6.8
    Medium

    CVE-2010-1936

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openComInterne 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1935

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1934

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) categorie.class.php, (2) profil.class.php, (3) collectivite.class.php, (4) ressource.class.php, (5) droit.class.php, (6) utilisateur.class.php, and (7) planning.class.php in obj/.

    Source:cr4wl3r
    Published:12 May 2010
    9.3
    Critical

    CVE-2010-1932

    Last Modified: 25 Oct 2016

    Heap-based buffer overflow in XnView 1.97.4 and possibly earlier allows remote attackers to execute arbitrary code via a MultiBitMap (MBM) file with a Paint Data Section that contains a malformed Encoding field.

    Source:Mauro Olea
    Published:16 Jun 2010
    7.5
    High

    CVE-2010-1931

    Last Modified: 4 Oct 2016

    SQL injection vulnerability in includes/content/cart.inc.php in CubeCart PHP Shopping cart 4.3.4 through 4.3.9 allows remote attackers to execute arbitrary SQL commands via the shipKey parameter to index.php.

    Source:Core Security
    Published:10 Jun 2010
    5
    Medium

    CVE-2010-1930

    Last Modified: 24 Jun 2010

    Off-by-one error in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allows remote attackers to cause a denial of service (daemon crash) via a long tree parameter in a login request to nps/servlet/webacc.

    Source:Core Security Technologies
    Published:28 Jun 2010
    9
    Critical

    CVE-2010-1929

    Last Modified: 24 Jun 2010

    Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll in the Tomcat web server in Novell iManager 2.7, 2.7.3, and 2.7.3 FTF2 allow remote authenticated users to execute arbitrary code via the (1) EnteredClassID or (2) NewClassName parameter to nps/servlet/webacc.

    Source:Core Security Technologies
    Published:28 Jun 2010
    6.8
    Medium

    CVE-2010-1928

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openPlanning 1.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1927

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) bible.class.php, (2) dossier.class.php, (3) service.class.php, (4) collectivite.class.php, (5) droit.class.php, (6) tache.class.php, (7) emetteur.class.php, (8) utilisateur.class.php, (9) courrier.recherche.tab.class.php, and (10) profil.class.php in obj/. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1926

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in openMairie openCourrier 2.02 and 2.03 beta, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069. NOTE: some of these details are obtained from third party information.

    Source:cr4wl3r
    Published:12 May 2010
    7.5
    High

    CVE-2010-1925

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-2817.

    Source:CoBRa_21
    Published:12 May 2010
    7.5
    High

    CVE-2010-1924

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers to execute arbitrary SQL commands via the artikel parameter.

    Source:Easy Laster
    Published:12 May 2010
    7.5
    High

    CVE-2010-1923

    Last Modified: 9 Jul 2014

    SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.

    Source:Easy Laster
    Published:12 May 2010
    7.5
    High

    CVE-2010-1922

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in 29o3 CMS 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the LibDir parameter to (1) lib/page/pageDescriptionObject.php, and (2) layoutHeaderFuncs.php, (3) layoutManager.php, and (4) layoutParser.php in lib/layout/.

    Source:eidelweiss
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1921

    Last Modified: 11 Apr 2025

    Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the path_om parameter to (1) annuaire.class.php, (2) droit.class.php, (3) collectivite.class.php, (4) profil.class.php, (5) direction.class.php, (6) service.class.php, (7) directiongenerale.class.php, and (8) utilisateur.class.php in obj/.

    Source:cr4wl3r
    Published:12 May 2010
    6.8
    Medium

    CVE-2010-1920

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in scr/soustab.php in OpenMairie openAnnuaire 2.00, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the dsn[phptype] parameter, a related issue to CVE-2007-2069.

    Source:cr4wl3r
    Published:12 May 2010
    7.5
    High

    CVE-2010-1918

    Last Modified: 5 Jul 2014

    SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.

    Source:Stefan Esser
    Published:12 May 2010
    4.3
    Medium

    CVE-2010-1905

    Last Modified: 3 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allow remote attackers to inject arbitrary web script or HTML via crafted input to ASP pages, as demonstrated using the backurl parameter to sdccommon/verify/asp/n6plugindestructor.asp.

    Source:Ruben Santamarta
    Published:11 May 2010
    9.3
    Critical

    CVE-2010-1900

    Last Modified: 11 Sept 2010

    Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not properly handle malformed records in a Word file, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, aka "Word Record Parsing Vulnerability."

    Source:Abysssec
    Published:11 Aug 2010
    4.3
    Medium

    CVE-2010-1899

    Last Modified: 1 Oct 2010

    Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0, and 7.5 allows remote attackers to cause a denial of service (daemon outage) via a crafted request, related to asp.dll, aka "IIS Repeated Parameter Request Denial of Service Vulnerability."

    Source:kingcope
    Published:15 Sept 2010
    7.2
    High

    CVE-2010-1897

    Last Modified: 10 Aug 2010

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate pseudo-handle values in callback parameters during window creation, which allows local users to gain privileges via a crafted application, aka "Win32k Window Creation Vulnerability."

    Source:Core Security
    Published:11 Aug 2010
    7.2
    High

    CVE-2010-1894

    Last Modified: 7 Mar 2019

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."

    Source:MJ0011
    Published:11 Aug 2010
    4.6
    Medium

    CVE-2010-1890

    Last Modified: 17 Aug 2010

    The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate ACLs on kernel objects, which allows local users to cause a denial of service (reboot) via a crafted application, aka "Windows Kernel Improper Validation Vulnerability."

    Source:Tavis Ormandy
    Published:11 Aug 2010
    7.8
    High

    CVE-2010-1889

    Last Modified: 17 Aug 2010

    Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, allows local users to gain privileges via a crafted application, related to object initialization during error handling, aka "Windows Kernel Double Free Vulnerability."

    Source:Tavis Ormandy
    Published:11 Aug 2010
    6.8
    Medium

    CVE-2010-1888

    Last Modified: 17 Aug 2010

    Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thread creation, aka "Windows Kernel Data Initialization Vulnerability."

    Source:Tavis Ormandy
    Published:11 Aug 2010
    4.4
    Medium

    CVE-2010-1887

    Last Modified: 17 Aug 2010

    The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 do not properly validate an unspecified system-call argument, which allows local users to cause a denial of service (system hang) via a crafted application, aka "Win32k Bounds Checking Vulnerability."

    Source:Tavis Ormandy
    Published:11 Aug 2010
    9.3
    Critical

    CVE-2010-1885

    Last Modified: 10 Mar 2011

    The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."

    Source:Metasploit
    Published:14 Jun 2010
    7.5
    High

    CVE-2010-1878

    Last Modified: 20 Dec 2016

    Directory traversal vulnerability in the OrgChart (com_orgchart) component 1.0.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

    Source:AntiSecurity
    Published:11 May 2010
    7.5
    High

    CVE-2010-1877

    Last Modified: 19 Dec 2016

    SQL injection vulnerability in the JTM Reseller (com_jtm) component 1.9 Beta for Joomla! allows remote attackers to execute arbitrary SQL commands via the author parameter in a search action to index.php.

    Source:kaMtiEz
    Published:11 May 2010
    7.5
    High

    CVE-2010-1876

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL commands via the maincatid parameter in a showmaincatlanding action.

    Source:v3n0m
    Published:11 May 2010
    7.5
    High

    CVE-2010-1875

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.

    Source:Chip d3 bi0s
    Published:11 May 2010
    7.5
    High

    CVE-2010-1874

    Last Modified: 20 Dec 2016

    SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.

    Source:c4uR
    Published:11 May 2010
    7.5
    High

    CVE-2010-1873

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.

    Source:Chip d3 bi0s
    Published:11 May 2010
    4.3
    Medium

    CVE-2010-1872

    Last Modified: 25 Jun 2014

    Cross-site scripting (XSS) vulnerability in cPlayer.php in FlashCard 2.6.5 and 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

    Source:Valentin
    Published:11 May 2010
    8.8
    High

    CVE-2010-1871

    Last Modified: 6 Apr 2015

    JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

    Source:Metasploit
    Published:27 Jul 2010
    5
    Medium

    CVE-2010-1870

    Last Modified: 19 Aug 2011

    The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fisheye, Crucible, and possibly other products, uses a permissive whitelist, which allows remote attackers to modify server-side context objects and bypass the "#" protection mechanism in ParameterInterceptors via the (1) #context, (2) #_memberAccess, (3) #root, (4) #this, (5) #_typeResolver, (6) #_classResolver, (7) #_traceEvaluations, (8) #_lastEvaluation, (9) #_keepLastEvaluation, and possibly other OGNL context variables, a different vulnerability than CVE-2008-6504.

    Source:Metasploit
    Published:25 Jul 2010
    9.3
    Critical

    CVE-2010-1869

    Last Modified: 18 Jul 2010

    Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.

    Source:Rodrigo Rubira Branco
    Published:11 May 2010
    9.8
    Critical

    CVE-2010-1866

    Last Modified: 29 Jun 2014

    The dechunk filter in PHP 5.3 through 5.3.2, when decoding an HTTP chunked encoding stream, allows context-dependent attackers to cause a denial of service (crash) and possibly trigger memory corruption via a negative chunk size, which bypasses a signed comparison, related to an integer overflow in the chunk size decoder.

    Source:Stefan Esser
    Published:2 May 2010
    6.8
    Medium

    CVE-2010-1859

    Last Modified: 2 Jul 2014

    SQL injection vulnerability in newpost.php in DeluxeBB 1.3 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the membercookie cookie when adding a new thread.

    Source:Stefan Esser
    Published:7 May 2010
    5
    Medium

    CVE-2010-1858

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the controller parameter to index.php.

    Source:Chip d3 bi0s
    Published:7 May 2010
    2.6
    Low

    CVE-2010-1856

    Last Modified: 17 Jun 2014

    Cross-site scripting (XSS) vulnerability in index.php in RepairShop2 1.9.023 Trial, when magic_quotes_gpc is disabled, allows remote attackers to inject arbitrary web script or HTML via the prod parameter in a products.details action.

    Source:kaMtiEz
    Published:7 May 2010
    7.5
    High

    CVE-2010-1855

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in auktion.php in Pay Per Watch & Bid Auktions System allows remote attackers to execute arbitrary SQL commands via the id_auk parameter.

    Source:Easy Laster
    Published:7 May 2010
    7.5
    High

    CVE-2010-1840

    Last Modified: 1 Dec 2010

    Stack-based buffer overflow in the password-validation functionality in Directory Services in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors.

    Source:Rodrigo Rubira
    Published:15 Nov 2010
    9.3
    Critical

    CVE-2010-1818

    Last Modified: 30 Aug 2010

    The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions allows remote attackers to execute arbitrary code via the _Marshaled_pUnk attribute, which triggers unmarshalling of an untrusted pointer.

    Source:Ruben Santamarta
    Published:31 Aug 2010
    6.8
    Medium

    CVE-2010-1813

    Last Modified: 10 Sept 2010

    WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors involving HTML object outlines.

    Source:Jose A. Vazquez
    Published:8 Sept 2010
    9.3
    Critical

    CVE-2010-1807

    Last Modified: 18 Dec 2018

    WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation.

    Source:MJ Keith
    Published:7 Sept 2010
    9.3
    Critical

    CVE-2010-1799

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

    Source:Metasploit
    Published:16 Aug 2010
    9.3
    Critical

    CVE-2010-1797

    Last Modified: 2 Mar 2018

    Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpreter in cff/cffgload.c in FreeType before 2.4.2, as used in Apple iOS before 4.0.2 on the iPhone and iPod touch and before 3.2.2 on the iPad, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted CFF opcodes in embedded fonts in a PDF document, as demonstrated by JailbreakMe. NOTE: some of these details are obtained from third party information.

    Source:jailbreakme
    Published:5 Aug 2010
    9.3
    Critical

    CVE-2010-1759

    Last Modified: 1 Feb 2012

    Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the Node.normalize method.

    Source:MJ Keith
    Published:7 Jun 2010
    4.3
    Medium

    CVE-2010-1748

    Last Modified: 23 Jul 2014

    The cgi_initialize_string function in cgi-bin/var.c in the web interface in CUPS before 1.4.4, as used on Apple Mac OS X 10.5.8, Mac OS X 10.6 before 10.6.4, and other platforms, does not properly handle parameter values containing a % (percent) character without two subsequent hex characters, which allows context-dependent attackers to obtain sensitive information from cupsd process memory via a crafted request, as demonstrated by the (1) /admin?OP=redirect&URL=% and (2) /admin?URL=/admin/&OP=% URIs.

    Source:Luca Carettoni
    Published:14 Jun 2010