|
311151
|
5.0 |
MEDIUM
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality via unknown ve…
|
NVD-CWE-noinfo
|
CVE-2010-3551
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311152
|
9.3 |
HIGH
|
sun
|
jre jdk
|
Unspecified vulnerability in the Java Web Start component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update 25 allows remote attackers to affect confidentiality, integrity, and avail…
|
NVD-CWE-noinfo
|
CVE-2010-3550
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311153
|
6.8 |
MEDIUM
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, int…
|
NVD-CWE-noinfo
|
CVE-2010-3549
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311154
|
5.0 |
MEDIUM
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Java Naming and Directory Interface (JNDI) component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affec…
|
NVD-CWE-noinfo
|
CVE-2010-3548
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311155
|
5.1 |
MEDIUM
|
sun
|
jre jdk sdk
|
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, int…
|
NVD-CWE-noinfo
|
CVE-2010-3541
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311156
|
9.3 |
HIGH
|
adobe
|
flash_player
|
Untrusted search path vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows allows local users, and possibly remote attackers, to execute arbitrary code and cond…
|
NVD-CWE-Other
|
CVE-2010-3976
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311157
|
9.3 |
HIGH
|
adobe
|
flash_player
|
Untrusted search path vulnerability in Adobe Flash Player 9 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.…
|
NVD-CWE-Other
|
CVE-2010-3975
|
2024-11-21 10:19 |
2010-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311158
|
9.3 |
HIGH
|
realnetworks
|
realplayer realplayer_sp
|
Multiple heap-based buffer overflows in an ActiveX control in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 allow remote attackers to execute arbitrary code via a long…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3751
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311159
|
9.3 |
HIGH
|
realnetworks
|
realplayer realplayer_sp
|
rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction w…
|
CWE-20
Improper Input Validation
|
CVE-2010-3750
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311160
|
9.3 |
HIGH
|
realnetworks
|
realplayer realplayer_sp
|
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote att…
|
CWE-94
Code Injection
|
CVE-2010-3749
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311161
|
10.0 |
HIGH
|
realnetworks
|
realplayer realplayer_sp
|
Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an u…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3748
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311162
|
9.3 |
HIGH
|
realnetworks
|
realplayer realplayer_sp
|
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly initialize an unspecified object component during p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3747
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311163
|
4.3 |
MEDIUM
|
twiki
|
twiki
|
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via (1) the rev parameter to the view script or…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3841
|
2024-11-21 10:19 |
2010-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311164
|
6.8 |
MEDIUM
|
rim
|
blackberry_device_software
|
The browser in Research In Motion (RIM) BlackBerry Device Software 5.0.0.593 Platform 5.1.0.147 on the BlackBerry 9700 does not properly restrict cross-domain execution of JavaScript, which allows re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3934
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311165
|
9.0 |
HIGH
|
oracle
|
vm
|
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen…
|
NVD-CWE-noinfo
|
CVE-2010-3585
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311166
|
4.3 |
MEDIUM
|
oracle
|
vm
|
Unspecified vulnerability in the Oracle VM component in Oracle VM 2.2.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agent. NOTE: the …
|
NVD-CWE-noinfo
|
CVE-2010-3584
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311167
|
9.0 |
HIGH
|
oracle
|
vm
|
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen…
|
NVD-CWE-noinfo
|
CVE-2010-3583
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311168
|
9.0 |
HIGH
|
oracle
|
vm
|
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to ovs-agen…
|
NVD-CWE-noinfo
|
CVE-2010-3582
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311169
|
3.5 |
LOW
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows remote authenticated users to affect integrity via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3581
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311170
|
4.6 |
MEDIUM
|
oracle
|
opensolaris
|
Unspecified vulnerability in Oracle OpenSolaris allows local users to affect availability via unknown vectors related to Kernel/File System.
|
NVD-CWE-noinfo
|
CVE-2010-3580
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311171
|
6.4 |
MEDIUM
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the (1) Sun Convergence 1 and (2) Sun Java Communications Suite 7 components in Oracle Sun Products Suite 1.0 and 7.0 allows remote attackers to affect confidentiality an…
|
NVD-CWE-noinfo
|
CVE-2010-3579
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311172
|
9.0 |
HIGH
|
oracle
|
opensolaris
|
Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Depot Server.
|
NVD-CWE-noinfo
|
CVE-2010-3578
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311173
|
6.4 |
MEDIUM
|
oracle
|
opensolaris
|
Unspecified vulnerability in Oracle OpenSolaris allows remote attackers to affect confidentiality and integrity, related to Kernel/CIFS.
|
NVD-CWE-noinfo
|
CVE-2010-3577
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311174
|
3.6 |
LOW
|
oracle
|
solaris opensolaris
|
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect integrity and availability, related to the SCSI enclosure services device driver.
|
NVD-CWE-noinfo
|
CVE-2010-3576
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311175
|
6.4 |
MEDIUM
|
oracle
|
sun_product_suite
|
Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 6.0, 6.2, 6.3, and 7.0 allows remote attackers to aff…
|
NVD-CWE-noinfo
|
CVE-2010-3575
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311176
|
6.4 |
MEDIUM
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the Oracle Communications Messaging Server (Sun Java System Messaging Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality…
|
NVD-CWE-noinfo
|
CVE-2010-3564
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311177
|
5.5 |
MEDIUM
|
oracle
|
peoplesoft_and_jdedwards_product_suite
|
Unspecified vulnerability in the PeopleSoft FMS ESA - EX component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users to affe…
|
NVD-CWE-noinfo
|
CVE-2010-3547
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311178
|
5.8 |
MEDIUM
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the Sun Java System Identity Manager component in Oracle Sun Products Suite 8.1 allows remote attackers to affect confidentiality and integrity via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-3546
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311179
|
5.8 |
MEDIUM
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect confidentiality and integrity via …
|
NVD-CWE-noinfo
|
CVE-2010-3545
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311180
|
5.8 |
MEDIUM
|
oracle
|
sun_products_suite
|
Unspecified vulnerability in the Oracle iPlanet Web Server (Sun Java System Web Server) component in Oracle Sun Products Suite 7.0 allows remote attackers to affect integrity and availability via unk…
|
NVD-CWE-noinfo
|
CVE-2010-3544
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311181
|
1.9 |
LOW
|
oracle
|
solaris opensolaris
|
Unspecified vulnerability in Oracle Solaris 8, 9, and 10, and OpenSolaris, allows local users to affect confidentiality, related to USB.
|
NVD-CWE-noinfo
|
CVE-2010-3542
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311182
|
4.0 |
MEDIUM
|
oracle
|
opensolaris solaris
|
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability, related to ZFS.
|
NVD-CWE-noinfo
|
CVE-2010-3540
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311183
|
5.5 |
MEDIUM
|
oracle
|
peoplesoft_and_jdedwards_product_suite
|
Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users …
|
NVD-CWE-noinfo
|
CVE-2010-3539
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311184
|
5.5 |
MEDIUM
|
oracle
|
peoplesoft_and_jdedwards_product_suite
|
Unspecified vulnerability in the PeopleSoft Enterprise FMS - GL component in Oracle PeopleSoft and JDEdwards Suite 8.9 Bundle #38, 9.0 Bundle #31, and 9.1 Bundle #6 allows remote authenticated users …
|
NVD-CWE-noinfo
|
CVE-2010-3538
|
2024-11-21 10:19 |
2010-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311185
|
5.0 |
MEDIUM
|
infradead
|
openconnect
|
Unspecified vulnerability in OpenConnect before 2.23 allows remote AnyConnect SSL VPN servers to cause a denial of service (application crash) via a 404 HTTP status code.
|
NVD-CWE-noinfo
|
CVE-2010-3903
|
2024-11-21 10:19 |
2010-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311186
|
5.0 |
MEDIUM
|
infradead
|
openconnect
|
OpenConnect before 2.26 places the webvpn cookie value in the debugging output, which might allow remote attackers to obtain sensitive information by reading this output, as demonstrated by output po…
|
CWE-200
Information Exposure
|
CVE-2010-3902
|
2024-11-21 10:19 |
2010-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311187
|
6.4 |
MEDIUM
|
infradead
|
openconnect
|
OpenConnect before 2.25 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary AnyConnect SSL VPN servers via a crafted server certificate that (1)…
|
CWE-20
Improper Input Validation
|
CVE-2010-3901
|
2024-11-21 10:19 |
2010-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311188
|
5.8 |
MEDIUM
|
christian_dywan
|
midori
|
Midori before 0.2.5, when WebKitGTK+ before 1.1.14 or LibSoup before 2.29.91 is used, does not verify X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary https web sites v…
|
NVD-CWE-Other
|
CVE-2010-3900
|
2024-11-21 10:19 |
2010-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311189
|
4.0 |
MEDIUM
|
redhat
|
enterprise_mrg
|
lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.2.2 allows remote authenticated users to cause a denial of service (stack memory exhaustion and broker crash) via a large persistent messag…
|
CWE-399
Resource Management Errors
|
CVE-2010-3701
|
2024-11-21 10:19 |
2010-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311190
|
7.2 |
HIGH
|
microsoft
|
windows
|
Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified…
|
NVD-CWE-noinfo
|
CVE-2010-3889
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311191
|
7.2 |
HIGH
|
microsoft
|
windows
|
Unspecified vulnerability in Microsoft Windows on 32-bit platforms allows local users to gain privileges via unknown vectors, as exploited in the wild in July 2010 by the Stuxnet worm, and identified…
|
NVD-CWE-noinfo
|
CVE-2010-3888
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311192
|
4.3 |
MEDIUM
|
apple
|
mail
|
The Limit Mail feature in the Parental Controls functionality in Mail on Apple Mac OS X does not properly enforce the correspondence whitelist, which allows remote attackers to bypass intended access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3887
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311193
|
4.3 |
MEDIUM
|
microsoft
|
internet_explorer
|
The CTimeoutEventList::InsertIntoTimeoutList function in Microsoft mshtml.dll uses a certain pointer value as part of producing Timer ID values for the setTimeout and setInterval methods in VBScript …
|
CWE-200
Information Exposure
|
CVE-2010-3886
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311194
|
6.8 |
MEDIUM
|
cmsmadesimple
|
cms_made_simple
|
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that reset the administrative …
|
CWE-352
Origin Validation Error
|
CVE-2010-3884
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311195
|
6.8 |
MEDIUM
|
cmsmadesimple
|
cms_made_simple
|
Cross-site request forgery (CSRF) vulnerability in the Change Group Permissions module in CMS Made Simple 1.7.1 and earlier allows remote attackers to hijack the authentication of arbitrary users for…
|
CWE-352
Origin Validation Error
|
CVE-2010-3883
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311196
|
4.3 |
MEDIUM
|
cmsmadesimple
|
cms_made_simple
|
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple 1.7.1 and earlier allow remote attackers to inject arbitrary web script or HTML via input to the (1) Add Pages, (2) Add Global C…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3882
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311197
|
5.0 |
MEDIUM
|
rene_tegel
|
visual_synapse
|
Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
|
CWE-22
Path Traversal
|
CVE-2010-3743
|
2024-11-21 10:19 |
2010-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311198
|
4.3 |
MEDIUM
|
freeradius
|
freeradius
|
The wait_for_child_to_die function in main/event.c in FreeRADIUS 2.1.x before 2.1.10, in certain circumstances involving long-term database outages, does not properly handle long queue times for requ…
|
CWE-399
Resource Management Errors
|
CVE-2010-3697
|
2024-11-21 10:19 |
2010-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311199
|
4.3 |
MEDIUM
|
freeradius
|
freeradius
|
The fr_dhcp_decode function in lib/dhcp.c in FreeRADIUS 2.1.9, in certain non-default builds, does not properly handle the DHCP Relay Agent Information option, which allows remote attackers to cause …
|
CWE-399
Resource Management Errors
|
CVE-2010-3696
|
2024-11-21 10:19 |
2010-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311200
|
6.4 |
MEDIUM
|
apereo
|
phpcas
|
Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitrary files via directo…
|
CWE-22
Path Traversal
|
CVE-2010-3692
|
2024-11-21 10:19 |
2010-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|