Skip to main content

Year archive

CVEs published in 2010

Archive summary

4,639 CVEs published in 2010 — 1,019 Critical, 1,102 High, 2,241 Medium, 277 Low, 0 Unrated.

CVE-2010-0316

Published Jan 15, 2010

Integer overflow in Google SketchUp before 7.1 M2 allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code via a crafted SK…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0249

Published Jan 15, 2010

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and S…

CVSS 8.8 · High
evidence mentions
3
Buzz score
45.4
KEV listed

CVE-2010-0315

Published Jan 14, 2010

WebKit before r53607, as used in Google Chrome before 4.0.249.89, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0314

Published Jan 14, 2010

Apple Safari allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a st…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0313

Published Jan 14, 2010

The core_get_proxyauth_dn function in ns-slapd in Sun Java System Directory Server Enterprise Edition 7.0 allows remote attackers to cause a denial of service (NULL pointer derefe…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0310

Published Jan 14, 2010

Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software updates.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0184

Published Jan 14, 2010

The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4613

Published Jan 14, 2010

SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password param…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4355

Published Jan 14, 2010

Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of s…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-0015

Published Jan 14, 2010

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0014

Published Jan 14, 2010

System Security Services Daemon (SSSD) before 1.0.1, when the krb5 auth_provider is configured but the KDC is unreachable, allows physically proximate attackers to authenticate, v…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0002

Published Jan 14, 2010

The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows loc…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-4182

Published Jan 14, 2010

Multiple unspecified vulnerabilities in HP Web Jetadmin 10.2, when a remote SQL server is used, allow remote attackers to obtain access to data or cause a denial of service, possi…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4612

Published Jan 13, 2010

Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4611

Published Jan 13, 2010

Mort Bay Jetty 6.x through 6.1.22 and 7.0.0 writes backtrace data without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or po…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2009-4610

Published Jan 13, 2010

Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/d…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4609

Published Jan 13, 2010

The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4496

Published Jan 13, 2010

Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4495

Published Jan 13, 2010

Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary comma…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4494

Published Jan 13, 2010

AOLserver 4.5.1 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4493

Published Jan 13, 2010

Orion Application Server 2.0.7 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly ex…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-4492

Published Jan 13, 2010

WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,476-4,500 of 4,639 CVEsPage 180 of 186