Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-0341

Published Jan 15, 2010

SQL injection vulnerability in the BB Simple Jobs (bb_simplejobs) extension 0.1.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0340

Published Jan 15, 2010

SQL injection vulnerability in the MJS Event Pro (mjseventpro) extension 0.2.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0339

Published Jan 15, 2010

SQL injection vulnerability in the User Links (vm19_userlinks) extension 0.1.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vect…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0338

Published Jan 15, 2010

SQL injection vulnerability in the TT_Products editor (ttpedit) extension 0.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vec…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0337

Published Jan 15, 2010

SQL injection vulnerability in the tt_news Mail alert (dl3_tt_news_alerts) extension 0.2.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unsp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0336

Published Jan 15, 2010

Unspecified vulnerability in the kiddog_mysqldumper (kiddog_mysqldumper) extension 0.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0333

Published Jan 15, 2010

SQL injection vulnerability in the Helpdesk (mg_help) extension 1.1.6 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0330

Published Jan 15, 2010

SQL injection vulnerability in the Googlemaps for tt_news (jf_easymaps) extension 1.0.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspeci…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0329

Published Jan 15, 2010

SQL injection vulnerability in the powermail extension 1.5.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors related to the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0328

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in the Unit Converter (cs2_unitconv) extension 1.0.4 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0325

Published Jan 15, 2010

Unspecified vulnerability in the SB Folderdownload (sb_folderdownload) extension 0.2.2 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0324

Published Jan 15, 2010

SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecifi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0323

Published Jan 15, 2010

Unspecified vulnerability in the Photo Book (goof_fotoboek) extension 1.7.14 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown attack vecto…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0321

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in jobs/index.php in Jamit Job Board 3.0 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0320

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in submitlink.php in Glitter Central Script allows remote attackers to inject arbitrary web script or HTML via the catid parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0319

Published Jan 15, 2010

Cross-site scripting (XSS) vulnerability in index.php in Docmint 1.0 and 2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: some of th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0318

Published Jan 15, 2010

The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the or…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0317

Published Jan 15, 2010

Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 4,451-4,475 of 4,639 CVEsPage 179 of 186