|
311101
|
9.3 |
HIGH
|
adobe
|
flash_player
|
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly handle unspecified encodings during the parsing o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3636
|
2024-11-21 10:19 |
2010-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311102
|
9.3 |
HIGH
|
justsystems
|
ichitaro
|
Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3915.
|
NVD-CWE-noinfo
|
CVE-2010-3916
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311103
|
9.3 |
HIGH
|
justsystems
|
ichitaro
|
Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3916.
|
NVD-CWE-noinfo
|
CVE-2010-3915
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311104
|
6.4 |
MEDIUM
|
redhat
|
luci
|
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authen…
|
CWE-287
Improper Authentication
|
CVE-2010-3852
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311105
|
6.8 |
MEDIUM
|
poppler foolabs kde glyphandcog
|
poppler xpdf kdegraphics xpdfreader
|
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows co…
|
CWE-20
Improper Input Validation
|
CVE-2010-3704
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311106
|
4.3 |
MEDIUM
|
poppler
|
poppler
|
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dep…
|
CWE-20
Improper Input Validation
|
CVE-2010-3703
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311107
|
7.5 |
HIGH
|
freedesktop xpdfreader apple fedoraproject opensuse suse debian redhat canonical
|
poppler xpdf cups fedora opensuse linux_enterprise_server debian_linux enterprise_linux_server enterprise_linux_workstation enterprise_linux_desktop ubuntu_linux
|
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent atta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-3702
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311108
|
4.3 |
MEDIUM
|
transware
|
active\!_mail
|
CRLF injection vulnerability in TransWARE Active! mail 6 build 6.40.010047750 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unsp…
|
CWE-94
Code Injection
|
CVE-2010-3913
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311109
|
5.0 |
MEDIUM
|
jsecurity apache
|
jsecurity shiro
|
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restric…
|
CWE-22
Path Traversal
|
CVE-2010-3863
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311110
|
6.9 |
MEDIUM
|
nongnu
|
cvs
|
Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trigger a heap-based bu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3846
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311111
|
5.0 |
MEDIUM
|
mozilla
|
bugzilla
|
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive inf…
|
CWE-200
Information Exposure
|
CVE-2010-3764
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311112
|
4.7 |
MEDIUM
|
libguestfs
|
libguestfs
|
libguestfs before 1.5.23, as used in virt-v2v, virt-inspector 1.5.3 and earlier, and possibly other products, when a raw-format disk image is used, allows local guest OS administrators to read files …
|
CWE-200
Information Exposure
|
CVE-2010-3851
|
2024-11-21 10:19 |
2010-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311113
|
4.3 |
MEDIUM
|
isc
|
dhcp
|
ISC DHCP server 4.0 before 4.0.2, 4.1 before 4.1.2, and 4.2 before 4.2.0-P1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a DHCPv6 packet containing a …
|
NVD-CWE-Other
|
CVE-2010-3611
|
2024-11-21 10:19 |
2010-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311114
|
9.3 |
HIGH
|
vim
|
gvim
|
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary co…
|
NVD-CWE-Other
|
CVE-2010-3914
|
2024-11-21 10:19 |
2010-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311115
|
5.0 |
MEDIUM
|
acegisecurity vmware ibm
|
acegi-security springsource_spring_security websphere_application_server
|
VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Application Server (WAS) 6.1 and 7.0, allows remote attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3700
|
2024-11-21 10:19 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311116
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
Stack-based buffer overflow in dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3655
|
2024-11-21 10:19 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311117
|
9.3 |
HIGH
|
adobe macromedia
|
flash_player acrobat acrobat_reader
|
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 on Android, and authplay.dll (aka AuthPlayLib.bundle or libauthplay.so.0.0.0) in…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3654
|
2024-11-21 10:19 |
2010-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311118
|
6.4 |
MEDIUM
|
rubyonrails
|
rails
|
Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes, which allows remote attackers to modify arbitrary records by changing the names of parameters for form inputs.
|
CWE-20
Improper Input Validation
|
CVE-2010-3933
|
2024-11-21 10:19 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311119
|
5.8 |
MEDIUM
|
curl
|
curl
|
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servers to create or overwrite arbitrary files by using \ (backs…
|
CWE-22
Path Traversal
|
CVE-2010-3842
|
2024-11-21 10:19 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311120
|
4.3 |
MEDIUM
|
usebb
|
usebb
|
rss.php in UseBB before 1.0.11 does not properly handle forum configurations in which a user has the view permission but not the read permission, which allows remote attackers to bypass intended acce…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3713
|
2024-11-21 10:19 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311121
|
4.3 |
MEDIUM
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x before 1.5.21 and 1.6.x before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving "multiple encoded e…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3712
|
2024-11-21 10:19 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311122
|
4.0 |
MEDIUM
|
pidgin
|
pidgin
|
libpurple in Pidgin before 2.7.4 does not properly validate the return value of the purple_base64_decode function, which allows remote authenticated users to cause a denial of service (NULL pointer d…
|
CWE-20
Improper Input Validation
|
CVE-2010-3711
|
2024-11-21 10:19 |
2010-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311123
|
9.3 |
HIGH
|
adobe
|
shockwave_player
|
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie wi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3653
|
2024-11-21 10:19 |
2010-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311124
|
5.0 |
MEDIUM
|
typo3
|
typo3
|
The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filter_var FILTER_VALIDATE_EMAIL operations in PHP, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3717
|
2024-11-21 10:19 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311125
|
6.0 |
MEDIUM
|
typo3
|
typo3
|
The be_user_creation task in TYPO3 4.2.x before 4.2.15 and 4.3.x before 4.3.7 allows remote authenticated users to gain privileges via a crafted POST request that creates a user account with arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2010-3716
|
2024-11-21 10:19 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311126
|
4.3 |
MEDIUM
|
typo3
|
typo3
|
Multiple cross-site scripting (XSS) vulnerabilities in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via vectors …
|
CWE-79
Cross-site Scripting
|
CVE-2010-3715
|
2024-11-21 10:19 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311127
|
7.1 |
HIGH
|
typo3
|
typo3
|
The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly compare certain hash values dur…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3714
|
2024-11-21 10:19 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311128
|
4.3 |
MEDIUM
|
php
|
php
|
Stack consumption vulnerability in the filter_var function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3, when FILTER_VALIDATE_EMAIL mode is used, allows remote attackers to cause a denial of s…
|
CWE-399
Resource Management Errors
|
CVE-2010-3710
|
2024-11-21 10:19 |
2010-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311129
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, int…
|
NVD-CWE-noinfo
|
CVE-2010-3574
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311130
|
5.1 |
MEDIUM
|
sun
|
jre jdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availabil…
|
NVD-CWE-noinfo
|
CVE-2010-3573
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311131
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrit…
|
NVD-CWE-noinfo
|
CVE-2010-3572
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311132
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, …
|
NVD-CWE-noinfo
|
CVE-2010-3571
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311133
|
7.6 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the Deployment Toolkit component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via un…
|
NVD-CWE-noinfo
|
CVE-2010-3570
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311134
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality,…
|
NVD-CWE-noinfo
|
CVE-2010-3569
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311135
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality,…
|
NVD-CWE-noinfo
|
CVE-2010-3568
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311136
|
10.0 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability via…
|
NVD-CWE-noinfo
|
CVE-2010-3567
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311137
|
10.0 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update and 25 allows remote attackers to affect confidentiality, integrity, and availability via…
|
NVD-CWE-noinfo
|
CVE-2010-3566
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311138
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availa…
|
NVD-CWE-noinfo
|
CVE-2010-3565
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311139
|
10.0 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown ve…
|
NVD-CWE-noinfo
|
CVE-2010-3563
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311140
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, …
|
NVD-CWE-noinfo
|
CVE-2010-3562
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311141
|
7.5 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and availability v…
|
NVD-CWE-noinfo
|
CVE-2010-3561
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311142
|
2.6 |
LOW
|
sun
|
jre jdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3560
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311143
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrit…
|
NVD-CWE-noinfo
|
CVE-2010-3559
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311144
|
10.0 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknow…
|
NVD-CWE-noinfo
|
CVE-2010-3558
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311145
|
6.8 |
MEDIUM
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrit…
|
NVD-CWE-noinfo
|
CVE-2010-3557
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311146
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, …
|
NVD-CWE-noinfo
|
CVE-2010-3556
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311147
|
9.3 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unknown ve…
|
NVD-CWE-noinfo
|
CVE-2010-3555
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311148
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the CORBA component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrit…
|
NVD-CWE-noinfo
|
CVE-2010-3554
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311149
|
10.0 |
HIGH
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Swing component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrit…
|
NVD-CWE-noinfo
|
CVE-2010-3553
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311150
|
10.0 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows remote attackers to affect confidentiality, integrity, and availability via unkn…
|
NVD-CWE-noinfo
|
CVE-2010-3552
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|