Skip to main content

CWE archive

CWE-200 CVEs

Programmatic archive

10,558 CVEs tagged with CWE-200359 Critical, 2,065 High, 6,937 Medium, 1,193 Low, 4 Unrated.

CVE-2010-1149

Published Apr 12, 2010

probers/udisks-dm-export.c in udisks before 1.0.1 exports UDISKS_DM_TARGETS_PARAMS information to udev even for a crypt UDISKS_DM_TARGETS_TYPE, which allows local users to discove…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1310

Published Apr 8, 2010

Opera 10.50 allows remote attackers to obtain sensitive information via crafted XSLT constructs, which cause Opera to return cached contents of other pages.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0750

Published Apr 6, 2010

pkexec.c in pkexec in libpolkit in PolicyKit 0.96 allows local users to determine the existence of arbitrary files via the argument.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0009

Published Apr 5, 2010

Apache CouchDB 0.8.0 through 0.10.1 allows remote attackers to obtain sensitive information by measuring the completion time of operations that verify (1) hashes or (2) passwords.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0826

Published Apr 5, 2010

The Free Software Foundation (FSF) Berkeley DB NSS module (aka libnss-db) 2.2.3pre1 reads the DB_CONFIG file in the current working directory, which allows local users to obtain s…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-1230

Published Apr 1, 2010

Google Chrome before 4.1.249.1036 does not have the expected behavior for attempts to delete Web SQL Databases and clear the Strict Transport Security (STS) state, which has unspe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0523

Published Mar 30, 2010

Wiki Server in Apple Mac OS X 10.5.8 does not restrict the file types of uploaded files, which allows remote attackers to obtain sensitive information or possibly have unspecified…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1126

Published Mar 26, 2010

The JavaScript implementation in WebKit allows remote attackers to send selected keystrokes to a form field in a hidden frame, instead of the intended form field in a visible fram…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1125

Published Mar 26, 2010

The JavaScript implementation in Mozilla Firefox 3.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to send selected keystrokes to a for…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-1007

Published Mar 19, 2010

Unspecified vulnerability in the Power Extension Manager (ch_lightem) extension 1.0.34 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unknown ve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0042

Published Mar 15, 2010

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to ob…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0041

Published Mar 15, 2010

ImageIO in Apple Safari before 4.0.5 and iTunes before 9.1 on Windows does not ensure that memory access is associated with initialized memory, which allows remote attackers to ob…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0790

Published Mar 10, 2010

sutil/ncpumount.c in ncpumount in ncpfs 2.2.6 produces certain detailed error messages about the results of privileged file-access attempts, which allows local users to determine…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0572

Published Mar 5, 2010

Cisco Digital Media Manager (DMM) before 5.2 allows remote authenticated users to discover Cisco Digital Media Player credentials via vectors related to reading a (1) error log or…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2010-0667

Published Feb 26, 2010

MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0119

Published Feb 25, 2010

Bournal before 1.4.1 on FreeBSD 8.0, when the -K option is used, places a ccrypt key on the command line, which allows local users to obtain sensitive information by listing the p…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-0670

Published Feb 22, 2010

Unspecified vulnerability in the IP-Tech JQuarks (com_jquarks) Component before 0.2.4 for Joomla! allows attackers to obtain the installation path for Joomla! via unknown vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0663

Published Feb 18, 2010

The ParamTraits<SkBitmap>::Read function in common/common_param_traits.cc in Google Chrome before 4.0.249.78 does not initialize the memory locations that will hold bitmap data, w…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0660

Published Feb 18, 2010

Google Chrome before 4.0.249.78 sends an https URL in the Referer header of an http request in certain circumstances involving https to http redirection, which allows remote HTTP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0656

Published Feb 18, 2010

WebKit before r51295, as used in Google Chrome before 4.0.249.78, presents a directory-listing page in response to an XMLHttpRequest for a file:/// URL that corresponds to a direc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 9,951-9,975 of 10,558 CVEsPage 399 of 423