|
311251
|
7.5 |
HIGH
|
netartmedia
|
websiteadmin
|
Directory traversal vulnerability in ADMIN/login.php in NetArtMEDIA WebSiteAdmin allows remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the ln…
|
CWE-22
Path Traversal
|
CVE-2010-3688
|
2024-11-21 10:19 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311252
|
5.0 |
MEDIUM
|
alex_kellner
|
powermail
|
Unspecified vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to bypass validation have an unspecified impact by "[injecting] arbitrary values into validate…
|
NVD-CWE-noinfo
|
CVE-2010-3687
|
2024-11-21 10:19 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311253
|
5.0 |
MEDIUM
|
drupal peter_wolanin
|
drupal openid
|
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attacker…
|
CWE-287
Improper Authentication
|
CVE-2010-3686
|
2024-11-21 10:19 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311254
|
5.0 |
MEDIUM
|
drupal peter_wolanin
|
drupal openid
|
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which all…
|
CWE-287
Improper Authentication
|
CVE-2010-3685
|
2024-11-21 10:19 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311255
|
2.1 |
LOW
|
synology
|
dsm
|
The FTP authentication module in Synology Disk Station 2.x logs passwords to the web application interface in cases of incorrect login attempts, which allows local users to obtain sensitive informati…
|
CWE-255
Credentials Management
|
CVE-2010-3684
|
2024-11-21 10:19 |
2010-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311256
|
7.5 |
HIGH
|
wire_plastic_design
|
wpquiz
|
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1) id and (2) password (pw) parameters to (a) admin.php or (b) user.php.
|
CWE-89
SQL Injection
|
CVE-2010-3608
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311257
|
4.3 |
MEDIUM
|
netartmedia
|
real_estate_portal
|
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3607
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311258
|
6.8 |
MEDIUM
|
netartmedia
|
real_estate_portal
|
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory travers…
|
CWE-22
Path Traversal
|
CVE-2010-3606
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311259
|
4.3 |
MEDIUM
|
alex_kellner
|
powermail
|
Cross-site scripting (XSS) vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-3605
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311260
|
7.5 |
HIGH
|
alex_kellner
|
powermail
|
SQL injection vulnerability in the powermail extension 1.5.3 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2010-3604
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311261
|
6.8 |
MEDIUM
|
sourcetreesolutions
|
mojoportal
|
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to hijack the authentication of admin…
|
CWE-352
Origin Validation Error
|
CVE-2010-3603
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311262
|
4.3 |
MEDIUM
|
sourcetreesolutions
|
mojoportal
|
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers to inject arbitrary web script or HTML via the User ID parameter. NOTE: some of…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3602
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311263
|
7.5 |
HIGH
|
invisionpower
|
ibphotohost
|
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands via the img parameter.
|
CWE-89
SQL Injection
|
CVE-2010-3601
|
2024-11-21 10:19 |
2010-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311264
|
5.9 |
MEDIUM
Network
|
owasp
|
enterprise_security_api_for_java
|
It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
|
-
|
CVE-2010-3300
|
2024-11-21 10:18 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311265
|
3.3 |
LOW
Local
|
hp redhat fedoraproject
|
hp-ux_directory_server redhat_directory_server 389_directory_server directory_server
|
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2010-3282
|
2024-11-21 10:18 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311266
|
5.5 |
MEDIUM
Local
|
babiloo_project debian
|
babiloo debian_linux
|
babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary files, allowing a local attacker to overwrite arbitrary files.
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2010-3440
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311267
|
8.8 |
HIGH
Network
|
pixelpost
|
pixelpost
|
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
|
CWE-352
Origin Validation Error
|
CVE-2010-3305
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311268
|
6.5 |
MEDIUM
Network
|
rubyonrails debian
|
rails debian_linux
|
The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2010-3299
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311269
|
5.5 |
MEDIUM
Local
|
mailscanner
|
mailscanner
|
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to…
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2010-3292
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311270
|
4.7 |
MEDIUM
Local
|
mailscanner
|
mailscanner
|
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-…
|
CWE-59
Link Following
|
CVE-2010-3095
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311271
|
6.5 |
MEDIUM
Network
|
cor-entertainment debian fedoraproject
|
alien-arena debian_linux fedora
|
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
|
CWE-20
Improper Input Validation
|
CVE-2010-3439
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311272
|
9.8 |
CRITICAL
Network
|
libpoe-component-irc-perl_project debian fedoraproject
|
libpoe-component-irc-perl debian_linux fedora
|
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'pri…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2010-3438
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311273
|
4.8 |
MEDIUM
Local
|
gargoyle_project debian
|
gargoyle debian_linux
|
If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. This can allow a local user to trick another user into running gargoyle in a dire…
|
CWE-20
Improper Input Validation
|
CVE-2010-3359
|
2024-11-21 10:18 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311274
|
9.8 |
CRITICAL
Network
|
qtparted_project
|
qtparted
|
qtparted has insecure library loading which may allow arbitrary code execution
|
CWE-20
Improper Input Validation
|
CVE-2010-3375
|
2024-11-21 10:18 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311275
|
5.5 |
MEDIUM
Local
|
grsecurity debian
|
paxtest debian_linux
|
paxtest handles temporary files insecurely
|
CWE-20
Improper Input Validation
|
CVE-2010-3373
|
2024-11-21 10:18 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311276
|
5.5 |
MEDIUM
Local
|
mailscanner
|
mailscanner
|
mailscanner can allow local users to prevent virus signatures from being updated
|
CWE-20
Improper Input Validation
|
CVE-2010-3293
|
2024-11-21 10:18 |
2019-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311277
|
5.0 |
MEDIUM
|
quassel-irc canonical
|
quassel_irc ubuntu_linux
|
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIV…
|
CWE-399
Resource Management Errors
|
CVE-2010-3443
|
2024-11-21 10:18 |
2013-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311278
|
6.4 |
MEDIUM
|
f-secure
|
anti-virus
|
F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via ma…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3499
|
2024-11-21 10:18 |
2012-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311279
|
6.4 |
MEDIUM
|
avg
|
anti-virus
|
AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary code via malware…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3498
|
2024-11-21 10:18 |
2012-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311280
|
6.4 |
MEDIUM
|
symantec
|
norton_antivirus
|
Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute arbitrary …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3497
|
2024-11-21 10:18 |
2012-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311281
|
6.4 |
MEDIUM
|
mcafee
|
virusscan_enterprise
|
McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remote attackers to execute…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3496
|
2024-11-21 10:18 |
2012-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311282
|
6.8 |
MEDIUM
|
ibm
|
websphere_application_server
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative console) in IBM WebSphere Application Server (WAS) 7.0.0.13 and earlier allow remote…
|
CWE-352
Origin Validation Error
|
CVE-2010-3271
|
2024-11-21 10:18 |
2011-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311283
|
6.4 |
MEDIUM
|
orbeon
|
forms
|
oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote at…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3260
|
2024-11-21 10:18 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311284
|
4.3 |
MEDIUM
|
horde
|
gollem
|
Cross-site scripting (XSS) vulnerability in view.php in the file viewer in Horde Gollem before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the file parameter in a view_fi…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3447
|
2024-11-21 10:18 |
2011-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311285
|
9.3 |
HIGH
|
videolan
|
vlc_media_player
|
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an NSV file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3276
|
2024-11-21 10:18 |
2011-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311286
|
9.3 |
HIGH
|
videolan
|
vlc_media_player
|
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a crafted width in an AMV file, related to a "dangling pointer vulnerability."
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3275
|
2024-11-21 10:18 |
2011-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311287
|
7.5 |
HIGH
|
moinejf fedoraproject
|
abcm2ps fedora
|
Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input…
|
CWE-120
Classic Buffer Overflow
|
CVE-2010-3441
|
2024-11-21 10:18 |
2011-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311288
|
4.3 |
MEDIUM
|
zohocorp
|
manageengine_adselfservice_plus
|
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in the Employee Search Engine in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allow remote attackers to inject a…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3274
|
2024-11-21 10:18 |
2011-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311289
|
5.0 |
MEDIUM
|
zohocorp
|
manageengine_adselfservice_plus
|
ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 allows remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, by providing a user id to accoun…
|
CWE-20
Improper Input Validation
|
CVE-2010-3273
|
2024-11-21 10:18 |
2011-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311290
|
4.3 |
MEDIUM
|
zohocorp
|
manageengine_adselfservice_plus
|
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and conse…
|
CWE-20
Improper Input Validation
|
CVE-2010-3272
|
2024-11-21 10:18 |
2011-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311291
|
6.8 |
MEDIUM
|
cisco
|
webex_meeting_center
|
Stack-based buffer overflow in Cisco WebEx Meeting Center T27LB before SP21 EP3 and T27LC before SP22 allows user-assisted remote authenticated users to execute arbitrary code by providing a crafted …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3270
|
2024-11-21 10:18 |
2011-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311292
|
9.3 |
HIGH
|
cisco
|
webex_recording_format_player webex_advanced_recording_format_player
|
Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3269
|
2024-11-21 10:18 |
2011-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311293
|
9.3 |
HIGH
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
Multiple off-by-one errors in the WW8DopTypography::ReadFromMem function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to cause a denial of service (application cr…
|
CWE-193
Off-by-one Error
|
CVE-2010-3454
|
2024-11-21 10:18 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311294
|
9.3 |
HIGH
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
The WW8ListManager::WW8ListManager function in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 does not properly handle an unspecified number of list levels in user-defined list styles in WW8…
|
CWE-787
Out-of-bounds Write
|
CVE-2010-3453
|
2024-11-21 10:18 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311295
|
9.3 |
HIGH
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…
|
CWE-416
Use After Free
|
CVE-2010-3452
|
2024-11-21 10:18 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311296
|
9.3 |
HIGH
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via…
|
CWE-416
Use After Free
|
CVE-2010-3451
|
2024-11-21 10:18 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311297
|
9.3 |
HIGH
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
Multiple directory traversal vulnerabilities in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allow remote attackers to overwrite arbitrary files via a .. (dot dot) in an entry in (1) an XSLT JAR filte…
|
CWE-22
Path Traversal
|
CVE-2010-3450
|
2024-11-21 10:18 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311298
|
4.7 |
MEDIUM
|
linux-pam
|
linux-pam
|
The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow …
|
NVD-CWE-Other
|
CVE-2010-3435
|
2024-11-21 10:18 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311299
|
1.9 |
LOW
|
linux-pam
|
linux-pam
|
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local use…
|
NVD-CWE-Other
|
CVE-2010-3431
|
2024-11-21 10:18 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311300
|
4.7 |
MEDIUM
|
linux-pam
|
linux-pam
|
The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow loc…
|
NVD-CWE-Other
|
CVE-2010-3430
|
2024-11-21 10:18 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|