|
311701
|
4.3 |
MEDIUM
|
apple
|
webkit
|
WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and C…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2441
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311702
|
9.3 |
HIGH
|
upredsun
|
subtitle_translation_wizard
|
Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time ra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2440
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311703
|
9.3 |
HIGH
|
moreforge
|
moreamp
|
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2439
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311704
|
7.5 |
HIGH
|
laubrotel
|
g.cms_generator
|
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.
|
CWE-89
SQL Injection
|
CVE-2010-2438
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311705
|
4.3 |
MEDIUM
|
anecms
|
anecms_blog
|
Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to mo…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2437
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311706
|
7.5 |
HIGH
|
anecms
|
anecms_blog
|
SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.
|
CWE-89
SQL Injection
|
CVE-2010-2436
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311707
|
5.0 |
MEDIUM
|
salvo_tomaselli
|
weborf_http_server
|
Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.
|
CWE-20
Improper Input Validation
|
CVE-2010-2435
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311708
|
2.1 |
LOW
|
redhat
|
enterprise_virtualization_manager
|
The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allow…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2224
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311709
|
2.1 |
LOW
|
redhat
|
enterprise_virtualization_hypervisor
|
Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2223
|
2024-11-21 10:16 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311710
|
7.5 |
HIGH
|
php
|
php
|
Use-after-free vulnerability in the SplObjectStorage unserializer in PHP 5.2.x and 5.3.x through 5.3.2 allows remote attackers to execute arbitrary code or obtain sensitive information via serialized…
|
CWE-399
Resource Management Errors
|
CVE-2010-2225
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311711
|
4.3 |
MEDIUM
|
ibm
|
websphere_ilog_jrules
|
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) e…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2433
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311712
|
4.3 |
MEDIUM
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2429
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311713
|
4.3 |
MEDIUM
|
wftpserver
|
wing_ftp_server
|
Cross-site scripting (XSS) vulnerability in admin_loginok.html in the Administrator web interface in Wing FTP Server for Windows 3.5.0 and earlier allows remote attackers to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2428
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311714
|
4.0 |
MEDIUM
|
southrivertech
|
titan_ftp_server
|
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read arbitrary files, determ…
|
CWE-22
Path Traversal
|
CVE-2010-2426
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311715
|
6.5 |
MEDIUM
|
southrivertech
|
titan_ftp_server
|
Directory traversal vulnerability in TitanFTPd in South River Technologies Titan FTP Server 8.10.1125, and probably earlier versions, allows remote authenticated users to read or delete arbitrary fil…
|
CWE-22
Path Traversal
|
CVE-2010-2425
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311716
|
4.3 |
MEDIUM
|
plone
|
plone
|
Cross-site scripting (XSS) vulnerability in PortalTransforms in Plone 2.1 through 3.3.4 before hotfix 20100612 allows remote attackers to inject arbitrary web script or HTML via the safe_html transfo…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2422
|
2024-11-21 10:16 |
2010-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311717
|
5.0 |
MEDIUM
|
apple
|
cups
|
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to c…
|
CWE-399
Resource Management Errors
|
CVE-2010-2432
|
2024-11-21 10:16 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311718
|
2.6 |
LOW
|
apple
|
cups
|
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cach…
|
CWE-59
Link Following
|
CVE-2010-2431
|
2024-11-21 10:16 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311719
|
10.0 |
HIGH
|
opera
|
opera_browser
|
Multiple unspecified vulnerabilities in Opera before 10.54 have unknown impact and attack vectors related to (1) "extremely severe," (2) "highly severe," (3) "moderately severe," and (4) "less severe…
|
NVD-CWE-noinfo
|
CVE-2010-2421
|
2024-11-21 10:16 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311720
|
6.8 |
MEDIUM
|
fenrir-inc
|
activegeckobrowser
|
Multiple unspecified vulnerabilities in Fenrir Inc. ActiveGeckoBrowser 1.0.0 and 1.0.5 alpha, a module for the Sleipnir web browser, allow remote attackers to cause a denial of service (crash) and po…
|
NVD-CWE-noinfo
|
CVE-2010-2420
|
2024-11-21 10:16 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311721
|
7.5 |
HIGH
|
activewebsoftwares
|
ewebquiz
|
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbitrary SQL commands via the QuizType parameter, a different vector than CVE-2007…
|
CWE-89
SQL Injection
|
CVE-2010-2359
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311722
|
5.1 |
MEDIUM
|
jeffkilroy
|
nakid_cms
|
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute a…
|
CWE-94
Code Injection
|
CVE-2010-2358
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311723
|
7.5 |
HIGH
|
eicrasoft
|
eicra_realestate_script
|
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are ob…
|
CWE-89
SQL Injection
|
CVE-2010-2357
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311724
|
4.3 |
MEDIUM
|
pilotgroup
|
elms_pro
|
Cross-site scripting (XSS) vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the course_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2356
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311725
|
4.3 |
MEDIUM
|
pilotgroup
|
elms_pro
|
Cross-site scripting (XSS) vulnerability in error.php in Pilot Group (PG) eLMS Pro allows remote attackers to inject arbitrary web script or HTML via the message parameter. NOTE: the provenance of t…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2355
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311726
|
7.5 |
HIGH
|
pilotgroup
|
elms_pro
|
SQL injection vulnerability in subscribe.php in Pilot Group (PG) eLMS Pro allows remote attackers to execute arbitrary SQL commands via the course_id parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2354
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311727
|
5.0 |
MEDIUM
|
yves_chedemois
|
cck
|
The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field in the backend URL for the autocomplete widget, wh…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2353
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311728
|
5.0 |
MEDIUM
|
karen_stevenson yves_chedemois
|
cck
|
The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allow…
|
CWE-20
Improper Input Validation
|
CVE-2010-2352
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311729
|
10.0 |
HIGH
|
novell
|
netware
|
Stack-based buffer overflow in the CIFS.NLM driver in Netware SMB 1.0 for Novell Netware 6.5 SP8 and earlier allows remote attackers to execute arbitrary code via a Sessions Setup AndX packet with a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2351
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311730
|
6.8 |
MEDIUM
|
daniel_mealha_cabrita
|
ziproxy
|
Heap-based buffer overflow in the PNG decoder in Ziproxy 3.1.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PNG file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2350
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311731
|
5.0 |
MEDIUM
|
timhillone
|
h264webcam
|
H264WebCam 3.7 allows remote attackers to cause a denial of service (crash) via a long URI in a GET request, which triggers a NULL pointer dereference. NOTE: some of these details are obtained from …
|
CWE-399
Resource Management Errors
|
CVE-2010-2349
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311732
|
9.3 |
HIGH
|
freesoftwaretoolbox
|
batch_audio_converter
|
Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2348
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311733
|
4.9 |
MEDIUM
|
sap
|
j2ee_engine_core server_core
|
The Telnet interface in the SAP J2EE Engine Core (SAP-JEECOR) 6.40 through 7.02, and Server Core (SERVERCORE) 7.10 through 7.30 allows remote authenticated users to bypass a security check and conduc…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-2347
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311734
|
6.8 |
MEDIUM
|
odcms
|
odcms
|
Cross-site request forgery (CSRF) vulnerability in odCMS 1.06, and possibly earlier, allows remote attackers to hijack the authentication of administrators for requests that change the administrative…
|
CWE-352
Origin Validation Error
|
CVE-2010-2345
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311735
|
4.3 |
MEDIUM
|
odcms
|
odcms
|
Multiple cross-site scripting (XSS) vulnerabilities in odCMS 1.06, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Page parameter to (1) _main/index.php, (…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2344
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311736
|
9.3 |
HIGH
|
dennisre
|
audio_converter
|
Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2343
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311737
|
7.5 |
HIGH
|
dmxready
|
online_notebook_manager
|
SQL injection vulnerability in onlinenotebookmanager.asp in DMXReady Online Notebook Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2342
|
2024-11-21 10:16 |
2010-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311738
|
7.5 |
HIGH
|
ezpx
|
ezpx_photoblog
|
PHP remote file inclusion vulnerability in system/application/views/public/commentform.php in EZPX Photoblog 1.2 beta allows remote attackers to execute arbitrary PHP code via a URL in the tpl_base_d…
|
CWE-94
Code Injection
|
CVE-2010-2341
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311739
|
6.8 |
MEDIUM
|
arabportal
|
arab_portal
|
SQL injection vulnerability in members.php in Arab Portal 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the by parameter in the msearch action.
|
CWE-89
SQL Injection
|
CVE-2010-2340
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311740
|
7.5 |
HIGH
|
subdreamer
|
subdreamer
|
SQL injection vulnerability in admin/pages.php in Subdreamer CMS 3.x.x allows remote attackers to execute arbitrary SQL commands via the categoryids[] parameter in an update_pages action.
|
CWE-89
SQL Injection
|
CVE-2010-2339
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311741
|
7.5 |
HIGH
|
vunet
|
vu_web_visitor_analyst
|
Multiple SQL injection vulnerabilities in redir.asp in VU Web Visitor Analyst allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter. NOTE: some of t…
|
CWE-89
SQL Injection
|
CVE-2010-2338
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311742
|
5.0 |
MEDIUM
|
yamamah
|
yamamah
|
index.php in Yamamah Photo Gallery 1.00 allows remote attackers to obtain the source code of executable files within the web document root via the download parameter.
|
CWE-200
Information Exposure
|
CVE-2010-2336
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311743
|
7.5 |
HIGH
|
yamamah
|
yamamah
|
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to execute arbitrary SQL commands via the news parameter.
|
CWE-89
SQL Injection
|
CVE-2010-2335
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311744
|
5.0 |
MEDIUM
|
yamamah
|
yamamah
|
Directory traversal vulnerability in themes/default/download.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote attackers to read arbitrary files via a .. (dot dot) in t…
|
CWE-22
Path Traversal
|
CVE-2010-2334
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311745
|
5.0 |
MEDIUM
|
litespeedtech
|
litespeed_web_server
|
LiteSpeed Technologies LiteSpeed Web Server 4.0.x before 4.0.15 allows remote attackers to read the source code of scripts via an HTTP request with a null byte followed by a .txt file extension.
|
CWE-200
Information Exposure
|
CVE-2010-2333
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311746
|
5.0 |
MEDIUM
|
impactfinancials
|
impact_pdf_reader
|
Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.
|
CWE-20
Improper Input Validation
|
CVE-2010-2332
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311747
|
9.3 |
HIGH
|
upredsun
|
isharer_file_sharing_wizard
|
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to execute arbitrary code via a long HEAD request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2331
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311748
|
9.3 |
HIGH
|
upredsun
|
isharer_file_sharing_wizard
|
Stack-based buffer overflow in iSharer File Sharing Wizard 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Content-Length header.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2330
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311749
|
9.3 |
HIGH
|
rosoftengineering
|
rosoft_audio_converter
|
Buffer overflow in Rosoft Audio Converter 4.4.4 allows remote attackers to execute arbitrary code via a long playlist entry in a .m3u file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-2329
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311750
|
5.0 |
MEDIUM
|
ibm
|
websphere_application_server
|
The HTTP Channel in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11 allows remote attackers to cause a denial of service (NullPointerException) via a large amount of chunked data that uses…
|
NVD-CWE-Other
|
CVE-2010-2328
|
2024-11-21 10:16 |
2010-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|