Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-3904

Published Dec 6, 2010

The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addre…

CVSS 7.8 · High
evidence mentions
2
Buzz score
42.5
KEV listed

CVE-2010-3449

Published Dec 6, 2010

Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1;…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3066

Published Dec 6, 2010

The io_submit_one function in fs/aio.c in the Linux kernel before 2.6.23 allows local users to cause a denial of service (NULL pointer dereference) via a crafted io_submit system…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2639

Published Dec 6, 2010

IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4254

Published Dec 6, 2010

Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic co…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3615

Published Dec 6, 2010

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests for private DNS records via t…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3614

Published Dec 6, 2010

named in ISC BIND 9.x before 9.6.2-P3, 9.7.x before 9.7.2-P3, 9.4-ESV before 9.4-ESV-R4, and 9.6-ESV before 9.6-ESV-R3 does not properly determine the security status of an NS RRs…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3613

Published Dec 6, 2010

named in ISC BIND 9.6.2 before 9.6.2-P3, 9.6-ESV before 9.6-ESV-R3, and 9.7.x before 9.7.2-P3 does not properly handle the combination of signed negative responses and correspondi…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4407

Published Dec 6, 2010

Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlGuest 1.1c-patched allow remote attackers to inject arbitrary web script or HTML via the (1) nome (nickname),…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4406

Published Dec 6, 2010

Directory traversal vulnerability in gallery.php in Brunetton LittlePhpGallery 1.0.2, when magic_quotes_gpc is disabled, allows remote attackers to list, include, and execute arbi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4405

Published Dec 6, 2010

Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4404

Published Dec 6, 2010

SQL injection vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to execute arbitrary SQL commands via unspecified vecto…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4403

Published Dec 6, 2010

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4402

Published Dec 6, 2010

Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Register Plus plugin 3.5.1 and earlier for WordPress allow remote attackers to inject arbitrary web scri…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4401

Published Dec 6, 2010

languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4400

Published Dec 6, 2010

SQL injection vulnerability in _rights.php in DynPG CMS 4.2.0 allows remote attackers to execute arbitrary SQL commands via the giveRights_UserId parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4399

Published Dec 6, 2010

Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4313

Published Dec 2, 2010

Unrestricted file upload vulnerability in fileman_file_upload.php in Orbis CMS 1.0.2 allows remote authenticated users to execute arbitrary code by uploading a .php file, and then…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4283

Published Dec 2, 2010

PHP remote file inclusion vulnerability in extras/pandora_diag.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code via a URL in the argv[1] param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4282

Published Dec 2, 2010

Multiple directory traversal vulnerabilities in Pandora FMS before 3.1.1 allow remote attackers to include and execute arbitrary local files via (1) the page parameter to ajax.php…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4281

Published Dec 2, 2010

Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows remote attackers to execute arbitrary PHP code by using a pag…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4280

Published Dec 2, 2010

Multiple SQL injection vulnerabilities in Pandora FMS before 3.1.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the id_group parameter in an operatio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4279

Published Dec 2, 2010

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 301-325 of 4,639 CVEsPage 13 of 186