|
310801
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4085
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310802
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4084
|
2024-11-21 10:20 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310803
|
7.5 |
HIGH
|
ibm
|
tivoli_provisioning_manager_os_deployment
|
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read datab…
|
CWE-287
Improper Authentication
|
CVE-2010-4121
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310804
|
4.3 |
MEDIUM
|
ibm
|
tivoli_access_manager_for_e-business
|
Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web scr…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4120
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310805
|
7.5 |
HIGH
|
hp
|
storage_essentials
|
Unspecified vulnerability in HP Storage Essentials before 6.3.0, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of servic…
|
NVD-CWE-noinfo
|
CVE-2010-4029
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310806
|
7.5 |
HIGH
|
hp
|
loadrunner_web_tours loadrunner
|
Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data,…
|
NVD-CWE-noinfo
|
CVE-2010-4028
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310807
|
5.6 |
MEDIUM
|
hp
|
palm_webos
|
Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4027
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310808
|
6.2 |
MEDIUM
|
hp
|
palm_webos
|
Unspecified vulnerability in the service API in HP Palm webOS 1.4.1 allows local users to gain privileges by leveraging the ability to perform certain service calls.
|
NVD-CWE-noinfo
|
CVE-2010-4026
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310809
|
9.3 |
HIGH
|
hp
|
palm_webos
|
Unspecified vulnerability in Doc Viewer in HP Palm webOS 1.4.1 allows remote attackers to execute arbitrary code via a crafted document, as demonstrated by a Word document.
|
NVD-CWE-noinfo
|
CVE-2010-4025
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310810
|
6.8 |
MEDIUM
|
hp
|
insight_control_power_management
|
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2010-4024
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310811
|
4.3 |
MEDIUM
|
hp
|
insight_control_power_management
|
Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4023
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310812
|
4.3 |
MEDIUM
|
hp
|
version_control_repository_manager hp
|
Cross-site scripting (XSS) vulnerability in HP Version Control Repository Manager (VCRM) before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3994
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310813
|
6.4 |
MEDIUM
|
hp
|
insight_control_server_migration insight_control_server_migration6.0.1
|
Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to obtain sensitive information or modify data via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3993
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310814
|
9.0 |
HIGH
|
hp
|
insight_control_server_migration insight_control_server_migration6.0.1
|
Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote authenticated users to gain privileges via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3992
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310815
|
4.3 |
MEDIUM
|
hp
|
insight_control_server_migration insight_control_server_migration6.0.1
|
Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3991
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310816
|
5.0 |
MEDIUM
|
hp
|
virtual_server_environment
|
Unspecified vulnerability in HP Virtual Server Environment before 6.2 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3990
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310817
|
6.8 |
MEDIUM
|
hp
|
insight_control_virtual_machine_management
|
Cross-site request forgery (CSRF) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vec…
|
CWE-352
Origin Validation Error
|
CVE-2010-3989
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310818
|
5.0 |
MEDIUM
|
hp
|
insight_control_virtual_machine_management
|
Unspecified vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to bypass intended access restrictions and cause a denial of service via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3988
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310819
|
4.3 |
MEDIUM
|
hp
|
insight_control_virtual_machine_management
|
Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3987
|
2024-11-21 10:20 |
2010-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310820
|
6.8 |
MEDIUM
|
nitrosecurity
|
nitroview_esm_software
|
ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.
|
CWE-20
Improper Input Validation
|
CVE-2010-4099
|
2024-11-21 10:20 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310821
|
5.0 |
MEDIUM
|
monotone
|
monotone
|
monotone before 0.48.1, when configured to allow remote commands, allows remote attackers to cause a denial of service (crash) via an empty argument to the mtn command.
|
NVD-CWE-Other
|
CVE-2010-4098
|
2024-11-21 10:20 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310822
|
4.3 |
MEDIUM
|
avatic
|
aardvark_topsites_php
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Aardvark Topsites PHP 5.2.0 and 5.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) mail, (2) title, (3…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4097
|
2024-11-21 10:20 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310823
|
4.6 |
MEDIUM
|
monkeysphere_project
|
monkeysphere
|
share/ma/keys_for_user in Monkeysphere 0.31 and 0.32 allows local users to execute arbitrary code via unknown manipulations related to the "monkeysphere-authentication keys-for-user" command.
|
CWE-94
Code Injection
|
CVE-2010-4096
|
2024-11-21 10:20 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310824
|
9.3 |
HIGH
|
robo-ftp
|
robo-ftp
|
Directory traversal vulnerability in the FTP client in Serengeti Systems Incorporated Robo-FTP 3.7.3, and probably other versions before 3.7.5, allows remote FTP servers to write arbitrary files via …
|
CWE-22
Path Traversal
|
CVE-2010-4095
|
2024-11-21 10:20 |
2010-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310825
|
4.3 |
MEDIUM
|
hp
|
operations_orchestration
|
Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9.0, when Internet Explorer 6.0 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified …
|
CWE-79
Cross-site Scripting
|
CVE-2010-3985
|
2024-11-21 10:20 |
2010-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310826
|
5.0 |
MEDIUM
|
ibm
|
rational_test_lab_manager rational_quality_manager
|
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN account, which makes it easier for remote attackers to execute arbitrary code by l…
|
CWE-255
Credentials Management
|
CVE-2010-4094
|
2024-11-21 10:20 |
2010-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310827
|
5.0 |
MEDIUM
|
hp
|
virtual_connect_enterprise_manager
|
Unspecified vulnerability in HP Virtual Connect Enterprise Manager (VCEM) 6.0 and 6.1 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3986
|
2024-11-21 10:20 |
2010-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310828
|
10.0 |
HIGH
|
ibm
|
informix_dynamic_server
|
Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before…
|
CWE-189
Numeric Errors
|
CVE-2010-4070
|
2024-11-21 10:20 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310829
|
8.5 |
HIGH
|
ibm
|
informix_dynamic_server
|
Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenti…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4069
|
2024-11-21 10:20 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310830
|
4.9 |
MEDIUM
|
typo3
|
typo3
|
Unspecified vulnerability in the Extension Manager in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allows remote authenticated administrators to read and possibly modify arbi…
|
CWE-20
Improper Input Validation
|
CVE-2010-4068
|
2024-11-21 10:20 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310831
|
5.0 |
MEDIUM
|
ibm
|
soliddb
|
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, whic…
|
CWE-189
Numeric Errors
|
CVE-2010-4057
|
2024-11-21 10:20 |
2010-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310832
|
5.0 |
MEDIUM
|
ibm
|
soliddb
|
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attacke…
|
NVD-CWE-Other
|
CVE-2010-4056
|
2024-11-21 10:20 |
2010-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310833
|
5.0 |
MEDIUM
|
ibm
|
soliddb
|
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denial of service (memory consumption and daemon crash) by connecting to TCP port 13…
|
CWE-399
Resource Management Errors
|
CVE-2010-4055
|
2024-11-21 10:20 |
2010-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310834
|
4.3 |
MEDIUM
|
artifex
|
gpl_ghostscript afpl_ghostscript ghostscript_fonts
|
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data st…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4054
|
2024-11-21 10:20 |
2010-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310835
|
9.0 |
HIGH
|
ibm
|
informix_dynamic_server
|
Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4053
|
2024-11-21 10:20 |
2010-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310836
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 allows remote attackers to cause a denial of service (memory corruption) by referencing an SVG document in an IMG element.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4050
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310837
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 allows remote attackers to cause a denial of service (application crash) via a Flash movie with a transparent Window Mode (aka wmode) property, which is not properly handled during…
|
CWE-20
Improper Input Validation
|
CVE-2010-4049
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310838
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 allows user-assisted remote web servers to cause a denial of service (application crash) by sending a redirect during the saving of a file.
|
CWE-20
Improper Input Validation
|
CVE-2010-4048
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310839
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 does not properly select the security context of JavaScript code associated with an error page, which allows user-assisted remote attackers to conduct cross-site scripting (XSS) at…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4047
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310840
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 does not properly verify the origin of video content, which allows remote attackers to obtain sensitive information by using a video stream as HTML5 canvas content.
|
CWE-200
Information Exposure
|
CVE-2010-4046
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310841
|
9.3 |
HIGH
|
opera
|
opera_browser
|
Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers to spoof the Address Bar, conduct cross-site scrip…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4045
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310842
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 does not ensure that the portion of a URL shown in the Address Bar contains the beginning of the URL, which allows remote attackers to spoof URLs by changing a window's size.
|
CWE-20
Improper Input Validation
|
CVE-2010-4044
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310843
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera before 10.63 does not prevent interpretation of a cross-origin document as a CSS stylesheet when the document lacks a CSS token sequence, which allows remote attackers to obtain sensitive infor…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4043
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310844
|
9.8 |
CRITICAL
Network
|
google opensuse
|
chrome opensuse
|
Google Chrome before 7.0.517.41 does not properly handle element maps, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to "sta…
|
CWE-20
Improper Input Validation
|
CVE-2010-4042
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310845
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unsp…
|
NVD-CWE-noinfo
|
CVE-2010-4041
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310846
|
7.8 |
HIGH
Local
|
google debian opensuse
|
chrome debian_linux opensuse
|
Google Chrome before 7.0.517.41 does not properly handle animated GIF images, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact …
|
CWE-20
Improper Input Validation
|
CVE-2010-4040
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310847
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4039
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310848
|
7.5 |
HIGH
Network
|
google
|
chrome
|
The Web Sockets implementation in Google Chrome before 7.0.517.41 does not properly handle a shutdown action, which allows remote attackers to cause a denial of service (application crash) via unspec…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2010-4038
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310849
|
4.3 |
MEDIUM
|
google
|
chrome
|
Unspecified vulnerability in Google Chrome before 7.0.517.41 allows remote attackers to bypass the pop-up blocker via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4037
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310850
|
6.8 |
MEDIUM
|
google
|
chrome
|
Google Chrome before 7.0.517.41 does not properly handle the unloading of a page, which allows remote attackers to spoof URLs via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2010-4036
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|