4.3
    Medium

    CVE-2010-3026

    Last Modified: 5 Aug 2010

    Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests to admin/users/edit that grant administrative privileges.

    Source:High-Tech Bridge SA
    Published:16 Aug 2010
    6.8
    Medium

    CVE-2010-3024

    Last Modified: 19 Aug 2010

    Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly earlier, allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrative password or (2) change the site's configuration.

    Source:High-Tech Bridge SA
    Published:16 Aug 2010
    4.3
    Medium

    CVE-2010-3023

    Last Modified: 26 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) category[description] parameter to user/main/update_category, which is not properly handled by _app/views/categories/index.html.erb; and the (2) setting[site_title] parameter to user/main/update_settings, which is not properly handled by _app/views/settings/_list_settings.rhtml.

    Source:High-Tech Bridge SA
    Published:16 Aug 2010
    7.2
    High

    CVE-2010-3007

    Last Modified: 11 Dec 2012

    Unspecified vulnerability in HP Data Protector Express, and Data Protector Express Single Server Edition (SSE), 3.x before build 56936 and 4.x before build 56906 allows local users to gain privileges or cause a denial of service via unknown vectors.

    Source:Metasploit
    Published:9 Sept 2010
    4.3
    Medium

    CVE-2010-3003

    Last Modified: 7 Sept 2014

    Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Mr Teatime
    Published:10 Sept 2010
    9.3
    Critical

    CVE-2010-3000

    Last Modified: 16 Sept 2010

    Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.

    Source:Abysssec
    Published:30 Aug 2010
    6.9
    Medium

    CVE-2010-2973

    Last Modified: 2 Mar 2018

    Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privileges via vectors involving IOSurface properties, as demonstrated by JailbreakMe.

    Source:jailbreakme
    Published:5 Aug 2010
    Low

    CVE-2010-2972

    Last Modified: 2 Mar 2018

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-1797. Reason: This candidate is a duplicate of CVE-2010-1797. Notes: All CVE users should reference CVE-2010-1797 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:jailbreakme
    Published:5 Aug 2010
    6.2
    Medium

    CVE-2010-2963

    Last Modified: 18 Dec 2010

    drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory locations, and consequently gain privileges, via a VIDIOCSTUNER ioctl call on a /dev/video device, followed by a VIDIOCSMICROCODE ioctl call on this device.

    Source:Kees Cook
    Published:19 Oct 2010
    6.9
    Medium

    CVE-2010-2961

    Last Modified: 12 Nov 2016

    mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain privileges by modifying this file.

    Source:fuzz
    Published:14 Sept 2010
    7.2
    High

    CVE-2010-2959

    Last Modified: 4 Sept 2016

    Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a denial of service (system crash) via crafted CAN traffic.

    Source:Jon Oberheide
    Published:11 Aug 2010
    8.1
    High

    CVE-2010-2943

    Last Modified: 29 Sept 2010

    The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.

    Source:Red Hat
    Published:20 Jun 2010
    4.3
    Medium

    CVE-2010-2939

    Last Modified: 28 Aug 2014

    Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue.

    Source:Georgi Guninski
    Published:7 Aug 2010
    7.5
    High

    CVE-2010-2933

    Last Modified: 1 Nov 2017

    SQL injection vulnerability in AV Scripts AV Arcade 3 allows remote attackers to execute arbitrary SQL commands via the ava_code cookie to the "main page," related to index.php and the login task.

    Source:saudi0hacker
    Published:4 Aug 2010
    9.3
    Critical

    CVE-2010-2932

    Last Modified: 17 Aug 2010

    Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument to the LoadProperties method.

    Source:loneferret
    Published:4 Aug 2010
    9.3
    Critical

    CVE-2010-2931

    Last Modified: 22 Aug 2010

    Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a long eighth argument (HexString) to the LCDWriteString method.

    Source:mr_me
    Published:4 Aug 2010
    7.5
    High

    CVE-2010-2926

    Last Modified: 24 Jul 2010

    SQL injection vulnerability in index.php in sNews 1.7 allows remote attackers to execute arbitrary SQL commands via the category parameter.

    Source:CoBRa_21
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2925

    Last Modified: 26 Jul 2010

    SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL commands via the ecPath parameter.

    Source:**RoAd_KiLlEr**
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2924

    Last Modified: 22 Jul 2010

    SQL injection vulnerability in myLDlinker.php in the myLinksDump Plugin 1.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the url parameter. NOTE: some of these details are obtained from third party information.

    Source:H-SK33PY
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2923

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the YouTube (com_youtube) component 1.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id_cate parameter to index.php.

    Source:Forza-Dz
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2922

    Last Modified: 24 Jul 2010

    SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:v0calist
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2921

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Golf Course Guide (com_golfcourseguide) component 0.9.6.0 beta and 1 beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a golfcourses action to index.php.

    Source:Valentin
    Published:30 Jul 2010
    6.8
    Medium

    CVE-2010-2920

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Foobla Suggestions (com_foobla_suggestions) component 1.5.1.2 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2919

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the StaticXT (com_staticxt) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:Palyo34 & KroNicKq
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2918

    Last Modified: 17 Feb 2014

    PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component 1.1 RC2 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:NoGe
    Published:30 Jul 2010
    4.3
    Medium

    CVE-2010-2917

    Last Modified: 28 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) emailid, (2) fname, (3) lname, (4) company, (5) address1, (6) address2, (7) city, (8) state, (9) zipcode, (10) phone, and (11) fax parameters in an update action. NOTE: some of these details are obtained from third party information.

    Source:Sid3^effects
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2916

    Last Modified: 22 Jul 2010

    SQL injection vulnerability in news.php in AJ Square AJ HYIP MERIDIAN allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JosS
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2915

    Last Modified: 22 Jul 2010

    SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JosS
    Published:30 Jul 2010
    7.5
    High

    CVE-2010-2912

    Last Modified: 20 Jul 2010

    SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the _a parameter in a downloads action.

    Source:ScOrPiOn
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2911

    Last Modified: 20 Jul 2010

    SQL injection vulnerability in index.php in Kayako eSupport 3.70.02 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a viewnews action.

    Source:ScOrPiOn
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2910

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the Ozio Gallery (com_oziogallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the Itemid parameter to index.php.

    Source:ViRuS Qalaa
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2909

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid parameter in a video action to index.php.

    Source:Salvatore Fresta
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2908

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers to execute arbitrary SQL commands via the course_id parameter in a detail action to index.php.

    Source:kaMtiEz
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2907

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the Huru Helpdesk (com_huruhelpdesk) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a detail action to index.php.

    Source:Amine_92
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2906

    Last Modified: 7 Aug 2010

    SQL injection vulnerability in articlesdetails.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2010-2905.

    Source:k4k4shi
    Published:28 Jul 2010
    7.5
    High

    CVE-2010-2905

    Last Modified: 15 Jul 2010

    SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:D4rk357
    Published:28 Jul 2010
    8.5
    High

    CVE-2010-2892

    Last Modified: 11 Nov 2010

    gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

    Source:Aureliano Calvo
    Published:15 Nov 2010
    7.5
    High

    CVE-2010-2891

    Last Modified: 20 Oct 2010

    Buffer overflow in the smiGetNode function in lib/smi.c in libsmi 0.4.8 allows context-dependent attackers to execute arbitrary code via an Object Identifier (aka OID) represented as a numerical string containing many components separated by . (dot) characters.

    Source:Core Security
    Published:20 Oct 2010
    7.3
    High

    CVE-2010-2883

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:8 Sept 2010
    9.3
    Critical

    CVE-2010-2866

    Last Modified: 3 Oct 2010

    Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a count value associated with an "undocumented structure" and the tSAC chunk in a Director movie.

    Source:Abysssec
    Published:26 Aug 2010
    9.3
    Critical

    CVE-2010-2862

    Last Modified: 14 Aug 2010

    Integer overflow in CoolType.dll in Adobe Reader 8.2.3 and 9.3.3, and Acrobat 9.3.3, allows remote attackers to execute arbitrary code via a TrueType font with a large maxCompositePoints value in a Maximum Profile (maxp) table.

    Source:Ramz Afzar
    Published:4 Aug 2010
    9.8
    Critical

    CVE-2010-2861

    Last Modified: 3 Nov 2017

    Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2) logging/settings.cfm, (3) datasources/index.cfm, (4) j2eepackaging/editarchive.cfm, and (5) enter.cfm in CFIDE/administrator/.

    Source:anonymous
    Published:11 Aug 2010
    9.3
    Critical

    CVE-2010-2860

    Last Modified: 3 Aug 2010

    The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the appliance, which allows remote attackers to read, create, or modify arbitrary files in the user data directory via NFS requests.

    Source:Trustwave's SpiderLabs
    Published:4 Aug 2010
    4.3
    Medium

    CVE-2010-2858

    Last Modified: 7 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in news.php in SimpNews 2.47.03 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) layout and (2) sortorder parameters.

    Source:MustLive
    Published:23 Jul 2010
    6.8
    Medium

    CVE-2010-2857

    Last Modified: 3 Nov 2016

    Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.

    Source:Sid3^effects
    Published:23 Jul 2010
    4.3
    Medium

    CVE-2010-2856

    Last Modified: 7 Aug 2014

    Cross-site scripting (XSS) vulnerability in admin/currencies.php in osCSS 1.2.2, and probably earlier versions, allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:High-Tech Bridge SA
    Published:23 Jul 2010
    7.5
    High

    CVE-2010-2853

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in flashPlayer/playVideo.php in iScripts VisualCaster allows remote attackers to execute arbitrary SQL commands via the product_id parameter.

    Source:Sid3^effects
    Published:23 Jul 2010
    6.8
    Medium

    CVE-2010-2850

    Last Modified: 4 Aug 2010

    Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions before 10.07.12, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the dir parameter.

    Source:John Leitch
    Published:23 Jul 2010
    5
    Medium

    CVE-2010-2848

    Last Modified: 15 Dec 2016

    Directory traversal vulnerability in assets/captcha/includes/alikon/playcode.php in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.

    Source:Salvatore Fresta
    Published:23 Jul 2010
    7.5
    High

    CVE-2010-2847

    Last Modified: 15 Dec 2016

    Multiple SQL injection vulnerabilities in the InterJoomla ArtForms (com_artforms) component 2.1b7.2 RC2 for Joomla! allow remote attackers to execute arbitrary SQL commands via the viewform parameter in a (1) ferforms or (2) tferforms action to index.php, and the (3) id parameter in a vferforms action to index.php.

    Source:Salvatore Fresta
    Published:23 Jul 2010