Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-4486

Published Dec 7, 2010

Use-after-free vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4485

Published Dec 7, 2010

Google Chrome before 8.0.552.215 does not properly restrict the generation of file dialogs, which allows remote attackers to cause a denial of service (reduced usability and possi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4484

Published Dec 7, 2010

Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to cause a denial of service (application crash) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4483

Published Dec 7, 2010

Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4482

Published Dec 7, 2010

Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the pop-up blocker via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4479

Published Dec 7, 2010

Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4412

Published Dec 7, 2010

Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml acti…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4330

Published Dec 7, 2010

Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4261

Published Dec 7, 2010

Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4260

Published Dec 7, 2010

Multiple unspecified vulnerabilities in pdf.c in libclamav in ClamAV before 0.96.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4259

Published Dec 7, 2010

Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long CHARSET_RE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4257

Published Dec 7, 2010

SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4246

Published Dec 7, 2010

Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4478

Published Dec 6, 2010

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for know…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7270

Published Dec 6, 2010

OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attacker…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4252

Published Dec 6, 2010

OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowle…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4411

Published Dec 6, 2010

Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4409

Published Dec 6, 2010

Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (appli…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4408

Published Dec 6, 2010

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a use…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 276-300 of 4,639 CVEsPage 12 of 186