|
310751
|
9.8 |
CRITICAL
Network
|
google webkitgtk fedoraproject
|
chrome webkitgtk fedora
|
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a …
|
NVD-CWE-noinfo
|
CVE-2010-4204
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310752
|
9.8 |
CRITICAL
Network
|
google webmproject redhat
|
chrome libvpx enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
WebM libvpx (aka the VP8 Codec SDK) before 0.9.5, as used in Google Chrome before 7.0.517.44, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary co…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2010-4203
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310753
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2010-4202
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310754
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Use-after-free vulnerability in Google Chrome before 7.0.517.44 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text control selec…
|
CWE-416
Use After Free
|
CVE-2010-4201
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310755
|
8.8 |
HIGH
Network
|
google debian
|
chrome debian_linux
|
Google Chrome before 7.0.517.44 does not properly perform a cast of an unspecified variable during processing of an SVG use element, which allows remote attackers to cause a denial of service or poss…
|
CWE-20
Improper Input Validation
|
CVE-2010-4199
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310756
|
8.8 |
HIGH
Network
|
google webkitgtk fedoraproject
|
chrome webkitgtk fedora
|
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (…
|
CWE-20
Improper Input Validation
|
CVE-2010-4198
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310757
|
9.8 |
CRITICAL
Network
|
google webkitgtk fedoraproject
|
chrome webkitgtk fedora
|
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have u…
|
CWE-416
Use After Free
|
CVE-2010-4197
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310758
|
6.9 |
MEDIUM
|
gnome
|
tomboy
|
The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse…
|
CWE-94
Code Injection
|
CVE-2010-4005
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310759
|
4.6 |
MEDIUM
|
gromacs
|
gromacs
|
GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current workin…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4001
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310760
|
6.9 |
MEDIUM
|
gnome
|
gnome-shell
|
gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working dire…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4000
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310761
|
6.9 |
MEDIUM
|
banshee-project
|
banshee
|
The (1) banshee-1 and (2) muinshee scripts in Banshee 1.8.0 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse share…
|
NVD-CWE-Other
|
CVE-2010-3998
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310762
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
Use-after-free vulnerability in an unspecified compatibility component in Adobe Shockwave Player before 11.5.9.620 allows user-assisted remote attackers to execute arbitrary code via a crafted web si…
|
CWE-399
Resource Management Errors
|
CVE-2010-4092
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310763
|
7.5 |
HIGH
|
onlinetechtools.com
|
oasys_professional
|
SQL injection vulnerability in process.asp in OnlineTechTools Online Work Order System (OWOS) Professional Edition 2.10 allows remote attackers to execute arbitrary SQL commands via the password para…
|
CWE-89
SQL Injection
|
CVE-2010-4186
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310764
|
7.5 |
HIGH
|
energine
|
energine
|
SQL injection vulnerability in index.php in Energine, possibly 2.3.8 and earlier, allows remote attackers to execute arbitrary SQL commands via the NRGNSID cookie.
|
CWE-89
SQL Injection
|
CVE-2010-4185
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310765
|
5.0 |
MEDIUM
|
netsupportsoftware
|
netsupport_manager
|
NetSupport Manager (NSM) before 11.00.0005 sends HTTP headers with cleartext fields containing details about client machines, which allows remote attackers to obtain potentially sensitive information…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4184
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310766
|
4.3 |
MEDIUM
|
htmlpurifier
|
htmlpurifier
|
Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) back…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4183
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310767
|
6.9 |
MEDIUM
|
gnucash
|
gnucash
|
gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current wor…
|
NVD-CWE-Other
|
CVE-2010-3999
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310768
|
6.9 |
MEDIUM
|
cstr
|
festival
|
festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gai…
|
NVD-CWE-Other
|
CVE-2010-3996
|
2024-11-21 10:20 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310769
|
9.3 |
HIGH
|
microsoft
|
windows_xp windows_7 windows_vista windows_server_2003
|
Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Busine…
|
NVD-CWE-Other
|
CVE-2010-4182
|
2024-11-21 10:20 |
2010-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310770
|
5.0 |
MEDIUM
|
yaws
|
yaws
|
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequences.
|
CWE-22
Path Traversal
|
CVE-2010-4181
|
2024-11-21 10:20 |
2010-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310771
|
4.3 |
MEDIUM
|
exv2
|
exv2
|
Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/caferss/example.php and t…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4155
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310772
|
9.3 |
HIGH
|
rhinosoft
|
ftp_voyager
|
Directory traversal vulnerability in Rhino Software, Inc. FTP Voyager 15.2.0.11, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
|
CWE-22
Path Traversal
|
CVE-2010-4154
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310773
|
9.3 |
HIGH
|
crossftp
|
crossftp_pro
|
Directory traversal vulnerability in CrossFTP Pro 1.65a, and probably earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
|
CWE-22
Path Traversal
|
CVE-2010-4153
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310774
|
7.5 |
HIGH
|
4site
|
4site_cms
|
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the cat parameter. NOTE: the i and th vectors…
|
CWE-89
SQL Injection
|
CVE-2010-4152
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310775
|
6.8 |
MEDIUM
|
deluxebb
|
deluxebb
|
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat para…
|
CWE-89
SQL Injection
|
CVE-2010-4151
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310776
|
7.5 |
HIGH
|
wsnlinks wsn
|
wsn_links links
|
Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1)…
|
CWE-89
SQL Injection
|
CVE-2010-4006
|
2024-11-21 10:20 |
2010-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310777
|
4.3 |
MEDIUM
|
deliciousdays
|
cforms
|
Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1)…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3977
|
2024-11-21 10:20 |
2010-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310778
|
10.0 |
HIGH
|
realflex
|
realwin
|
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SC…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4142
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310779
|
6.8 |
MEDIUM
|
hp
|
insight_control_for_linux
|
Cross-site request forgery (CSRF) vulnerability in HP Insight Control for Linux before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2010-4106
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310780
|
6.4 |
MEDIUM
|
hp
|
insight_orchestration
|
Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to bypass intended access restrictions, and obtain sensitive information or modify data, via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4105
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310781
|
5.0 |
MEDIUM
|
hp
|
insight_orchestration
|
Unspecified vulnerability in HP Insight Orchestration before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4104
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310782
|
5.0 |
MEDIUM
|
hp
|
insight_managed_system_setup_wizard
|
Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4103
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310783
|
5.0 |
MEDIUM
|
hp
|
insight_recovery
|
Unspecified vulnerability in HP Insight Recovery before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4102
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310784
|
4.3 |
MEDIUM
|
hp
|
insight_recovery
|
Cross-site scripting (XSS) vulnerability in HP Insight Recovery before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4101
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310785
|
5.0 |
MEDIUM
|
hp
|
insight_control_performance_management
|
Unspecified vulnerability in HP Insight Control Performance Management before 6.1 update 2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4100
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310786
|
6.8 |
MEDIUM
|
hp
|
insight_control_performance_management
|
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2010-4032
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310787
|
8.0 |
HIGH
|
hp
|
insight_control_performance_management
|
Unspecified vulnerability in HP Insight Control Performance Management before 6.2 allows remote authenticated users to gain privileges via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4031
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310788
|
4.3 |
MEDIUM
|
hp
|
insight_control_performance_management
|
Cross-site scripting (XSS) vulnerability in HP Insight Control Performance Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4030
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310789
|
9.3 |
HIGH
|
freshwebmaster
|
fresh_ftp
|
Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE…
|
CWE-22
Path Traversal
|
CVE-2010-4149
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310790
|
9.3 |
HIGH
|
anyconnect
|
anyconnect
|
Directory traversal vulnerability in AnyConnect 1.2.3.0, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename.
|
CWE-22
Path Traversal
|
CVE-2010-4148
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310791
|
7.5 |
HIGH
|
avactis
|
avactis_shopping_cart
|
Multiple SQL injection vulnerabilities in Pentasoft Avactis Shopping Cart 1.9.1 build 8356 free edition and earlier allow remote attackers to execute arbitrary SQL commands via the User-Agent header …
|
CWE-89
SQL Injection
|
CVE-2010-4147
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310792
|
4.3 |
MEDIUM
|
attachmate
|
reflection_for_the_web
|
Cross-site scripting (XSS) vulnerability in Attachmate Reflection for the Web 2008 R2 (builds 10.1.569 and earlier), 2008 R1, and 9.6 and earlier allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4146
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310793
|
5.0 |
MEDIUM
|
aspindir
|
kisisel_radyo_script
|
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4145
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310794
|
7.5 |
HIGH
|
aspindir
|
kisisel_radyo_script
|
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4144
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310795
|
6.8 |
MEDIUM
|
phpcheckz
|
phpcheckz
|
SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-4143
|
2024-11-21 10:20 |
2010-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310796
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4090
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310797
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file containing "duplicated LCSM entries i…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4089
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310798
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with "duplicated references to the s…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4088
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310799
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
IML32.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a .dir file with a crafted mmap record containing…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4087
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310800
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Director (.dir) media file with an inv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4086
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|