Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-3767

Published Dec 10, 2010

Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary cod…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3766

Published Dec 10, 2010

Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors i…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4518

Published Dec 9, 2010

Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4517

Published Dec 9, 2010

SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4516

Published Dec 9, 2010

Multiple cross-site scripting (XSS) vulnerabilities in the JXtended Comments component before 1.3.1 for Joomla allow remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4515

Published Dec 9, 2010

Cross-site scripting (XSS) vulnerability in Citrix Web Interface 5.0, 5.1, and 5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a differ…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4514

Published Dec 9, 2010

Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __V…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4513

Published Dec 9, 2010

Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) file parame…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4512

Published Dec 9, 2010

Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4511

Published Dec 9, 2010

Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message."

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4509

Published Dec 9, 2010

Multiple unspecified vulnerabilities in Movable Type 4.x before 4.35 and 5.x before 5.04 have unknown impact and attack vectors related to the (1) mt:AssetProperty and (2) mt:Entr…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4508

Published Dec 9, 2010

The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4009

Published Dec 9, 2010

Integer overflow in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3922

Published Dec 9, 2010

SQL injection vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3921

Published Dec 9, 2010

Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3802

Published Dec 9, 2010

Integer signedness error in Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) v…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3801

Published Dec 9, 2010

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3800

Published Dec 9, 2010

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted PICT file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-2235

Published Dec 9, 2010

template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Pyt…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-1508

Published Dec 9, 2010

Heap-based buffer overflow in Apple QuickTime before 7.6.9 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafte…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0530

Published Dec 9, 2010

Apple QuickTime before 7.6.9 on Windows sets weak permissions for the Apple Computer directory in the profile of a user account, which allows local users to obtain sensitive infor…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-5021

Published Dec 9, 2010

Cobbler before 1.6.1 does not properly determine whether an installation has the default password, which makes it easier for attackers to obtain access by using this password.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4505

Published Dec 8, 2010

Multiple SQL injection vulnerabilities in login.php in Injader 2.4.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) un an…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4504

Published Dec 8, 2010

Multiple cross-site scripting (XSS) vulnerabilities in eSyndiCat Directory 2.3 allow remote attackers to inject arbitrary web script or HTML via the title parameter to (1) suggest…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 4,639 CVEsPage 10 of 186