Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0777 | 1 Ibm | 1 Websphere Application Server | 2017-08-16 | 2.6 LOW | N/A |
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file. | |||||
CVE-2010-0776 | 1 Ibm | 1 Websphere Application Server | 2017-08-16 | 5.0 MEDIUM | N/A |
The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle chunked transfer encoding during a call to response.sendRedirect, which allows remote attackers to cause a denial of service via a GET request. | |||||
CVE-2010-0786 | 1 Ibm | 1 Websphere Application Server | 2017-08-16 | 5.0 MEDIUM | N/A |
The Web Services Security component in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.13 does not properly implement the Java API for XML Web Services (aka JAX-WS), which allows remote attackers to cause a denial of service (data corruption) via a crafted JAX-WS request that leads to incorrectly encoded data. | |||||
CVE-2010-1174 | 1 Cisco | 1 Tftp Server | 2017-08-16 | 5.0 MEDIUM | N/A |
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information. | |||||
CVE-2010-1155 | 1 Irssi | 1 Irssi | 2017-08-16 | 6.8 MEDIUM | N/A |
Irssi before 0.8.15, when SSL is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) field or a Subject Alternative Name field of the X.509 certificate, which allows man-in-the-middle attackers to spoof IRC servers via an arbitrary certificate. | |||||
CVE-2010-1586 | 1 Hp | 1 System Management Homepage | 2017-08-16 | 4.3 MEDIUM | N/A |
Open redirect vulnerability in red2301.html in HP System Management Homepage (SMH) 2.x.x.x allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the RedirectUrl parameter. | |||||
CVE-2010-1591 | 1 Rising-global | 1 Rising Antivirus | 2017-08-16 | 7.2 HIGH | N/A |
Beijing Rising International Rising Antivirus 2008 through 2010 does not properly validate input to certain IOCTLs, including 0x83003C07, which allows local users to gain privileges via crafted IOCTL requests to the (1) HookCont.sys, (2) HookNtos.sys, (3) HOOKREG.sys, or (4) HookSys.sys device driver; or the (5) RsNTGdi.sys kernel module, reachable through \Device\RSNTGDI. | |||||
CVE-2010-1598 | 1 Silisoftware | 1 Phpthumb\(\) | 2017-08-16 | 6.8 MEDIUM | N/A |
phpThumb.php in phpThumb() 1.7.9 and possibly other versions, when ImageMagick is installed, allows remote attackers to execute arbitrary commands via the fltr[] parameter, as discovered in the wild in April 2010. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |||||
CVE-2010-2021 | 2 Drupal, Nicholasthompson | 2 Drupal, Global Redirect | 2017-08-16 | 5.8 MEDIUM | N/A |
Open redirect vulnerability in the Global Redirect module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.4 for Drupal, when non-clean to clean is enabled, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter. | |||||
CVE-2010-2078 | 1 Magnoware | 1 Datatrack System | 2017-08-16 | 5.0 MEDIUM | N/A |
DataTrack System 3.5 allows remote attackers to list the root directory via a (1) /%u0085/ or (2) /%u00A0/ URI. | |||||
CVE-2010-2079 | 1 Magnoware | 1 Datatrack System | 2017-08-16 | 5.0 MEDIUM | N/A |
DataTrack System 3.5 allows remote attackers to bypass intended restrictions on file extensions, and read arbitrary files, via a trailing backslash in a URI, as demonstrated by (1) web.config\ and (2) .ascx\ files. | |||||
CVE-2010-2090 | 2 Ibm, Microsoft | 3 Aix, Communications Server, Windows | 2017-08-16 | 5.0 MEDIUM | N/A |
The npb_protocol_error function in sna V5router64 in IBM Communications Server for Windows 6.1.3 and Communications Server for AIX (aka CSAIX or CS/AIX) in sna.rte before 6.3.1.2 allows remote attackers to cause a denial of service (daemon crash) via APPC data containing a GDSID variable with a GDS length that is too small. | |||||
CVE-2010-2262 | 1 Galileo Students | 1 Team Weborf | 2017-08-16 | 5.0 MEDIUM | N/A |
Galileo Students Team Weborf before 0.12.1 allows remote attackers to cause a denial of service (crash) via a crafted Range header. | |||||
CVE-2010-2310 | 1 Solarwinds | 1 Tftp Server | 2017-08-16 | 5.0 MEDIUM | N/A |
SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. | |||||
CVE-2010-2332 | 2 Apple, Impactfinancials | 2 Iphone Os, Impact Pdf Reader | 2017-08-16 | 5.0 MEDIUM | N/A |
Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request. | |||||
CVE-2010-2337 | 1 Rsa | 1 Federated Identity Manager | 2017-08-16 | 6.0 MEDIUM | N/A |
Open redirect vulnerability in RSA Federated Identity Manager 4.0 before 4.0.25 and 4.1 before 4.1.26 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unknown vectors. | |||||
CVE-2010-2352 | 3 Drupal, Karen Stevenson, Yves Chedemois | 3 Drupal, Cck, Cck | 2017-08-16 | 5.0 MEDIUM | N/A |
The Node Reference module in Content Construction Kit (CCK) module 5.x before 5.x-1.11 and 6.x before 6.x-2.7 for Drupal does not perform access checks before displaying referenced nodes, which allows remote attackers to read controlled nodes. | |||||
CVE-2010-2361 | 1 Winny | 1 Winny | 2017-08-16 | 10.0 HIGH | N/A |
Winny 2.0b7.1 and earlier does not properly process BBS information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks. | |||||
CVE-2010-2362 | 1 Winny | 1 Winny | 2017-08-16 | 10.0 HIGH | N/A |
Winny 2.0b7.1 and earlier does not properly process node information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks. | |||||
CVE-2010-2795 | 1 Joachim Fritschi | 1 Phpcas | 2017-08-16 | 4.0 MEDIUM | N/A |
phpCAS before 1.1.2 allows remote authenticated users to hijack sessions via a query string containing a crafted ticket value. |