2.9.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0335

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Vote rank for news (vote_for_tt_news) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0327

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the KJ: Imagelightbox (kj_imagelightbox2) extension 2.0.0 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2008-2490.

    Published: 15 Jan 2010
    5
    Medium

    CVE-2010-0348

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in C3 Corp. WebCalenderC3 0.32 and earlier allows remote attackers to read arbitrary files via unknown vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0347

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the VD / Geomap (vd_geomap) extension 0.3.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0346

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Tip many friends (mimi_tipfriends) extension 0.0.2 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0329

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the "SQL selection field" and "typoscript."

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0330

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Googlemaps for tt_news (jf_easymaps) extension 1.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0331

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0332

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TV21 Talkshow (tv21_talkshow) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0333

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Helpdesk (mg_help) extension 1.1.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0328

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in the Unit Converter (cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0337

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0338

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0339

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0340

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0341

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0342

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Reports for Job (job_reports) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    5
    Medium

    CVE-2010-0325

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the SB Folderdownload (sb_folderdownload) extension 0.2.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0324

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    7.8
    High

    CVE-2010-0323

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in the Photo Book (goof_fotoboek) extension 1.7.14 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vectors.

    Published: 15 Jan 2010
    7.5
    High

    CVE-2010-0322

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 15 Jan 2010
    4.3
    Medium

    CVE-2010-0321

    Last Modified: 23 Apr 2026

    Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.

    Published: 15 Jan 2010
    6.9
    Medium

    CVE-2010-0318

    Last Modified: 23 Apr 2026

    The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.

    Published: 15 Jan 2010
    7.8
    High

    CVE-2010-0317

    Last Modified: 23 Apr 2026

    Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. NOTE: some of these details are obtained from third party information.

    Published: 15 Jan 2010
    8.8
    High

    CVE-2010-0249

    Last Modified: 20 May 2026

    Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

    Published: 15 Jan 2010
    9.3
    Critical

    CVE-2010-0316

    Last Modified: 23 Apr 2026

    Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SKP file.

    Published: 15 Jan 2010
    9.3
    Critical

    CVE-2010-0280

    Last Modified: 23 Apr 2026

    Array index error in Jan Eric Kyprianidis lib3ds 1.x, as used in Google SketchUp 7.x before 7.1 M2, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted structures in a 3DS file, probably related to mesh.c.

    Published: 15 Jan 2010
    4.9
    Medium

    CVE-2010-1436

    Last Modified: 11 Apr 2025

    gfs2 in the Linux kernel 2.6.18, and possibly other versions, does not properly handle when the gfs2_quota struct occupies two separate pages, which allows local users to cause a denial of service (kernel panic) via certain manipulations that cause an out-of-bounds write, as demonstrated by writing from an ext3 file system to a gfs2 file system.

    Published: 15 Jan 2010
    10
    Critical

    CVE-2008-7251

    Last Modified: 23 Apr 2026

    libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.

    Published: 15 Jan 2010
    10
    Critical

    CVE-2008-7252

    Last Modified: 23 Apr 2026

    libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.

    Published: 15 Jan 2010
    5
    Medium

    CVE-2009-4605

    Last Modified: 23 Apr 2026

    scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which might allow remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

    Published: 15 Jan 2010
    6.8
    Medium

    CVE-2010-0311

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Sun Java System Identity Manager (aka IdM) 8.1.0.5 and 8.1.0.6, when Sun Java System Access Manager, OpenSSO Enterprise 8.0, or IBM Tivoli Access Manager is used, allows remote attackers to obtain administrative access via unknown vectors.

    Published: 14 Jan 2010
    6.8
    Medium

    CVE-2010-0310

    Last Modified: 23 Apr 2026

    Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.

    Published: 14 Jan 2010
    7.5
    High

    CVE-2009-4613

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 14 Jan 2010
    7.2
    High

    CVE-2010-0184

    Last Modified: 23 Apr 2026

    The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.

    Published: 14 Jan 2010
    5
    Medium

    CVE-2010-0312

    Last Modified: 23 Apr 2026

    The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted SecureWay 3.2 Event Registration Request (aka a 1.3.18.0.2.12.1 request).

    Published: 14 Jan 2010
    5
    Medium

    CVE-2010-0315

    Last Modified: 23 Apr 2026

    WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

    Published: 14 Jan 2010
    5
    Medium

    CVE-2010-0314

    Last Modified: 23 Apr 2026

    Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value.

    Published: 14 Jan 2010
    5
    Medium

    CVE-2010-0313

    Last Modified: 23 Apr 2026

    The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.

    Published: 14 Jan 2010
    9
    Critical

    CVE-2009-4182

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in HP Web Jetadmin 10.2, when a remote SQL server is used, allow remote attackers to obtain access to data or cause a denial of service, possibly by leveraging authentication and encryption weaknesses on the SQL server.

    Published: 14 Jan 2010
    2.1
    Low

    CVE-2010-0002

    Last Modified: 23 Apr 2026

    The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.

    Published: 14 Jan 2010
    10
    Critical

    CVE-2009-4012

    Last Modified: 23 Apr 2026

    Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to (1) thbrk/thbrk.c and (2) thwbrk/thwbrk.c. NOTE: some of these details are obtained from third party information.

    Published: 14 Jan 2010
    5
    Medium

    CVE-2009-4489

    Last Modified: 23 Apr 2026

    header.c in Cherokee before 0.99.32 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

    Published: 13 Jan 2010
    5
    Medium

    CVE-2009-4495

    Last Modified: 23 Apr 2026

    Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

    Published: 13 Jan 2010