6.5
    Medium

    CVE-2010-0461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the casino (com_casino) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a (1) category or (2) player action to index.php.

    Source:B-HUNT3|2
    Published:28 Jan 2010
    7.5
    High

    CVE-2010-0459

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Mochigames (com_mochigames) component 0.51 and possibly other versions for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:B-HUNT3|2
    Published:28 Jan 2010
    7.5
    High

    CVE-2010-0458

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in NetArt Media Blog System 1.5 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to index.php and the (2) note parameter to blog.php.

    Source:h4ck3r
    Published:28 Jan 2010
    7.5
    High

    CVE-2010-0457

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in home.php in magic-portal 2.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:alnjm33
    Published:28 Jan 2010
    7.5
    High

    CVE-2010-0456

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the indianpulse Game Server (com_gameserver) component 1.2 for Joomla! allows remote attackers to execute arbitrary SQL commands via the grp parameter in a gameserver action to index.php.

    Source:B-HUNT3|2
    Published:28 Jan 2010
    4.9
    Medium

    CVE-2010-0453

    Last Modified: 28 Jun 2010

    The ucode_ioctl function in intel/io/ucode_drv.c in Sun Solaris 10 and OpenSolaris snv_69 through snv_133, when running on x86 architectures, allows local users to cause a denial of service (panic) via a request with a 0 size value to the UCODE_GET_VERSION IOCTL, which triggers a NULL pointer dereference in the ucode_get_rev function, related to retrieval of the microcode revision.

    Source:Patroklos Argyroudis
    Published:3 Feb 2010
    6.5
    Medium

    CVE-2010-0442

    Last Modified: 29 May 2014

    The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."

    Source:Intevydis
    Published:27 Jan 2010
    4.3
    Medium

    CVE-2010-0440

    Last Modified: 29 May 2014

    Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.

    Source:Matias Pablo Brutti
    Published:3 Feb 2010
    7.8
    High

    CVE-2010-0437

    Last Modified: 6 Sept 2016

    The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.

    Source:Rémi Denis-Courmont
    Published:9 Sept 2008
    4.3
    Medium

    CVE-2010-0432

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the Apache Open For Business Project (aka OFBiz) 09.04 and earlier, as used in Opentaps, Neogia, and Entente Oya, allow remote attackers to inject arbitrary web script or HTML via (1) the productStoreId parameter to control/exportProductListing, (2) the partyId parameter to partymgr/control/viewprofile (aka partymgr/control/login), (3) the start parameter to myportal/control/showPortalPage, (4) an invalid URI beginning with /facility/control/ReceiveReturn (aka /crmsfa/control/ReceiveReturn or /cms/control/ReceiveReturn), (5) the contentId parameter (aka the entityName variable) to ecommerce/control/ViewBlogArticle, (6) the entityName parameter to webtools/control/FindGeneric, or the (7) subject or (8) content parameter to an unspecified component under ecommerce/control/contactus.

    Source:Lucas Apa
    Published:15 Apr 2010
    6.9
    Medium

    CVE-2010-0426

    Last Modified: 11 Apr 2025

    sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the name of an executable file in an arbitrary directory, which allows local users to gain privileges via a crafted executable file, as demonstrated by a file named sudoedit in a user's home directory.

    Published:21 Feb 2010
    10
    Critical

    CVE-2010-0425

    Last Modified: 31 Jan 2017

    modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."

    Source:Brett Gervasoni
    Published:5 Mar 2010
    7.5
    High

    CVE-2010-0416

    Last Modified: 3 Jun 2014

    Buffer overflow in the Unescape function in common/util/hxurl.cpp and player/hxclientkit/src/CHXClientSink.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a URL argument containing a % (percent) character that is not followed by two hex digits.

    Source:gwright
    Published:19 Jan 2010
    4.6
    Medium

    CVE-2010-0415

    Last Modified: 23 Nov 2016

    The do_pages_move function in mm/migrate.c in the Linux kernel before 2.6.33-rc7 does not validate node values, which allows local users to read arbitrary kernel memory locations, cause a denial of service (OOPS), and possibly have unspecified other impact by specifying a node that is not part of the kernel's node set.

    Source:spender
    Published:5 Feb 2010
    4.9
    Medium

    CVE-2010-0411

    Last Modified: 1 Jun 2014

    Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.

    Source:Josh Stone
    Published:29 Jan 2010
    5
    Medium

    CVE-2010-0397

    Last Modified: 14 Jun 2014

    The xmlrpc extension in PHP 5.3.1 does not properly handle a missing methodName element in the first argument to the xmlrpc_decode_request function, which allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) and possibly have unspecified other impact via a crafted argument.

    Source:Auke van Slooten
    Published:12 Mar 2010
    6.8
    Medium

    CVE-2010-0390

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it via a direct request to the file in original/. NOTE: some of these details are obtained from third party information.

    Source:indoushka
    Published:26 Jan 2010
    7.5
    High

    CVE-2010-0388

    Last Modified: 29 May 2014

    Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.

    Source:Intevydis
    Published:25 Jan 2010
    7.5
    High

    CVE-2010-0387

    Last Modified: 28 May 2014

    Multiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long string in an "Authorization: Digest" HTTP header.

    Source:Intevydis
    Published:25 Jan 2010
    5
    Medium

    CVE-2010-0380

    Last Modified: 11 Apr 2025

    install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application settings via a direct request. NOTE: this is only a vulnerability when the administrator does not follow recommendations in the product's installation documentation.

    Source:LionTurk
    Published:22 Jan 2010
    4.3
    Medium

    CVE-2010-0376

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to inject arbitrary web script or HTML via the cat parameter. NOTE: this issue is reportedly resultant from a forced SQL error message that occurs from exploitation of CVE-2010-0375.

    Source:LionTurk
    Published:21 Jan 2010
    7.5
    High

    CVE-2010-0375

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in product_list.php in JCE-Tech PHP Calendars, downloaded 2010-01-11, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:LionTurk
    Published:21 Jan 2010
    4.3
    Medium

    CVE-2010-0374

    Last Modified: 27 May 2014

    Cross-site scripting (XSS) vulnerability in the Marketplace (com_marketplace) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the catid parameter in a show_category action to index.php.

    Source:ViRuSMaN
    Published:21 Jan 2010
    7.5
    High

    CVE-2010-0373

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action to index.php.

    Source:FL0RiX
    Published:21 Jan 2010
    7.5
    High

    CVE-2010-0372

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Articlemanager (com_articlemanager) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the artid parameter in a display action to index.php.

    Source:FL0RiX
    Published:21 Jan 2010
    4.3
    Medium

    CVE-2010-0371

    Last Modified: 20 Jul 2014

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Hitmaaan Gallery 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) gall and (2) levela parameters.

    Source:indoushka
    Published:21 Jan 2010
    Unknown

    CVE-2010-0368

    https://www.exploit-db.com/exploits/33603

    7.5
    High

    CVE-2010-0367

    Last Modified: 20 Jul 2014

    Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a URL in the rowptem[template] parameter to (1) showcasesearch.php and (2) showcase2search.php.

    Source:indoushka
    Published:21 Jan 2010
    6.8
    Medium

    CVE-2010-0366

    Last Modified: 20 Jul 2014

    Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Source:indoushka
    Published:21 Jan 2010
    4.3
    Medium

    CVE-2010-0365

    Last Modified: 20 Jul 2014

    Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via the order parameter.

    Source:indoushka
    Published:21 Jan 2010
    9.3
    Critical

    CVE-2010-0364

    Last Modified: 23 Nov 2016

    Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.

    Source:fl0 fl0w
    Published:21 Jan 2010
    10
    Critical

    CVE-2010-0361

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.

    Source:Metasploit
    Published:20 Jan 2010
    10
    Critical

    CVE-2010-0359

    Last Modified: 27 May 2014

    Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.

    Source:Intevydis
    Published:20 Jan 2010
    9.3
    Critical

    CVE-2010-0356

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom Software Movie Player Pro SDK ActiveX 6.8 allows remote attackers to execute arbitrary code via a long strFontName parameter to the DrawText method.

    Source:shinnai
    Published:18 Jan 2010
    4.3
    Medium

    CVE-2010-0321

    Last Modified: 23 May 2014

    Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.

    Source:Crux
    Published:15 Jan 2010
    4.3
    Medium

    CVE-2010-0319

    Last Modified: 26 May 2014

    Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of these details are obtained from third party information.

    Source:Red-D3v1L
    Published:15 Jan 2010
    7.8
    High

    CVE-2010-0317

    Last Modified: 23 Apr 2026

    Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. NOTE: some of these details are obtained from third party information.

    Source:Francis Provencher
    Published:15 Jan 2010
    5
    Medium

    CVE-2010-0315

    Last Modified: 29 May 2014

    WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

    Source:Cesar Cerrudo
    Published:14 Jan 2010
    5
    Medium

    CVE-2010-0314

    Last Modified: 29 May 2014

    Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value.

    Source:Cesar Cerrudo
    Published:14 Jan 2010
    5
    Medium

    CVE-2010-0313

    Last Modified: 23 May 2014

    The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted LDAP Search Request message.

    Source:Intevydis
    Published:14 Jan 2010
    4.7
    Medium

    CVE-2010-0307

    Last Modified: 30 May 2014

    The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service (system crash) via a 32-bit application that attempts to execute a 64-bit application and then triggers a segmentation fault, as demonstrated by amd64_killer, related to the flush_old_exec function.

    Source:Mathias Krause
    Published:28 Jan 2010
    7.5
    High

    CVE-2010-0304

    Last Modified: 6 Mar 2011

    Multiple buffer overflows in the LWRES dissector in Wireshark 0.9.15 through 1.0.10 and 1.2.0 through 1.2.5 allow remote attackers to cause a denial of service (crash) via a malformed packet, as demonstrated using a stack-based buffer overflow to the dissect_getaddrsbyname_request function.

    Source:Metasploit
    Published:27 Jan 2010
    5
    Medium

    CVE-2010-0303

    Last Modified: 30 May 2014

    mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote attackers to cause a denial of service (daemon crash) via a ":help \t" private message to the MemoServ service.

    Source:Julien Cristau
    Published:4 Feb 2010
    5
    Medium

    CVE-2010-0295

    Last Modified: 1 Jun 2014

    lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.

    Source:Li Ming
    Published:3 Feb 2010
    7.5
    High

    CVE-2010-0288

    Last Modified: 11 Apr 2025

    A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to gain privileges and access closed wikis by editing current ACL statements, as demonstrated in the wild in January 2010.

    Source:IHTeam
    Published:17 Jan 2010
    5
    Medium

    CVE-2010-0287

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.

    Source:IHTeam
    Published:17 Jan 2010
    6.8
    Medium

    CVE-2010-0279

    Last Modified: 23 Apr 2026

    Unrestricted file upload vulnerability in upload.php in BTS-GI Read excel 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory. NOTE: some of these details are obtained from third party information.

    Source:Yozgat.Us
    Published:13 Jan 2010
    4.3
    Medium

    CVE-2010-0278

    Last Modified: 23 Apr 2026

    A certain ActiveX control in msgsc.14.0.8089.726.dll in Microsoft Windows Live Messenger 2009 build 14.0.8089.726 on Windows Vista and Windows 7 allows remote attackers to cause a denial of service (msnmsgr.exe crash) by calling the ViewProfile method with a crafted argument during an MSN Messenger session.

    Source:HACKATTACK IT SECURITY GmbH
    Published:12 Jan 2010
    10
    Critical

    CVE-2010-0270

    Last Modified: 20 Feb 2011

    The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Transaction Vulnerability."

    Source:laurent gaffie
    Published:14 Apr 2010
    10
    Critical

    CVE-2010-0269

    Last Modified: 20 Feb 2011

    The SMB client in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly allocate memory for SMB responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted (1) SMBv1 or (2) SMBv2 response, aka "SMB Client Memory Allocation Vulnerability."

    Source:laurent gaffie
    Published:14 Apr 2010