7.5
    High

    CVE-2010-3205

    Last Modified: 28 Aug 2010

    PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the inc parameter.

    Source:Sn!pEr.S!Te
    Published:3 Sept 2010
    7.5
    High

    CVE-2010-3204

    Last Modified: 27 Aug 2010

    Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP code via a URL in the template parameter to (1) post.php, (2) article.php, (3) blog.php, or (4) home.php in pec_templates/nova-blue/.

    Source:eidelweiss
    Published:3 Sept 2010
    5
    Medium

    CVE-2010-3203

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the dflink parameter in a prevsell dwnfree action to index.php.

    Source:Craw
    Published:3 Sept 2010
    4.3
    Medium

    CVE-2010-3202

    Last Modified: 1 Sept 2014

    Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.

    Source:Lostmon
    Published:13 Sept 2010
    4.3
    Medium

    CVE-2010-3201

    Last Modified: 26 Sept 2014

    Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web script or HTML via the username_ex parameter to the surgeweb program.

    Source:Kerem Kocaer
    Published:7 Jan 2011
    9.3
    Critical

    CVE-2010-3189

    Last Modified: 1 Apr 2017

    The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2010 allows remote attackers to execute arbitrary code via an invalid address that is dereferenced as a pointer.

    Source:Trancer
    Published:31 Aug 2010
    10
    Critical

    CVE-2010-3187

    Last Modified: 5 Dec 2016

    Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

    Source:kingcope
    Published:30 Aug 2010
    9.3
    Critical

    CVE-2010-3179

    Last Modified: 5 Oct 2014

    Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a long argument to the document.write method.

    Source:Alexander Miller
    Published:19 Oct 2010
    5.8
    Medium

    CVE-2010-3171

    Last Modified: 11 Sept 2014

    The Math.random function in the JavaScript implementation in Mozilla Firefox 3.5.10 through 3.5.11, 3.6.4 through 3.6.8, and 4.0 Beta1 uses a random number generator that is seeded only once per document object, which makes it easier for remote attackers to track a user, or trick a user into acting upon a spoofed pop-up message, by calculating the seed value, related to a "temporary footprint" and an "in-session phishing attack." NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-5913.

    Source:Amit Klein
    Published:15 Sept 2010
    9.3
    Critical

    CVE-2010-3155

    Last Modified: 25 Sept 2010

    Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jsx file.

    Source:LiquidWorm
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3154

    Last Modified: 25 Sept 2010

    Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .mxi or .mxp file.

    Source:LiquidWorm
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3153

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe InDesign CS4 6.0, InDesign CS5 7.0.2 and earlier, Adobe InDesign Server CS5 7.0.2 and earlier, and Adobe InCopy CS5 7.0.2 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an .indl, .indp, .indt, or .inx file.

    Source:Glafkos Charalambous
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3152

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe Illustrator CS4 14.0.0, CS5 15.0.1 and earlier, and possibly other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or aires.dll that is located in the same folder as an .ait or .eps file.

    Source:Glafkos Charalambous
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3151

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.

    Source:Glafkos Charalambous
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3150

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as a .pproj, .prfpset, .prexport, .prm, .prmp, .prpreset, .prproj, .prsl, .prtl, or .vpr file.

    Source:Glafkos Charalambous
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3149

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe Device Central CS5 3.0.0(376), 3.0.1.0 (3027), and probably other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse qtcf.dll that is located in the same folder as an ADCP file.

    Source:Glafkos Charalambous
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3148

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft Visio 2003 SP3 allows local users to gain privileges via a Trojan horse mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .vsd, .vdx, .vst, or .vtx file, aka "Microsoft Visio Insecure Library Loading Vulnerability."

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3147

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges via a Trojan horse wab32res.dll file in the current working directory, as demonstrated by a directory that contains a Windows Address Book (WAB), VCF (aka vCard), or P7C file, aka "Insecure Library Loading Vulnerability." NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3143.

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3146

    Last Modified: 25 Aug 2010

    Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the current working directory, as demonstrated by a directory that contains a Groove vCard (.vcg) or Groove Tool Archive (.gta) file, aka "Microsoft Groove Insecure Library Loading Vulnerability."

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3145

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working directory, as demonstrated by a directory that contains a Windows Backup Catalog (.wbcat) file, aka "Backup Manager Insecure Library Loading Vulnerability."

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3144

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in the Internet Connection Signup Wizard in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a Trojan horse smmscrpt.dll file in the current working directory, as demonstrated by a directory that contains an ISP or INS file, aka "Internet Connection Signup Wizard Insecure Library Loading Vulnerability."

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3143

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .contact, .group, .p7c, .vcf, or .wab file. NOTE: the codebase for this product may overlap the codebase for the product referenced in CVE-2010-3147.

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3142

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft Office PowerPoint 2007 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse rpawinet.dll that is located in the same folder as a .odp, .pothtml, .potm, .potx, .ppa, .ppam, .pps, .ppt, .ppthtml, .pptm, .pptxml, .pwz, .sldm, .sldx, and .thmx file.

    Source:storm
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3141

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot, .potm, .potx, .ppa, .pps, .ppsm, .ppsx, .ppt, .pptm, .pptx, .pwz, .sldm, or .sldx file.

    Source:storm
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3140

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll that is located in the same folder as an ISP file.

    Source:ALPdaemon
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3139

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse imm.dll that is located in the same folder as a .grp file.

    Source:Beenu Arora
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3138

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Player Classic to a directory that contains a .avi, .mka, .ra, or .ram file, aka "Indeo Codec Insecure Library Loading Vulnerability." NOTE: some of these details are obtained from third party information.

    Source:Encrypt3d.M!nd
    Published:27 Aug 2010
    9.3
    Critical

    CVE-2010-3137

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wnaspi32.dll that is located in the same folder as a .669, .aac, .aiff, .amf, .au, .avr, .b4s, .caf or .cda file.

    Source:LiquidWorm
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3136

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Skype 4.2.0.169 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32.dll that is located in the same folder as a .skype file.

    Source:Glafkos Charalambous
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3135

    Last Modified: 7 Sept 2010

    Untrusted search path vulnerability in Cisco Packet Tracer 5.2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .pkt or .pkz file.

    Source:CCNA
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3134

    Last Modified: 26 Aug 2010

    Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz file.

    Source:LiquidWorm
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3133

    Last Modified: 24 Aug 2010

    Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse airpcap.dll, and possibly other DLLs, that is located in the same folder as a file that automatically launches Wireshark.

    Source:TheLeader
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3132

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mfc90loc.dll or (2) dwmapi.dll that is located in the same folder as a CSS, PHP, ASP, or other file that automatically launches Dreamweaver.

    Source:Glafkos Charalambous
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3131

    Last Modified: 24 Aug 2010

    Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

    Source:Glafkos Charalambous
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3130

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a snag, snagcc, or snagprof file.

    Source:Encrypt3d.M!nd
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3129

    Last Modified: 9 Mar 2018

    Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse plugin_dll.dll, userenv.dll, shfolder.dll, dnsapi.dll, dwmapi.dll, iphlpapi.dll, dhcpcsvc.dll, dhcpcsvc6.dll, or rpcrtremote.dll that is located in the same folder as a .torrent or .btsearch file.

    Source:TheLeader
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3128

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in TeamViewer 5.0.8703 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .tvs or .tvc file.

    Source:Glafkos Charalambous
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3127

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll or Wintab32.dll that is located in the same folder as a PSD or other file that is processed by PhotoShop. NOTE: some of these details are obtained from third party information.

    Source:storm
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3126

    Last Modified: 7 Mar 2019

    Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the same folder as an avast license (.avastlic) file.

    Source:diwr
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3125

    Last Modified: 25 Aug 2010

    Untrusted search path vulnerability in TeamMate Audit Management Software Suite 8.0 patch 2 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc71enu.dll that is located in the same folder as a .tmx file.

    Source:Beenu Arora
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3124

    Last Modified: 15 Nov 2016

    Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .mp3 file.

    Source:Secfence
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-3106

    Last Modified: 21 Sept 2010

    The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.

    Source:Trancer
    Published:23 Aug 2010
    7.8
    High

    CVE-2010-3081

    Last Modified: 28 Nov 2016

    The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt function (aka the MCAST_MSFILTER getsockopt support) to control a certain length value, related to a "stack pointer underflow" issue, as exploited in the wild in September 2010.

    Source:Ac1dB1tCh3z
    Published:15 Sept 2010
    4.3
    Medium

    CVE-2010-3077

    Last Modified: 10 Sept 2014

    Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows remote attackers to inject arbitrary web script or HTML via the subdir parameter.

    Source:Moritz Naumann
    Published:9 Nov 2010
    2.1
    Low

    CVE-2010-3073

    Last Modified: 28 Mar 2019

    SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for randomization of initialization vectors, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.

    Source:Micha Riser
    Published:17 Sept 2010
    4.3
    Medium

    CVE-2010-3070

    Last Modified: 8 Sept 2014

    Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to an arbitrary PHP script that uses NuSOAP classes.

    Source:Bogdan Calin
    Published:31 Aug 2010
    6.8
    Medium

    CVE-2010-3039

    Last Modified: 14 Oct 2014

    /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.

    Source:Knud Erik Hjgaard
    Published:9 Nov 2010
    6.8
    Medium

    CVE-2010-3030

    Last Modified: 5 Aug 2010

    Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative password. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:High-Tech Bridge SA
    Published:17 Aug 2010
    7.5
    High

    CVE-2010-3029

    Last Modified: 8 Aug 2010

    SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote attackers to execute arbitrary SQL commands via the gameday parameter in an overview action.

    Source:garwga
    Published:16 Aug 2010
    7.5
    High

    CVE-2010-3027

    Last Modified: 7 Aug 2010

    SQL injection vulnerability in index.php in Tycoon Baseball Script 1.0.9 allows remote attackers to execute arbitrary SQL commands via the game_id parameter in a game_player action.

    Source:Silic0n
    Published:16 Aug 2010