NVD Vulnerability Information Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
In descending order of publication date
In descending order of update date
Number of items displayed

You can search the list of vulnerabilities managed by the NVD (National Vulnerability Database).
Since vulnerability information is often updated before JVN (Japan Vulnerability Note), vulnerabilities that are not listed in JVN may be updated.

If there is a vulnerability related to JVN (Japan Vulnerability Note), the information will be displayed on the detail page.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Update Date:June 23, 2026, 4 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
311051 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3798 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311052 3.5 LOW
apple mac_os_x_server Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vect… CWE-79
Cross-site Scripting
CVE-2010-3797 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311053 4.3 MEDIUM
apple mac_os_x
mac_os_x_server
Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an ap… CWE-200
Information Exposure
CVE-2010-3796 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311054 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3795 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311055 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a d… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3794 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311056 6.8 MEDIUM
apple quicktime
mac_os_x
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie … CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3793 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311057 6.8 MEDIUM
apple quicktime
mac_os_x
mac_os_x_server
Integer signedness error in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movi… CWE-189
Numeric Errors
CVE-2010-3792 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311058 6.8 MEDIUM
apple quicktime
mac_os_x
mac_os_x_server
Buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MPEG movie file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3791 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311059 6.8 MEDIUM
apple quicktime
mac_os_x
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file that… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3790 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311060 6.8 MEDIUM
apple mac_os_x
quicktime
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted AVI file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3789 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311061 6.8 MEDIUM
apple mac_os_x
quicktime
mac_os_x_server
QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of JP2 image data, which allows remote attackers to execute arbitrary code or cause a denial… CWE-20
 Improper Input Validation 
CVE-2010-3788 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311062 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
Heap-based buffer overflow in QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JP2 ima… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3787 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311063 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
QuickLook in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Excel file. CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3786 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311064 6.8 MEDIUM
apple mac_os_x
mac_os_x_server
Buffer overflow in QuickLook in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microso… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3785 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311065 5.0 MEDIUM
apple mac_os_x
mac_os_x_server
The PMPageFormatCreateWithDataRepresentation API in Printing in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly handle XML data, which allows attackers to cause a denial of service (… NVD-CWE-Other
CVE-2010-3784 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311066 6.8 MEDIUM
apple mac_os_x_server Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replication, which allows remote authenticated users to bypass verification of the current password via uns… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3783 2024-11-21 10:19 2010-11-17 Show GitHub Exploit DB Packet Storm
311067 5.0 MEDIUM
ibm omnifind IBM OmniFind Enterprise Edition 8.x and 9.x performs web crawls with an unlimited recursion depth, which allows remote web servers to cause a denial of service (infinite loop) via a crafted series of… CWE-399
 Resource Management Errors
CVE-2010-3899 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311068 5.0 MEDIUM
ibm omnifind IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remote attackers to bypass authentication by leveragin… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3898 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311069 5.0 MEDIUM
ibm omnifind ESSearchApplication/palette.do in IBM OmniFind Enterprise Edition 8.x and 9.x includes the administrator password in the HTML source code, which might allow remote attackers to obtain sensitive infor… CWE-255
Credentials Management
CVE-2010-3897 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311070 7.5 HIGH
ibm omnifind The ESSearchApplication directory tree in IBM OmniFind Enterprise Edition 8.x and 9.x does not require authentication, which allows remote attackers to modify the server configuration via a request t… CWE-287
Improper Authentication
CVE-2010-3896 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311071 7.2 HIGH
ibm omnifind esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first argument. CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3895 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311072 9.3 HIGH
ibm omnifind Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.cryptionjni.so in the login form in the administration interface in IBM OmniFind Ent… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3894 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311073 7.5 HIGH
ibm omnifind The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP address, which allows remote attackers to perform arbit… CWE-264
Permissions, Privileges, and Access Controls
CVE-2010-3893 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311074 6.8 MEDIUM
ibm omnifind Session fixation vulnerability in the login form in the administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x allows remote attackers to hijack web sessions by replaying a session ID… NVD-CWE-Other
CVE-2010-3892 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311075 6.8 MEDIUM
ibm omnifind Cross-site request forgery (CSRF) vulnerability in ESAdmin/security.do in the administrator interface in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to hijack the authenticatio… CWE-352
 Origin Validation Error
CVE-2010-3891 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311076 4.3 MEDIUM
ibm omnifind Cross-site scripting (XSS) vulnerability in IBM OmniFind Enterprise Edition before 9.1 allows remote attackers to inject arbitrary web script or HTML via the command parameter to the administration i… CWE-79
Cross-site Scripting
CVE-2010-3890 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311077 6.8 MEDIUM
php
canonical
php
ubuntu_linux
The utf8_decode function in PHP before 5.3.4 does not properly handle non-shortest form UTF-8 encoding and ill-formed subsequences in UTF-8 data, which makes it easier for remote attackers to bypass … CWE-20
 Improper Input Validation 
CVE-2010-3870 2024-11-21 10:19 2010-11-13 Show GitHub Exploit DB Packet Storm
311078 4.3 MEDIUM
microsoft forefront_unified_access_gateway Cross-site scripting (XSS) vulnerability in Signurl.asp in Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, 2010 Update 1, and 2010 Update 2 allows remote attackers to inject arbitrary web… CWE-79
Cross-site Scripting
CVE-2010-3936 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311079 10.0 HIGH
adobe flash_media_server Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vuln… CWE-94
Code Injection
CVE-2010-3635 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311080 5.0 MEDIUM
adobe flash_media_server Unspecified vulnerability in the edge process in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service via unknow… NVD-CWE-noinfo
CVE-2010-3634 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311081 5.0 MEDIUM
adobe flash_media_server Memory leak in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service (memory consumption) via unspecified vectors. CWE-399
 Resource Management Errors
CVE-2010-3633 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311082 4.3 MEDIUM
mahara mahara Cross-site scripting (XSS) vulnerability in blocktype/groupviews/theme/raw/groupviews.tpl in Mahara before 1.3.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors… CWE-79
Cross-site Scripting
CVE-2010-3871 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311083 7.1 HIGH
proftpd proftpd Multiple directory traversal vulnerabilities in the mod_site_misc module in ProFTPD before 1.3.3c allow remote authenticated users to create directories, delete directories, create symlinks, and modi… CWE-22
Path Traversal
CVE-2010-3867 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311084 6.8 MEDIUM
horde horde_application_framework Cross-site request forgery (CSRF) vulnerability in the Horde Application Framework before 3.3.9 allows remote attackers to hijack the authentication of unspecified victims for requests to a preferenc… CWE-352
 Origin Validation Error
CVE-2010-3694 2024-11-21 10:19 2010-11-10 Show GitHub Exploit DB Packet Storm
311085 4.3 MEDIUM
php
canonical
php
ubuntu_linux
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and applicatio… CWE-20
 Improper Input Validation 
CVE-2010-3709 2024-11-21 10:19 2010-11-9 Show GitHub Exploit DB Packet Storm
311086 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3652 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311087 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3650 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311088 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3649 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311089 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3648 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311090 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3647 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311091 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3646 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311092 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3645 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311093 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3644 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311094 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3643 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311095 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3642 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311096 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3641 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311097 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to execute arbitrary … NVD-CWE-noinfo
CVE-2010-3640 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311098 9.3 HIGH
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, allows attackers to cause a denial of … NVD-CWE-noinfo
CVE-2010-3639 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311099 4.3 MEDIUM
adobe flash_player Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Mac OS X, when Safari is used, allows attackers to obtain sensitive information via unknown vectors. NVD-CWE-noinfo
CVE-2010-3638 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm
311100 9.3 HIGH
adobe flash_player An unspecified ActiveX control in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 (Flash10h.ocx) on Windows allows remote attackers to execute arbitrary code or cause a denial of serv… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2010-3637 2024-11-21 10:19 2010-11-8 Show GitHub Exploit DB Packet Storm