9.3
    Critical

    CVE-2010-2439

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

    Source:Sid3^effects
    Published:24 Jun 2010
    7.5
    High

    CVE-2010-2438

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.

    Source:Sid3^effects
    Published:24 Jun 2010
    4.3
    Medium

    CVE-2010-2437

    Last Modified: 22 Jul 2014

    Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.

    Source:High-Tech Bridge SA
    Published:24 Jun 2010
    7.5
    High

    CVE-2010-2436

    Last Modified: 22 Jul 2014

    SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

    Source:High-Tech Bridge SA
    Published:24 Jun 2010
    5
    Medium

    CVE-2010-2435

    Last Modified: 12 Nov 2010

    Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.

    Source:Crash
    Published:24 Jun 2010
    4.3
    Medium

    CVE-2010-2433

    Last Modified: 27 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.

    Source:IBM
    Published:23 Jun 2010
    1.9
    Low

    CVE-2010-2387

    Last Modified: 11 Apr 2025

    vicious-extensions/ve-misc.c in GNOME Display Manager (gdm) 2.20.x before 2.20.11, when GDM debug is enabled, logs the user password when it contains invalid UTF8 encoded characters, which might allow local users to gain privileges by reading the information from syslog logs.

    Published:15 Feb 2009
    3.2
    Low

    CVE-2010-2384

    Last Modified: 11 Aug 2014

    Unspecified vulnerability in Oracle Solaris 9 and 10 allows local users to affect confidentiality and integrity via unknown vectors related to Solaris Management Console.

    Source:Frank Stuart
    Published:13 Jul 2010
    3.2
    Low

    CVE-2010-2383

    Last Modified: 11 Aug 2014

    Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality and integrity, related to NFS.

    Source:Frank Stuart
    Published:13 Jul 2010
    3.2
    Low

    CVE-2010-2382

    Last Modified: 11 Aug 2014

    Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows local users to affect confidentiality and integrity via unknown vectors.

    Source:Frank Stuart
    Published:13 Jul 2010
    6.4
    Medium

    CVE-2010-2375

    Last Modified: 11 Aug 2014

    Package/Privilege: Plugins for Apache, Sun and IIS web servers Unspecified vulnerability in the WebLogic Server component in Oracle Fusion Middleware 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality and integrity, related to IIS.

    Source:Timothy D. Morgan
    Published:13 Jul 2010
    4.3
    Medium

    CVE-2010-2370

    Last Modified: 11 Aug 2014

    Unspecified vulnerability in the Oracle Business Process Management component in Oracle Fusion Middleware 5.7 MP3, 6.0 MP5, and 10.3 MP2 allows remote attackers to affect integrity, related to BPM.

    Source:Markot
    Published:13 Jul 2010
    7.5
    High

    CVE-2010-2359

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007-1706.

    Source:ajann
    Published:21 Jun 2010
    5.1
    Medium

    CVE-2010-2358

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path] parameter. NOTE: some of these details are obtained from third party information.

    Source:sh00t0ut
    Published:21 Jun 2010
    7.5
    High

    CVE-2010-2357

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.

    Source:L0rd CrusAd3r
    Published:21 Jun 2010
    4.3
    Medium

    CVE-2010-2356

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.

    Source:Sid3^effects
    Published:21 Jun 2010
    4.3
    Medium

    CVE-2010-2355

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Sid3^effects
    Published:21 Jun 2010
    7.5
    High

    CVE-2010-2354

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.

    Source:Sid3^effects
    Published:21 Jun 2010
    10
    Critical

    CVE-2010-2351

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a long AccountName.

    Source:laurent gaffie
    Published:21 Jun 2010
    5
    Medium

    CVE-2010-2349

    Last Modified: 11 Apr 2025

    H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from third party information.

    Source:fl0 fl0w
    Published:21 Jun 2010
    9.3
    Critical

    CVE-2010-2348

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.

    Source:modpr0be
    Published:21 Jun 2010
    9.3
    Critical

    CVE-2010-2343

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.

    Source:sud0
    Published:21 Jun 2010
    7.5
    High

    CVE-2010-2342

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.

    Source:L0rd CrusAd3r
    Published:21 Jun 2010
    7.5
    High

    CVE-2010-2341

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_dir parameter.

    Source:sh00t0ut
    Published:18 Jun 2010
    6.8
    Medium

    CVE-2010-2340

    Last Modified: 21 Jul 2014

    SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.

    Source:SwEET-DeViL
    Published:18 Jun 2010
    7.5
    High

    CVE-2010-2338

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of these details are obtained from third party information.

    Source:L0rd CrusAd3r
    Published:18 Jun 2010
    5
    Medium

    CVE-2010-2336

    Last Modified: 27 Oct 2016

    index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.

    Source:anT!-Tr0J4n
    Published:18 Jun 2010
    7.5
    High

    CVE-2010-2335

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.

    Source:anT!-Tr0J4n
    Published:18 Jun 2010
    5
    Medium

    CVE-2010-2334

    Last Modified: 27 Oct 2016

    Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. (dot dot) in the download parameter.

    Source:anT!-Tr0J4n
    Published:18 Jun 2010
    5
    Medium

    CVE-2010-2333

    Last Modified: 11 Apr 2025

    LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.

    Source:kingcope
    Published:18 Jun 2010
    5
    Medium

    CVE-2010-2332

    Last Modified: 11 Apr 2025

    Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.

    Source:Nishant Das Patnaik
    Published:18 Jun 2010
    9.3
    Critical

    CVE-2010-2331

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request.

    Source:b0nd
    Published:18 Jun 2010
    9.3
    Critical

    CVE-2010-2330

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.

    Source:m-1-k-3
    Published:18 Jun 2010
    9.3
    Critical

    CVE-2010-2329

    Last Modified: 11 Apr 2025

    Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file.

    Source:blake
    Published:18 Jun 2010
    9.3
    Critical

    CVE-2010-2321

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe InDesign CS3 10.0 allows user-assisted remote attackers to execute arbitrary code via a crafted .indd file.

    Source:LiquidWorm
    Published:18 Jun 2010
    7.5
    High

    CVE-2010-2319

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in IDevSpot TextAds 2.08 allows remote attackers to execute arbitrary SQL commands via the page parameter.

    Source:Sid3^effects
    Published:17 Jun 2010
    7.5
    High

    CVE-2010-2317

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in WmsCms 2.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) search, (2) sbr, (3) pid, (4) sbl, and (5) FilePath parameters to default.asp; and the (6) sbr, (7) pr, and (8) psPrice parameters to printpage.asp.

    Source:Ariko-Security
    Published:17 Jun 2010
    4.3
    Medium

    CVE-2010-2316

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) search, (2) sbr, (3) p, and (4) sbl parameters, different vectors than CVE-2007-3137.

    Source:Ariko-Security
    Published:17 Jun 2010
    7.5
    High

    CVE-2010-2315

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in picturelib.php in SmartISoft phpBazar 2.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cat parameter.

    Source:Sid3^effects
    Published:17 Jun 2010
    6.8
    Medium

    CVE-2010-2314

    Last Modified: 11 Apr 2025

    PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DIR_PLUGINS parameter. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:17 Jun 2010
    6.8
    Medium

    CVE-2010-2313

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:AntiSecurity
    Published:17 Jun 2010
    7.5
    High

    CVE-2010-2312

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.

    Source:Sid3^effects
    Published:16 Jun 2010
    9.3
    Critical

    CVE-2010-2311

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Power Tab Editor 1.7 build 80 allows user-assisted remote attackers to execute arbitrary code via a .ptb file with a long font name.

    Source:sud0
    Published:16 Jun 2010
    5
    Medium

    CVE-2010-2310

    Last Modified: 27 Sept 2016

    SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.

    Source:Nullthreat
    Published:16 Jun 2010
    7.5
    High

    CVE-2010-2309

    Last Modified: 22 Nov 2017

    Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary code via a long GET request.

    Source:d1dn0t
    Published:16 Jun 2010
    5
    Medium

    CVE-2010-2307

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.

    Source:S2 Crew
    Published:16 Jun 2010
    9.3
    Critical

    CVE-2010-2305

    Last Modified: 11 Apr 2025

    Buffer overflow in an ActiveX control in SSHelper.dll for Symantec Sygate Personal Firewall 5.6 build 2808 allows remote attackers to execute arbitrary code via a long third argument to the SetRegString method.

    Source:Lincoln
    Published:16 Jun 2010
    10
    Critical

    CVE-2010-2300

    Last Modified: 1 Feb 2012

    Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to handlers for DOM mutation events, aka rdar problem 7948784. NOTE: this might overlap CVE-2010-1759.

    Source:MJ Keith
    Published:15 Jun 2010
    5.1
    Medium

    CVE-2010-2282

    Last Modified: 20 Jul 2010

    Cross-site request forgery (CSRF) vulnerability in TomatoCMS 2.0.6 allows remote attackers to hijack the authentication of administrators for requests that change the administrative password.

    Source:10n1z3d
    Published:14 Jun 2010
    4.3
    Medium

    CVE-2010-2275

    Last Modified: 24 Nov 2017

    Cross-site scripting (XSS) vulnerability in dijit/tests/_testCommon.js in Dojo Toolkit SDK before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the theme parameter, as demonstrated by an attack against dijit/tests/form/test_Button.html.

    Source:Adam Bixby
    Published:14 Jun 2010