Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-0367

Published Jan 21, 2010

Multiple PHP remote file inclusion vulnerabilities in BitScripts Bits Video Script 2.05 Gold Beta, and possibly 2.04, allow remote attackers to execute arbitrary PHP code via a UR…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0366

Published Jan 21, 2010

Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allow remote attackers to execut…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0365

Published Jan 21, 2010

Cross-site scripting (XSS) vulnerability in search.php in BitScripts Bits Video Script 2.04 and 2.05 Gold Beta allows remote attackers to inject arbitrary web script or HTML via t…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0364

Published Jan 21, 2010

Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation A…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4003

Published Jan 21, 2010

Multiple integer overflows in Adobe Shockwave Player before 11.5.6.606 allow remote attackers to execute arbitrary code via (1) an unspecified block type in a Shockwave file, lead…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4002

Published Jan 21, 2010

Heap-based buffer overflow in Adobe Shockwave Player before 11.5.6.606 allows remote attackers to execute arbitrary code via a crafted 3D model in a Shockwave file.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2009-4000

Published Jan 20, 2010

Directory traversal vulnerability in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to overwrite arbitrary files, and execute arbitrary code,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3999

Published Jan 20, 2010

Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0363

Published Jan 20, 2010

Cross-site scripting (XSS) vulnerability in Zeus Web Server before 4.3r5, when SSL is enabled for the admin server, allows remote attackers to inject arbitrary web script or HTML…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0362

Published Jan 20, 2010

Zeus Web Server before 4.3r5 does not use random transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0361

Published Jan 20, 2010

Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (da…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0360

Published Jan 20, 2010

Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of memory locations, via a malforme…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0359

Published Jan 20, 2010

Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a l…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0358

Published Jan 20, 2010

Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other i…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0357

Published Jan 20, 2010

Cross-site scripting (XSS) vulnerability in the Login page in IBM Lotus Web Content Management (WCM) 6.0.1.4, 6.0.1.5, and 6.0.1.6 before iFix 32; and 6.1.0.1 and 6.1.0.2 before i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0037

Published Jan 20, 2010

Buffer overflow in Image RAW in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted D…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0036

Published Jan 20, 2010

Buffer overflow in CoreAudio in Apple Mac OS X 10.5.8 and 10.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted M…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0007

Published Jan 19, 2010

net/bridge/netfilter/ebtables.c in the ebtables module in the netfilter framework in the Linux kernel before 2.6.33-rc4 does not require the CAP_NET_ADMIN capability for setting o…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4605

Published Jan 19, 2010

scripts/setup.php (aka the setup script) in phpMyAdmin 2.11.x before 2.11.10 calls the unserialize function on the values of the (1) configuration and (2) v[0] parameters, which m…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4141

Published Jan 19, 2010

Use-after-free vulnerability in the fasync_helper function in fs/fcntl.c in the Linux kernel before 2.6.33-rc4-git1 allows local users to gain privileges via vectors that include…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4012

Published Jan 19, 2010

Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, re…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7252

Published Jan 19, 2010

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 uses predictable filenames for temporary files, which has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-7251

Published Jan 19, 2010

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,401-4,425 of 4,639 CVEsPage 177 of 186