NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 24, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311001 9.3 HIGH
mozilla firefox
seamonkey
Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to… CWE-399
 Resource Management Errors
CVE-2010-3766 2024-11-21 10:19 2010-12-11 Show GitHub Exploit DB Packet Storm
311002 7.5 HIGH
sixapart movabletype SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. CWE-89
SQL Injection
CVE-2010-3922 2024-11-21 10:19 2010-12-10 Show GitHub Exploit DB Packet Storm
311003 4.3 MEDIUM
sixapart movabletype Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. CWE-79
Cross-site Scripting
CVE-2010-3921 2024-11-21 10:19 2010-12-10 Show GitHub Exploit DB Packet Storm
311004 9.3 HIGH
apple quicktime Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted panoram… CWE-189
Numeric Errors
CVE-2010-3802 2024-11-21 10:19 2010-12-10 Show GitHub Exploit DB Packet Storm
311005 9.3 HIGH
apple quicktime Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3801 2024-11-21 10:19 2010-12-10 Show GitHub Exploit DB Packet Storm
311006 9.3 HIGH
apple quicktime Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3800 2024-11-21 10:19 2010-12-10 Show GitHub Exploit DB Packet Storm
311007 4.6 MEDIUM
epson lp-s7100_driver_4.1.0
lp-s7100_driver_4.1.7
lp-s9000_driver_4.1.0
lp-s9000_driver_4.1.11
The Seiko Epson printer driver installers for LP-S9000 before 4.1.11 and LP-S7100 before 4.1.7, or as downloaded from the vendor between May 2010 and 20101125, set weak permissions for the "C:\Progra… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3920 2024-11-21 10:19 2010-12-9 Show GitHub Exploit DB Packet Storm
311008 5.0 MEDIUM
redhat icedtea IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to obtain sensitive infor… CWE-200
Information Exposure
CVE-2010-3860 2024-11-21 10:19 2010-12-9 Show GitHub Exploit DB Packet Storm
311009 2.7 LOW
citrix xen The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a zombie domain, cause… CWE-399
 Resource Management Errors
CVE-2010-3699 2024-11-21 10:19 2010-12-9 Show GitHub Exploit DB Packet Storm
311010 5.0 MEDIUM
isc bind named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via the standard DNS quer… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3615 2024-11-21 10:19 2010-12-6 Show GitHub Exploit DB Packet Storm
311011 6.4 MEDIUM
isc bind named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRset during a DNSKEY a… CWE-20
 Improper Input Validation 
CVE-2010-3614 2024-11-21 10:19 2010-12-6 Show GitHub Exploit DB Packet Storm
311012 4.0 MEDIUM
isc bind named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and corresponding RRSIG records in … CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3613 2024-11-21 10:19 2010-12-6 Show GitHub Exploit DB Packet Storm
311013 4.9 MEDIUM
linux
debian
canonical
linux_kernel
debian_linux
ubuntu_linux
The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) … CWE-400
 Uncontrolled Resource Consumption
CVE-2010-3858 2024-11-21 10:19 2010-12-1 Show GitHub Exploit DB Packet Storm
311014 4.3 MEDIUM
vtiger vtiger_crm Multiple cross-site scripting (XSS) vulnerabilities in vtiger CRM before 5.2.1 allow remote attackers to inject arbitrary web script or HTML via (1) the username (aka default_user_name) field or (2) … CWE-79
Cross-site Scripting
CVE-2010-3911 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311015 6.8 MEDIUM
vtiger vtiger_crm Multiple directory traversal vulnerabilities in the return_application_language function in include/utils/utils.php in vtiger CRM before 5.2.1 allow remote attackers to include and execute arbitrary … CWE-22
Path Traversal
CVE-2010-3910 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311016 6.0 MEDIUM
vtiger vtiger_crm Incomplete blacklist vulnerability in config.template.php in vtiger CRM before 5.2.1 allows remote authenticated users to execute arbitrary code by using the draft save feature in the Compose Mail co… CWE-94
Code Injection
CVE-2010-3909 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311017 6.8 MEDIUM
freetype freetype Buffer overflow in the ft_var_readpackedpoints function in truetype/ttgxvar.c in FreeType 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execut… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3855 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311018 6.8 MEDIUM
apple iphone_os Heap-based buffer overflow in the GSM mobility management implementation in Telephony in Apple iOS before 4.2 on the iPhone and iPad allows remote attackers to execute arbitrary code on the baseband … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3832 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311019 4.3 MEDIUM
apple iphone_os Photos in Apple iOS before 4.2 enables support for HTTP Basic Authentication over an unencrypted connection, which allows man-in-the-middle attackers to read MobileMe account passwords by spoofing a … CWE-200
Information Exposure
CVE-2010-3831 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311020 7.2 HIGH
apple iphone_os Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privileges via unspecified vectors. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3830 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311021 5.8 MEDIUM
apple iphone_os WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail m… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3829 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311022 4.3 MEDIUM
apple iphone_os iAd Content Display in Apple iOS before 4.2 allows man-in-the-middle attackers to make calls via a crafted URL in an ad. NVD-CWE-Other
CVE-2010-3828 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311023 4.3 MEDIUM
apple iphone_os Apple iOS before 4.2 does not properly validate signatures before displaying a configuration profile in the configuration installation utility, which allows remote attackers to spoof profiles via uns… CWE-20
 Improper Input Validation 
CVE-2010-3827 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311024 6.8 MEDIUM
freetype freetype Heap-based buffer overflow in the Ins_SHZ function in ttinterp.c in FreeType 2.4.3 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3814 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311025 8.3 HIGH
linux
fedoraproject
debian
canonical
linux_kernel
fedora
debian_linux
ubuntu_linux
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denia… CWE-400
 Uncontrolled Resource Consumption
CVE-2010-3705 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311026 4.9 MEDIUM
linux
fedoraproject
linux_kernel
fedora
The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RU… CWE-400
 Uncontrolled Resource Consumption
CVE-2010-3698 2024-11-21 10:19 2010-11-27 Show GitHub Exploit DB Packet Storm
311027 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of colo… NVD-CWE-Other
CVE-2010-3826 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311028 9.3 HIGH
apple safari
webkit
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or … CWE-399
 Resource Management Errors
CVE-2010-3824 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311029 9.3 HIGH
apple safari
webkit
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or … CWE-399
 Resource Management Errors
CVE-2010-3823 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311030 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer during processing of Cascading Style Sheets (CSS) c… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3822 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311031 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the :first-letter pseudo-element in a Cascading Style Sheets… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3821 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311032 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses uninitialized memory during processing of editable elements, which allows re… CWE-399
 Resource Management Errors
CVE-2010-3820 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311033 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Casc… CWE-94
Code Injection
CVE-2010-3819 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311034 9.3 HIGH
apple safari
webkit
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or … CWE-399
 Resource Management Errors
CVE-2010-3818 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311035 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of Casc… NVD-CWE-Other
CVE-2010-3817 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311036 9.3 HIGH
apple safari
webkit
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or … CWE-399
 Resource Management Errors
CVE-2010-3816 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311037 5.8 MEDIUM
apple safari
webkit
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac O… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3813 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311038 9.3 HIGH
apple safari
webkit
Integer overflow in the Text::wholeText method in dom/Text.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk … CWE-189
Numeric Errors
CVE-2010-3812 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311039 9.3 HIGH
apple safari
webkit
Use-after-free vulnerability in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or … CWE-399
 Resource Management Errors
CVE-2010-3811 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311040 4.3 MEDIUM
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the History object, which allows remote attackers to spoof t… NVD-CWE-Other
CVE-2010-3810 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311041 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of inli… CWE-94
Code Injection
CVE-2010-3809 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311042 9.3 HIGH
apple safari
webkit
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly perform a cast of an unspecified variable during processing of edit… CWE-94
Code Injection
CVE-2010-3808 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311043 9.3 HIGH
apple safari
webkit
Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a den… CWE-189
Numeric Errors
CVE-2010-3805 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311044 5.0 MEDIUM
apple safari
webkit
The JavaScript implementation in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, uses a weak algorithm for generating values of rando… CWE-310
Cryptographic Issues
CVE-2010-3804 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311045 9.3 HIGH
apple safari
webkit
Integer overflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a deni… CWE-189
Numeric Errors
CVE-2010-3803 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311046 4.3 MEDIUM
pgp desktop_for_windows
desktop_for_mac
PGP Desktop 10.0.x before 10.0.3 SP2 and 10.1.0 before 10.1.0 SP1 does not properly implement the "Decrypt/Verify File via Right-Click" functionality for multi-packet OpenPGP messages that represent … CWE-310
Cryptographic Issues
CVE-2010-3618 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311047 7.2 HIGH
apache mod_fcgid A flaw was found in the mod_fcgid module of httpd. A malformed FastCGI response may result in a stack-based buffer overflow in the modules/fcgid/fcgid_bucket.c file in the fcgid_header_bucket_read() … CWE-189
Numeric Errors
CVE-2010-3872 2024-11-21 10:19 2010-11-22 Show GitHub Exploit DB Packet Storm
311048 4.0 MEDIUM
redhat certificate_system
dogtag_certificate_system
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System allow remote authenticated users to generate an arbitrary number of certificates by replaying a single SCEP one-time PIN. CWE-310
Cryptographic Issues
CVE-2010-3869 2024-11-21 10:19 2010-11-18 Show GitHub Exploit DB Packet Storm
311049 5.8 MEDIUM
redhat certificate_system
dogtag_certificate_system
Red Hat Certificate System (RHCS) 7.3 and 8 and Dogtag Certificate System do not require authentication for requests to decrypt SCEP one-time PINs, which allows remote attackers to obtain PINs by sni… CWE-287
Improper Authentication
CVE-2010-3868 2024-11-21 10:19 2010-11-18 Show GitHub Exploit DB Packet Storm
311050 7.6 HIGH
openssl openssl Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to ex… CWE-362
Race Condition
CVE-2010-3864 2024-11-21 10:19 2010-11-18 Show GitHub Exploit DB Packet Storm