9.3
    Critical

    CVE-2010-0266

    Last Modified: 10 Mar 2011

    Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."

    Source:Metasploit
    Published:14 Jul 2010
    9.3
    Critical

    CVE-2010-0265

    Last Modified: 7 Sept 2010

    Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."

    Source:Abysssec
    Published:10 Mar 2010
    8.8
    High

    CVE-2010-0249

    Last Modified: 10 Mar 2011

    Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

    Source:Metasploit
    Published:15 Jan 2010
    8.1
    High

    CVE-2010-0248

    Last Modified: 22 Mar 2012

    Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."

    Source:Metasploit
    Published:22 Jan 2010
    10
    Critical

    CVE-2010-0239

    Last Modified: 1 Jun 2014

    The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary code via crafted packets, aka "ICMPv6 Router Advertisement Vulnerability."

    Source:Sumit Gwalani
    Published:10 Feb 2010
    7.2
    High

    CVE-2010-0233

    Last Modified: 1 Jun 2014

    Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."

    Source:Tavis Ormandy
    Published:10 Feb 2010
    7.8
    High

    CVE-2010-0232

    Last Modified: 14 Aug 2017

    The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."

    Source:Tavis Ormandy
    Published:21 Jan 2010
    10
    Critical

    CVE-2010-0231

    Last Modified: 1 Nov 2010

    The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not use a sufficient source of entropy, which allows remote attackers to obtain access to files and other SMB resources via a large number of authentication requests, related to server-generated challenges, certain "duplicate values," and spoofing of an authentication token, aka "SMB NTLM Authentication Lack of Entropy Vulnerability."

    Source:Hernan Ochoa
    Published:10 Feb 2010
    10
    Critical

    CVE-2010-0219

    Last Modified: 6 Mar 2011

    Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a crafted web service.

    Source:Metasploit
    Published:18 Oct 2010
    9.8
    Critical

    CVE-2010-0211

    Last Modified: 17 Aug 2014

    The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8 sequences, which triggers a free of an invalid, uninitialized pointer in the slap_mods_free function, as demonstrated using the Codenomicon LDAPv3 test suite.

    Source:Ilkka Mattila
    Published:19 Jul 2010
    7.8
    High

    CVE-2010-0188

    Last Modified: 11 Oct 2012

    Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

    Source:Metasploit
    Published:16 Feb 2010
    4.3
    Medium

    CVE-2010-0187

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.

    Source:Mert SARICA
    Published:11 Feb 2010
    7.6
    High

    CVE-2010-0168

    Last Modified: 18 Jun 2014

    The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

    Source:Josh Soref
    Published:25 Mar 2010
    9.3
    Critical

    CVE-2010-0167

    Last Modified: 18 Jun 2014

    The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

    Source:Bob Clary
    Published:23 Mar 2010
    5.1
    Medium

    CVE-2010-0166

    Last Modified: 18 Jun 2014

    The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

    Source:Jesse Ruderman
    Published:25 Mar 2010
    7.5
    High

    CVE-2010-0158

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in the JoomlaBamboo (JB) Simpla Admin template for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an article action to the com_content component, reachable through index.php. NOTE: the vendor disputes this report, saying: "JoomlaBamboo has investigated this report, and it is incorrect. There is no SQL injection vulnerability involving the id parameter in an article view, and there never was. JoomlaBamboo customers have no reason to be concerned about this report.

    Source:R3d-D3V!L
    Published:6 Jan 2010
    7.5
    High

    CVE-2010-0157

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the Bible Study (com_biblestudy) component 6.1 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter in a studieslist action to index.php.

    Source:FL0RiX
    Published:6 Jan 2010
    7.5
    High

    CVE-2010-0122

    Last Modified: 17 Nov 2016

    Multiple SQL injection vulnerabilities in Employee Timeclock Software 0.99 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to (a) auth.php or (b) login_action.php.

    Source:Secunia Research
    Published:12 Mar 2010
    10
    Critical

    CVE-2010-0108

    Last Modified: 4 Jun 2014

    Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers to execute arbitrary code via a long argument to the SetRemoteComputerName function.

    Source:Alexander Polyakov
    Published:19 Feb 2010
    4.9
    Medium

    CVE-2010-0105

    Last Modified: 11 Apr 2025

    The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.

    Source:Maksymilian Arciemowicz
    Published:27 Apr 2010
    9.3
    Critical

    CVE-2010-0103

    Last Modified: 2 Nov 2017

    UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and execute these programs, via a request to TCP port 7777.

    Source:Metasploit
    Published:9 Mar 2010
    7.5
    High

    CVE-2010-0094

    Last Modified: 6 Mar 2011

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is due to missing privilege checks during deserialization of RMIConnectionImpl objects, which allows remote attackers to call system-level Java functions via the ClassLoader of a constructor that is being deserialized.

    Source:Metasploit
    Published:30 Mar 2010
    10
    Critical

    CVE-2010-0071

    Last Modified: 26 May 2014

    Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.

    Source:Dennis Yurichev
    Published:13 Jan 2010
    8.8
    High

    CVE-2010-0050

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

    Source:Dr_IDE
    Published:11 Mar 2010
    9.3
    Critical

    CVE-2010-0049

    Last Modified: 14 Jun 2014

    Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via HTML elements with right-to-left (RTL) text directionality.

    Source:wushi
    Published:11 Mar 2010
    9.3
    Critical

    CVE-2010-0033

    Last Modified: 10 Mar 2011

    Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint Viewer TextBytesAtom Record Stack Overflow Vulnerability."

    Source:Metasploit
    Published:10 Feb 2010
    9.3
    Critical

    CVE-2010-0028

    Last Modified: 11 Apr 2025

    Integer overflow in Microsoft Paint in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted JPEG (.JPG) file, aka "MS Paint Integer Overflow Vulnerability."

    Source:unsign
    Published:10 Feb 2010
    9.3
    Critical

    CVE-2010-0027

    Last Modified: 28 May 2014

    The URL validation functionality in Microsoft Internet Explorer 5.01, 6, 6 SP1, 7 and 8, and the ShellExecute API function in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, does not properly process input parameters, which allows remote attackers to execute arbitrary local programs via a crafted URL, aka "URL Validation Vulnerability."

    Source:Lostmon Lords
    Published:22 Jan 2010
    9.3
    Critical

    CVE-2010-0017

    Last Modified: 11 Apr 2025

    Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 allows local users to gain privileges, via a crafted SMB Negotiate response, aka "SMB Client Race Condition Vulnerability."

    Source:laurent gaffie
    Published:10 Feb 2010
    7.5
    High

    CVE-2010-0013

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in slp.c in the MSN protocol plugin in libpurple in Pidgin 2.6.4 and Adium 1.3.8 allows remote attackers to read arbitrary files via a .. (dot dot) in an application/x-msnmsgrp2p MSN emoticon (aka custom smiley) request, a related issue to CVE-2004-0122. NOTE: it could be argued that this is resultant from a vulnerability in which an emoticon download request is processed even without a preceding text/x-mms-emoticon message that announced availability of the emoticon.

    Source:Mathieu GASPARD
    Published:27 Dec 2009
    2.1
    Low

    CVE-2010-0002

    Last Modified: 26 May 2014

    The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows local users to send escape sequences to terminal emulators, or hide the existence of a file, via a crafted filename.

    Source:Eric Piel
    Published:14 Jan 2010
    7.3
    High

    CVE-2009-5147

    Last Modified: 20 Apr 2025

    DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

    Published:11 May 2009
    4
    Medium

    CVE-2009-5141

    Last Modified: 9 Jan 2011

    Format string vulnerability in War FTP Daemon (warftpd) 1.82 RC 12 allows remote authenticated users to cause a denial of service (crash) via format string specifiers in a LIST command.

    Source:corelanc0d3r
    Published:1 Apr 2014
    7.5
    High

    CVE-2009-5137

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667.

    Source:zAx
    Published:2 Jan 2014
    5
    Medium

    CVE-2009-5135

    Last Modified: 11 Apr 2025

    The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:SEC Consult
    Published:2 May 2013
    6.8
    Medium

    CVE-2009-5134

    Last Modified: 9 Mar 2018

    Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a text file containing a large string. NOTE: some of these details are obtained from third party information.

    Source:Dr_IDE
    Published:18 Jan 2013
    5
    Medium

    CVE-2009-5114

    Last Modified: 12 May 2015

    Directory traversal vulnerability in wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the DOC parameter.

    Source:MustLive
    Published:19 Mar 2012
    5
    Medium

    CVE-2009-5112

    Last Modified: 11 May 2015

    wgarcmin.cgi in WebGlimpse 2.18.7 and earlier allows remote attackers to obtain the installation path via a crafted request.

    Source:Websecurity
    Published:19 Mar 2012
    9.3
    Critical

    CVE-2009-5109

    Last Modified: 15 Nov 2017

    Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.

    Source:dijital1
    Published:25 Dec 2011
    4.3
    Medium

    CVE-2009-5103

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ATCOM Netvolution 1.0 ASP allows remote attackers to inject arbitrary web script or HTML via the email variable.

    Source:Ellinas
    Published:21 Oct 2011
    7.5
    High

    CVE-2009-5102

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.asp in ATCOM Netvolution 1.0 ASP allows remote attackers to execute arbitrary SQL commands via the bpe_nid parameter.

    Source:Ellinas
    Published:21 Oct 2011
    5.4
    Medium

    CVE-2009-5098

    Last Modified: 11 Apr 2025

    The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception.

    Source:Townsend Harris
    Published:13 Sept 2011
    6.8
    Medium

    CVE-2009-5095

    Last Modified: 5 May 2017

    PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute arbitrary PHP code via a URL in the inc_ordner parameter.

    Source:bd0rk
    Published:9 Sept 2011
    7.5
    High

    CVE-2009-5094

    Last Modified: 13 Feb 2017

    SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.

    Source:Osirys
    Published:9 Sept 2011
    5
    Medium

    CVE-2009-5093

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the start parameter.

    Source:bd0rk
    Published:9 Sept 2011
    7.5
    High

    CVE-2009-5091

    Last Modified: 13 Feb 2017

    SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:JIKO
    Published:9 Sept 2011
    6.8
    Medium

    CVE-2009-5090

    Last Modified: 13 Feb 2017

    SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.

    Source:Osirys
    Published:9 Sept 2011
    4.3
    Medium

    CVE-2009-5089

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.

    Source:nuclear
    Published:9 Sept 2011
    7.5
    High

    CVE-2009-5088

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL commands via the cID parameter.

    Source:nuclear
    Published:9 Sept 2011
    5
    Medium

    CVE-2009-5087

    Last Modified: 13 Feb 2017

    Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.

    Source:Dejan Levaja
    Published:9 Sept 2011