|
311651
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2207
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311652
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image…
|
CWE-189
Numeric Errors
|
CVE-2010-2206
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311653
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, access uninitialized memory, which allows attackers to execute arbitrary code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2010-2205
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311654
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code …
|
NVD-CWE-noinfo
|
CVE-2010-2204
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311655
|
6.8 |
MEDIUM
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3 on UNIX allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2203
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311656
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2202
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311657
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstri…
|
CWE-399
Resource Management Errors
|
CVE-2010-2201
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311658
|
9.3 |
HIGH
|
adobe
|
acrobat acrobat_reader
|
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content, involving the newfunction…
|
CWE-399
Resource Management Errors
|
CVE-2010-2168
|
2024-11-21 10:16 |
2010-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311659
|
7.5 |
HIGH
|
2daybiz
|
multi_level_marketing_software
|
Multiple SQL injection vulnerabilities in 2daybiz Multi Level Marketing (MLM) Software allow remote attackers to execute arbitrary SQL commands via the username parameter to (1) index.php and (2) adm…
|
CWE-89
SQL Injection
|
CVE-2010-2516
|
2024-11-21 10:16 |
2010-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311660
|
9.3 |
HIGH
|
kvirc
|
kvirc
|
Directory traversal vulnerability in the DCC functionality in KVIrc 3.4 and 4.0 allows remote attackers to overwrite arbitrary files via unknown vectors.
|
CWE-22
Path Traversal
|
CVE-2010-2452
|
2024-11-21 10:16 |
2010-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311661
|
10.0 |
HIGH
|
kvirc
|
kvirc
|
Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors.
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2010-2451
|
2024-11-21 10:16 |
2010-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311662
|
6.8 |
MEDIUM
|
dacian_strain
|
com_jfaq
|
Multiple SQL injection vulnerabilities in index.php in the JFaq (com_jfaq) component 1.2 for Joomla!, when magic_quotes_gpc is disabled, allow (1) remote attackers to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2010-2515
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311663
|
4.3 |
MEDIUM
|
dacian_strain
|
com_jfaq
|
Cross-site scripting (XSS) vulnerability in the JFaq (com_jfaq) component 1.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the question parameter in an add2 action t…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2514
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311664
|
7.5 |
HIGH
|
harmistechnology
|
com_jeajaxeventcalendar
|
SQL injection vulnerability in the JE Ajax Event Calendar (com_jeajaxeventcalendar) component 1.0.5 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to ind…
|
CWE-89
SQL Injection
|
CVE-2010-2513
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311665
|
7.5 |
HIGH
|
2daybiz
|
matrimonial_script
|
SQL injection vulnerability in customprofile.php in 2daybiz Matrimonial Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2512
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311666
|
7.5 |
HIGH
|
2daybiz
|
multi_level_marketing_software
|
SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2511
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311667
|
7.5 |
HIGH
|
2daybiz
|
web_template_software
|
SQL injection vulnerability in customize.php in 2daybiz Web Template Software allows remote attackers to execute arbitrary SQL commands via the tid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2510
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311668
|
4.3 |
MEDIUM
|
2daybiz
|
web_template_software
|
Multiple cross-site scripting (XSS) vulnerabilities in 2daybiz Web Template Software allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to category.php and th…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2509
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311669
|
7.5 |
HIGH
|
2daybiz
|
video_community_portal_script
|
SQL injection vulnerability in user-profile.php in 2daybiz Video Community Portal Script allows remote attackers to execute arbitrary SQL commands via the userid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2508
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311670
|
6.8 |
MEDIUM
|
masselink
|
com_picasa2gallery
|
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified othe…
|
CWE-22
Path Traversal
|
CVE-2010-2507
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311671
|
2.9 |
LOW
|
cisco
|
linksys_firmware linksys_wap54g
|
Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2506
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311672
|
5.0 |
MEDIUM
|
saschart
|
sascam_webcam_server
|
Soft SaschArt SasCAM Webcam Server 2.6.5, 2.7, and earlier allows remote attackers to cause a denial of service (crash) via a large number of requests with a long line, as demonstrated using a long G…
|
CWE-20
Improper Input Validation
|
CVE-2010-2505
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311673
|
6.0 |
MEDIUM
|
splunk
|
splunk
|
Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allows remote authenticated users to obtain sensitive information via HTTP header injection, aka SPL-31066.
|
NVD-CWE-Other
|
CVE-2010-2504
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311674
|
4.3 |
MEDIUM
|
splunk
|
splunk
|
Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067; …
|
CWE-79
Cross-site Scripting
|
CVE-2010-2503
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311675
|
7.5 |
HIGH
|
splunk
|
splunk
|
Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to mo…
|
CWE-22
Path Traversal
|
CVE-2010-2502
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311676
|
1.9 |
LOW
|
mozilla
|
bugzilla
|
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local user…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2470
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311677
|
6.8 |
MEDIUM
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in report/overview/report.php in the quiz module in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to hijack the authentication of…
|
CWE-352
Origin Validation Error
|
CVE-2010-2231
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311678
|
4.0 |
MEDIUM
|
moodle
|
moodle
|
The KSES text cleaning filter in lib/weblib.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 does not properly handle vbscript URIs, which allows remote authenticated users to conduct cross-site sc…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2230
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311679
|
4.3 |
MEDIUM
|
moodle
|
moodle
|
Multiple cross-site scripting (XSS) vulnerabilities in blog/index.php in Moodle before 1.8.13 and 1.9.x before 1.9.9 allow remote attackers to inject arbitrary web script or HTML via unspecified para…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2229
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311680
|
4.3 |
MEDIUM
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the MNET access-control interface in Moodle before 1.8.13 and 1.9.x before 1.9.9 allows remote attackers to inject arbitrary web script or HTML via vectors…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2228
|
2024-11-21 10:16 |
2010-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311681
|
5.0 |
MEDIUM
|
linearcorp
|
emerge_50 emerge_5000
|
The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the de…
|
CWE-255
Credentials Management
|
CVE-2010-2469
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311682
|
10.0 |
HIGH
|
s2sys linearcorp sonitrol
|
netbox emerge_50 emerge_5000 eaccess
|
The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for con…
|
CWE-310
Cryptographic Issues
|
CVE-2010-2468
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311683
|
5.0 |
MEDIUM
|
s2sys linearcorp sonitrol
|
netbox emerge_50 emerge_5000 eaccess
|
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, w…
|
CWE-255
Credentials Management
|
CVE-2010-2467
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311684
|
5.0 |
MEDIUM
|
s2sys linearcorp sonitrol
|
netbox emerge_50 emerge_5000 eaccess
|
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2466
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311685
|
5.0 |
MEDIUM
|
s2sys linearcorp sonitrol
|
netbox emerge_50 emerge_5000 eaccess
|
The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which al…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2465
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311686
|
4.3 |
MEDIUM
|
rsjoomla
|
com_rscomments
|
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) webs…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2464
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311687
|
4.3 |
MEDIUM
|
jamroom
|
jamroom
|
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2463
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311688
|
7.5 |
HIGH
|
tomacero
|
orohyip
|
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.
|
CWE-89
SQL Injection
|
CVE-2010-2462
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311689
|
7.5 |
HIGH
|
jce-tech
|
overstock_script
|
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL commands via the store parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2461
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311690
|
7.5 |
HIGH
|
jce-tech
|
shareasale_script
|
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers to execute arbitrary SQL commands via the mechant_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2460
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311691
|
7.5 |
HIGH
|
2daybiz
|
video_community_portal_script
|
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute arbitrary SQL commands via the videoid parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2459
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311692
|
4.3 |
MEDIUM
|
2daybiz
|
video_community_portal_script
|
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to inject arbitrary web script or HTML via the videoid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2458
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311693
|
4.3 |
MEDIUM
|
qsoft-inc
|
k-search
|
Cross-site scripting (XSS) vulnerability in index.php in K-Search allows remote attackers to inject arbitrary web script or HTML via the term parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2457
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311694
|
6.8 |
MEDIUM
|
codelib
|
linker_img
|
Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read and execute arbitrary local files via a URL in the (1) cook_lan cookie parameter…
|
CWE-22
Path Traversal
|
CVE-2010-2456
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311695
|
4.3 |
MEDIUM
|
opera
|
opera_browser
|
Opera does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2455
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311696
|
4.3 |
MEDIUM
|
apple
|
safari
|
Apple Safari does not properly manage the address bar between the request to open a URL and the retrieval of the new document's content, which might allow remote attackers to conduct spoofing attacks…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2454
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311697
|
4.3 |
MEDIUM
|
maradns
|
maradns
|
parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of…
|
NVD-CWE-Other
|
CVE-2010-2444
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311698
|
9.3 |
HIGH
|
ponsoftware
|
explzh
|
Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not proper…
|
CWE-120
Classic Buffer Overflow
|
CVE-2010-2434
|
2024-11-21 10:16 |
2010-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311699
|
5.0 |
MEDIUM
|
libtiff
|
libtiff
|
The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with u…
|
NVD-CWE-Other
|
CVE-2010-2443
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311700
|
4.3 |
MEDIUM
|
microsoft
|
internet_explorer
|
Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2442
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|