Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-4278

Published Dec 2, 2010

operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the layout parameter in an…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4374

Published Dec 2, 2010

The in_mkv plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via a Matroska Video (MKV) file containing a string with a crafted…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4373

Published Dec 2, 2010

The in_mp4 plugin in Winamp before 5.6 allows remote attackers to cause a denial of service (application crash) via crafted (1) metadata or (2) albumart in an invalid MP4 file.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4372

Published Dec 2, 2010

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metad…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4371

Published Dec 2, 2010

Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4370

Published Dec 2, 2010

Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI file that triggers a buffer overflow.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4369

Published Dec 2, 2010

Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4368

Published Dec 2, 2010

awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4367

Published Dec 2, 2010

awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4329

Published Dec 2, 2010

Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4021

Published Dec 2, 2010

The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authen…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4020

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3267

Published Dec 2, 2010

Multiple SQL injection vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to execute arbitrary SQL commands via (1) the qu_id parameter to bugs.aspx,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3266

Published Dec 2, 2010

Multiple cross-site scripting (XSS) vulnerabilities in BugTracker.NET before 3.4.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the pcd paramete…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-2586

Published Dec 2, 2010

Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Table of Contents (TOC) in a (1)…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-1324

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.7.x and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers to forge GSS tokens, gain pr…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1323

Published Dec 2, 2010

MIT Kerberos 5 (aka krb5) 1.3.x, 1.4.x, 1.5.x, 1.6.x, 1.7.x, and 1.8.x through 1.8.3 does not properly determine the acceptability of checksums, which might allow remote attackers…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-5020

Published Dec 2, 2010

Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vect…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4366

Published Dec 1, 2010

Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4364

Published Dec 1, 2010

DaDaBIK 4.3 beta3, when running in a case-sensitive environment, does not include the htmLawed library, which allows remote attackers to bypass the protection mechanism for CVE-20…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4363

Published Dec 1, 2010

Multiple SQL injection vulnerabilities in contact.php in MRCGIGUY (MCG) FreeTicket 1.0.0, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL comman…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4362

Published Dec 1, 2010

Multiple SQL injection vulnerabilities in MicroNetsoft RV Dealer Website allow remote attackers to execute arbitrary SQL commands via the (1) selStock parameter to search.asp and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-4361

Published Dec 1, 2010

Cross-site scripting (XSS) vulnerability in url-gateway.php in Jurpopage 0.2.0 allows remote attackers to inject arbitrary web script or HTML via the url parameter. NOTE: the pro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4360

Published Dec 1, 2010

Multiple SQL injection vulnerabilities in index.php in Jurpopage 0.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) note and (2) pg parameters, different v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 326-350 of 4,639 CVEsPage 14 of 186