|
310851
|
9.3 |
HIGH
|
google
|
chrome
|
Google Chrome before 7.0.517.41 does not properly perform autofill operations for forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ot…
|
CWE-20
Improper Input Validation
|
CVE-2010-4035
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310852
|
9.3 |
HIGH
|
google
|
chrome
|
Google Chrome before 7.0.517.41 does not properly handle forms, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted …
|
CWE-20
Improper Input Validation
|
CVE-2010-4034
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310853
|
5.0 |
MEDIUM
|
google
|
chrome
|
Google Chrome before 7.0.517.41 does not properly implement the autofill and autocomplete functionality, which allows remote attackers to conduct "profile spamming" attacks via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2010-4033
|
2024-11-21 10:20 |
2010-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310854
|
5.0 |
MEDIUM
|
oracle
|
mojarra
|
Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4007
|
2024-11-21 10:20 |
2010-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310855
|
9.0 |
HIGH
|
sap
|
businessobjects
|
CmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and the Program Login property.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3983
|
2024-11-21 10:20 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310856
|
5.0 |
MEDIUM
|
sap
|
businessobjects
|
SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to trigger TCP connections to arbitrary intranet hosts on any port, and obtain potentially sensitive information about open ports, via th…
|
CWE-200
Information Exposure
|
CVE-2010-3982
|
2024-11-21 10:20 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310857
|
4.3 |
MEDIUM
|
sap
|
businessobjects
|
Cross-site scripting (XSS) vulnerability in SAP BusinessObjects Enterprise XI 3.2 allows remote attackers to inject arbitrary web script or HTML via the ServiceClass field to the Edit Service Paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3981
|
2024-11-21 10:20 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310858
|
4.0 |
MEDIUM
|
sap
|
businessobjects
|
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 does not limit the number of CUIDs that may be requested, which allows remote authenticated users to cause a denial of service via a large numCuids …
|
NVD-CWE-Other
|
CVE-2010-3980
|
2024-11-21 10:20 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310859
|
5.0 |
MEDIUM
|
sap
|
businessobjects
|
Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate …
|
CWE-200
Information Exposure
|
CVE-2010-3979
|
2024-11-21 10:20 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310860
|
7.8 |
HIGH
Local
|
ettercap-project
|
ettercap
|
The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/e…
|
-
|
CVE-2010-3843
|
2024-11-21 10:19 |
2021-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310861
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive information via a crafted web site.
|
CWE-200
Information Exposure
|
CVE-2010-3917
|
2024-11-21 10:19 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310862
|
8.8 |
HIGH
Network
|
obs-server suse
|
obs-server linux_enterprise_server
|
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
|
CWE-863
Incorrect Authorization
|
CVE-2010-3782
|
2024-11-21 10:19 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310863
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_business_rules_management_system
|
JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3857
|
2024-11-21 10:19 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310864
|
8.8 |
HIGH
Network
|
ettercap-project debian
|
ettercap debian_linux
|
An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.
|
CWE-120
Classic Buffer Overflow
|
CVE-2010-3844
|
2024-11-21 10:19 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310865
|
6.1 |
MEDIUM
Network
|
typo3 debian
|
typo3 debian_linux
|
TYPO3 before 4.4.1 allows XSS in the frontend search box.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3674
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310866
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows information disclosure in the mail header of the HTML mailing API.
|
CWE-200
Information Exposure
|
CVE-2010-3673
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310867
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 allows XSS in the textarea view helper in an extbase extension.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3672
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310868
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 is open to a session fixation attack which allows remote attackers to hijack a victim's session.
|
CWE-384
Session Fixation
|
CVE-2010-3671
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310869
|
4.8 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness during generation of a hash with the "forgot password" function.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2010-3670
|
2024-11-21 10:19 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310870
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS and Open Redirection in the frontend login box.
|
CWE-79 CWE-601
Cross-site Scripting Open Redirect
|
CVE-2010-3669
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310871
|
7.5 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secure download feature jumpurl.
|
CWE-74
Injection
|
CVE-2010-3668
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310872
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Spam Abuse in the native form content element.
|
CWE-20
Improper Input Validation
|
CVE-2010-3667
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310873
|
5.3 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains insecure randomness in the uniqid function.
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2010-3666
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310874
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the Extension Manager.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3665
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310875
|
6.5 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Information Disclosure on the backend.
|
CWE-200
Information Exposure
|
CVE-2010-3664
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310876
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value of the variable fileDenyPattern which could allow remote attackers to execute ar…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2010-3663
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310877
|
8.8 |
HIGH
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
|
CWE-89
SQL Injection
|
CVE-2010-3662
|
2024-11-21 10:19 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310878
|
6.1 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Open Redirection on the backend.
|
CWE-601
Open Redirect
|
CVE-2010-3661
|
2024-11-21 10:19 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310879
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows XSS on the backend.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3660
|
2024-11-21 10:19 |
2019-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310880
|
5.4 |
MEDIUM
Network
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 CMS 4.1.x before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4, and 4.4.x before 4.4.1 allow remote authenticated backend users to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3659
|
2024-11-21 10:19 |
2017-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310881
|
9.8 |
CRITICAL
Network
|
apache_authenhook_project
|
apache_authenhook
|
libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.
|
CWE-200
Information Exposure
|
CVE-2010-3845
|
2024-11-21 10:19 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310882
|
6.8 |
MEDIUM
|
ffmpeg mplayerhq
|
ffmpeg mplayer
|
FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a mal…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3908
|
2024-11-21 10:19 |
2011-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310883
|
7.6 |
HIGH
|
microsoft
|
windows_server_2008 windows_xp windows_7 windows_vista windows_server_2003 windows_2003_server
|
fxscover.exe in the Fax Cover Page Editor in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold an…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3974
|
2024-11-21 10:19 |
2011-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310884
|
9.3 |
HIGH
|
microsoft
|
.net_framework
|
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted X…
|
CWE-20
Improper Input Validation
|
CVE-2010-3958
|
2024-11-21 10:19 |
2011-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310885
|
4.3 |
MEDIUM
|
horde
|
groupware dynamic_imp
|
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3693
|
2024-11-21 10:19 |
2011-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310886
|
4.3 |
MEDIUM
|
horde
|
imp groupware
|
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3695
|
2024-11-21 10:19 |
2011-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310887
|
5.0 |
MEDIUM
|
openslp vmware
|
openslp esxi esx
|
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.…
|
NVD-CWE-noinfo
|
CVE-2010-3609
|
2024-11-21 10:19 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310888
|
1.2 |
LOW
|
apache
|
tomcat
|
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write …
|
NVD-CWE-Other
|
CVE-2010-3718
|
2024-11-21 10:19 |
2011-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310889
|
5.0 |
MEDIUM
|
modxcms
|
evolution
|
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE…
|
CWE-22
Path Traversal
|
CVE-2010-3930
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310890
|
7.5 |
HIGH
|
modxcms
|
evolution
|
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
|
CWE-89
SQL Injection
|
CVE-2010-3929
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310891
|
4.3 |
MEDIUM
|
apache
|
couchdb
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3854
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310892
|
8.5 |
HIGH
|
symantec
|
im_manager
|
Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified param…
|
CWE-94
Code Injection
|
CVE-2010-3719
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310893
|
6.9 |
MEDIUM
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current…
|
CWE-22
Path Traversal
|
CVE-2010-3689
|
2024-11-21 10:19 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310894
|
6.9 |
MEDIUM
|
lunascape
|
lunascape
|
Untrusted search path vulnerability in Lunascape before 6.4.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
|
NVD-CWE-Other
|
CVE-2010-3927
|
2024-11-21 10:19 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310895
|
6.9 |
MEDIUM
|
linux-pam
|
linux-pam
|
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might …
|
NVD-CWE-Other
|
CVE-2010-3853
|
2024-11-21 10:19 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310896
|
5.8 |
MEDIUM
|
libfuse_project
|
libfuse
|
FUSE, possibly 2.8.5 and earlier, allows local users to create mtab entries with arbitrary pathnames, and consequently unmount any filesystem, via a symlink attack on the parent directory of the moun…
|
CWE-59
Link Following
|
CVE-2010-3879
|
2024-11-21 10:19 |
2011-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310897
|
4.3 |
MEDIUM
|
rocomotion
|
pm_bbs pplog_2 p_forum p_diary_r pm_forum p_link_compact pplog p_board p_link p_up_board
|
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and e…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3931
|
2024-11-21 10:19 |
2011-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310898
|
6.8 |
MEDIUM
|
wayneeseguin
|
ruby_version_manager
|
Ruby Version Manager (RVM) before 1.2.1 writes file contents to a terminal without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via a crafted …
|
NVD-CWE-Other
|
CVE-2010-3928
|
2024-11-21 10:19 |
2011-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310899
|
9.4 |
HIGH
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity and availability via unknown vectors r…
|
NVD-CWE-noinfo
|
CVE-2010-3599
|
2024-11-21 10:19 |
2011-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310900
|
7.1 |
HIGH
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect integrity via unknown vectors related to Import …
|
NVD-CWE-noinfo
|
CVE-2010-3598
|
2024-11-21 10:19 |
2011-01-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|