10
    Critical

    CVE-2010-4221

    Last Modified: 29 Aug 2017

    Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow remote attackers to execute arbitrary code via vectors involving a TELNET IAC escape character to a (1) FTP or (2) FTPS server.

    Source:Metasploit
    Published:9 Nov 2010
    7.8
    High

    CVE-2010-4210

    Last Modified: 7 Mar 2019

    The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a file system that uses pseudofs.

    Source:Babcia Padlina
    Published:20 Nov 2010
    7.5
    High

    CVE-2010-4186

    Last Modified: 2 Nov 2010

    SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: some of these details are obtained from third party information.

    Source:L0rd CrusAd3r
    Published:5 Nov 2010
    7.5
    High

    CVE-2010-4185

    Last Modified: 18 Dec 2010

    SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the NRGNSID cookie.

    Source:High-Tech Bridge SA
    Published:5 Nov 2010
    5
    Medium

    CVE-2010-4181

    Last Modified: 20 Feb 2017

    Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.

    Source:nitr0us
    Published:4 Nov 2010
    4.3
    Medium

    CVE-2010-4172

    Last Modified: 20 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/JspHelper.java, related to use of untrusted web applications.

    Source:Adam Muntner
    Published:22 Nov 2010
    7.2
    High

    CVE-2010-4170

    Last Modified: 26 Nov 2010

    The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OPTIONS environment variable to specify a malicious configuration file.

    Source:Tavis Ormandy
    Published:17 Nov 2010
    4.9
    Medium

    CVE-2010-4165

    Last Modified: 3 Mar 2011

    The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MAXSEG (aka MSS) values, which allows local users to cause a denial of service (OOPS) via a setsockopt call that specifies a small value, leading to a divide-by-zero error or incorrect use of a signed integer.

    Source:prdelka
    Published:10 Nov 2010
    2.1
    Low

    CVE-2010-4158

    Last Modified: 6 Sept 2016

    The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.

    Source:Dan Rosenberg
    Published:10 Nov 2010
    5
    Medium

    CVE-2010-4156

    Last Modified: 16 Oct 2017

    The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtain potentially sensitive information via a large value of the third parameter (aka the length parameter).

    Source:Mateusz Kocielski
    Published:8 Nov 2010
    7.5
    High

    CVE-2010-4152

    Last Modified: 5 Oct 2014

    SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors are already covered by CVE-2009-0646.

    Source:High-Tech Bridge SA
    Published:3 Nov 2010
    6.8
    Medium

    CVE-2010-4151

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.

    Source:girex
    Published:3 Nov 2010
    5
    Medium

    CVE-2010-4145

    Last Modified: 17 Oct 2010

    Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.

    Source:FuRty
    Published:1 Nov 2010
    7.5
    High

    CVE-2010-4144

    Last Modified: 17 Oct 2010

    SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.

    Source:FuRty
    Published:1 Nov 2010
    6.8
    Medium

    CVE-2010-4143

    Last Modified: 19 Oct 2010

    SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Salvatore Fresta
    Published:1 Nov 2010
    10
    Critical

    CVE-2010-4142

    Last Modified: 27 Oct 2016

    Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.

    Source:Luigi Auriemma
    Published:1 Nov 2010
    4.3
    Medium

    CVE-2010-4120

    Last Modified: 6 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.

    Source:IBM
    Published:28 Oct 2010
    4.3
    Medium

    CVE-2010-4111

    Last Modified: 30 Oct 2014

    Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Richard Brain
    Published:22 Dec 2010
    7.8
    High

    CVE-2010-4107

    Last Modified: 7 Aug 2011

    The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printers, Color LaserJet MFP printers, and LaserJet 4100, 4200, 4300, 5100, 8150, and 9000 printers enables PJL commands that use the device's filesystem, which allows remote attackers to read arbitrary files via a command inside a print job, as demonstrated by a directory traversal attack.

    Source:Myo Soe
    Published:17 Nov 2010
    6.8
    Medium

    CVE-2010-4099

    Last Modified: 26 Oct 2010

    ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.

    Source:Filip Palian
    Published:27 Oct 2010
    5
    Medium

    CVE-2010-4094

    Last Modified: 27 Oct 2016

    The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by leveraging access to the manager role. NOTE: this might overlap CVE-2009-3548.

    Source:Metasploit
    Published:26 Oct 2010
    9.3
    Critical

    CVE-2010-4091

    Last Modified: 9 Nov 2010

    The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document that triggers memory corruption, involving the printSeps function. NOTE: some of these details are obtained from third party information.

    Source:scup
    Published:4 Nov 2010
    1.9
    Low

    CVE-2010-4077

    Last Modified: 14 Mar 2011

    The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.

    Source:prdelka
    Published:15 Sept 2010
    1.9
    Low

    CVE-2010-4073

    Last Modified: 6 Dec 2016

    The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users to obtain potentially sensitive information from kernel stack memory via vectors related to the (1) compat_sys_semctl, (2) compat_sys_msgctl, and (3) compat_sys_shmctl functions in ipc/compat.c; and the (4) compat_sys_mq_open and (5) compat_sys_mq_getsetattr functions in ipc/compat_mq.c.

    Source:Jon Oberheide
    Published:6 Oct 2010
    5
    Medium

    CVE-2010-4057

    Last Modified: 16 Oct 2010

    solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.

    Source:Luigi Auriemma
    Published:22 Oct 2010
    5
    Medium

    CVE-2010-4056

    Last Modified: 16 Oct 2010

    solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.

    Source:Luigi Auriemma
    Published:22 Oct 2010
    5
    Medium

    CVE-2010-4055

    Last Modified: 16 Oct 2010

    Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 1315 and sending a packet with many integer fields, which trigger many recursive calls of a certain function.

    Source:Luigi Auriemma
    Published:22 Oct 2010
    5
    Medium

    CVE-2010-4052

    Last Modified: 26 Oct 2014

    Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD.

    Source:Maksymilian Arciemowicz
    Published:7 Dec 2010
    5
    Medium

    CVE-2010-4051

    Last Modified: 7 Jan 2011

    The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit for ProFTPD, related to a "RE_DUP_MAX overflow."

    Source:Maksymilian Arciemowicz
    Published:7 Dec 2010
    7.5
    High

    CVE-2010-4006

    Last Modified: 12 Jul 2015

    Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.

    Source:Mark Stanislav
    Published:3 Nov 2010
    4.3
    Medium

    CVE-2010-3977

    Last Modified: 12 Oct 2014

    Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.

    Source:Wagner Elias
    Published:3 Nov 2010
    9.3
    Critical

    CVE-2010-3973

    Last Modified: 10 Mar 2011

    The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possibly an untrusted pointer dereference, aka "Microsoft WMITools ActiveX Control Vulnerability."

    Source:Metasploit
    Published:23 Dec 2010
    10
    Critical

    CVE-2010-3972

    Last Modified: 24 Jan 2017

    Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information.

    Source:Matthew Bergin
    Published:23 Dec 2010
    9.3
    Critical

    CVE-2010-3971

    Last Modified: 8 Dec 2010

    Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in Microsoft Internet Explorer 6 through 8 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a self-referential @import rule in a stylesheet, aka "CSS Memory Corruption Vulnerability."

    Source:WooYun
    Published:22 Dec 2010
    9.3
    Critical

    CVE-2010-3970

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted .MIC or unspecified Office document containing a thumbnail bitmap with a negative biClrUsed value, as reported by Moti and Xu Hao, aka "Windows Shell Graphics Processing Overrun Vulnerability."

    Source:Metasploit
    Published:22 Dec 2010
    9.3
    Critical

    CVE-2010-3967

    Last Modified: 24 Aug 2010

    Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Movie Maker (MSWMM) file, aka "Insecure Library Loading Vulnerability."

    Source:TheLeader
    Published:16 Dec 2010
    7.5
    High

    CVE-2010-3964

    Last Modified: 31 Jul 2012

    Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."

    Source:Metasploit
    Published:16 Dec 2010
    8.1
    High

    CVE-2010-3962

    Last Modified: 3 Nov 2017

    Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or "Uninitialized Memory Corruption Vulnerability," as exploited in the wild in November 2010.

    Source:anonymous
    Published:5 Nov 2010
    7.2
    High

    CVE-2010-3944

    Last Modified: 17 Dec 2010

    win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability."

    Source:Stefan LE BERRE
    Published:16 Dec 2010
    4.3
    Medium

    CVE-2010-3906

    Last Modified: 17 Sept 2018

    Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) f and (2) fp parameters.

    Source:emgent
    Published:15 Dec 2010
    7.8
    High

    CVE-2010-3904

    Last Modified: 21 May 2018

    The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.

    Source:Metasploit
    Published:19 Oct 2010
    5
    Medium

    CVE-2010-3899

    Last Modified: 9 Nov 2010

    IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of documents.

    Source:Fatih Kilic
    Published:12 Nov 2010
    7.2
    High

    CVE-2010-3895

    Last Modified: 9 Nov 2010

    esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument.

    Source:Fatih Kilic
    Published:12 Nov 2010
    9.3
    Critical

    CVE-2010-3894

    Last Modified: 9 Nov 2010

    Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Enterprise Edition before 8.5 FP6 allows remote attackers to execute arbitrary code via a long password.

    Source:Fatih Kilic
    Published:12 Nov 2010
    7.5
    High

    CVE-2010-3893

    Last Modified: 19 Oct 2014

    The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbitrary administrative actions by leveraging cookie theft, related to a "session impersonation" issue.

    Source:Fatih Kilic
    Published:12 Nov 2010
    6.8
    Medium

    CVE-2010-3891

    Last Modified: 9 Nov 2010

    Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a saveNewUser action.

    Source:Fatih Kilic
    Published:12 Nov 2010
    7.2
    High

    CVE-2010-3888

    Last Modified: 27 Oct 2016

    Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified by Kaspersky Lab researchers and other researchers.

    Source:Metasploit
    Published:8 Oct 2010
    4.3
    Medium

    CVE-2010-3886

    Last Modified: 11 Jul 2010

    The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript and JScript, which allows remote attackers to obtain sensitive information about the heap memory addresses used by an application, as demonstrated by the Internet Explorer 8 application.

    Source:Ruben Santamarta
    Published:8 Oct 2010
    Low

    CVE-2010-3885

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3227. Reason: This candidate is a duplicate of CVE-2010-3227. Notes: All CVE users should reference CVE-2010-3227 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:fl0 fl0w
    Published:8 Oct 2010
    6.8
    Medium

    CVE-2010-3884

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:pratul agrawal
    Published:8 Oct 2010