Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-4503

Published Dec 8, 2010

SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in an export action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4502

Published Dec 8, 2010

Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of service (pool corruption) and execute arbitrary code via cr…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4012

Published Dec 8, 2010

Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call scre…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3860

Published Dec 8, 2010

IcedTea 1.7.x before 1.7.6, 1.8.x before 1.8.3, and 1.9.x before 1.9.2, as based on OpenJDK 6, declares multiple sensitive variables as public, which allows remote attackers to ob…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3699

Published Dec 8, 2010

The backend driver in Xen 3.x allows guest OS users to cause a denial of service via a kernel thread leak, which prevents the device and guest OS from being shut down or create a…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4109

Published Dec 8, 2010

Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4108

Published Dec 8, 2010

HP HP-UX B.11.11, B.11.23, and B.11.31 does not properly support threaded processes, which allows remote authenticated users to cause a denial of service via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3372

Published Dec 8, 2010

Untrusted search path vulnerability in NorduGrid Advanced Resource Connector (ARC) before 0.8.3 allows local users to gain privileges via vectors related to the LD_LIBRARY_PATH en…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4500

Published Dec 8, 2010

Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL comman…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4480

Published Dec 8, 2010

error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted BBcode tag containing "…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4179

Published Dec 7, 2010

The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4171

Published Dec 7, 2010

The staprun runtime tool in SystemTap 1.3 does not verify that a module to unload was previously loaded by SystemTap, which allows local users to cause a denial of service (unload…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4170

Published Dec 7, 2010

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privileges by setting the MODPROBE_OP…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4150

Published Dec 7, 2010

Double free vulnerability in the imap_do_open function in the IMAP extension (ext/imap/php_imap.c) in PHP 5.2 before 5.2.15 and 5.3 before 5.3.4 allows attackers to cause a denial…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4493

Published Dec 7, 2010

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service via vectors related to the handling of mouse dragging events.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4492

Published Dec 7, 2010

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involvi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4491

Published Dec 7, 2010

Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted ext…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4490

Published Dec 7, 2010

Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via malformed video content tha…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4489

Published Dec 7, 2010

libvpx, as used in Google Chrome before 8.0.552.215 and possibly other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebM video…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4488

Published Dec 7, 2010

Google Chrome before 8.0.552.215 does not properly handle HTTP proxy authentication, which allows remote attackers to cause a denial of service (application crash) via unspecified…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4487

Published Dec 7, 2010

Incomplete blacklist vulnerability in Google Chrome before 8.0.552.215 on Linux and Mac OS X allows remote attackers to have an unspecified impact via a "dangerous file."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 4,639 CVEsPage 11 of 186