Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 227

Количество 389 227

nvd логотип

CVE-2010-2452

около 16 лет назад

Directory traversal vulnerability in the DCC functionality in KVIrc 3.4 and 4.0 allows remote attackers to overwrite arbitrary files via unknown vectors.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2451

около 16 лет назад

Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2010-2450

почти 7 лет назад

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2449

почти 7 лет назад

Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-2448

около 16 лет назад

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

CVSS2: 3.5
EPSS: Низкий
nvd логотип

CVE-2010-2447

почти 7 лет назад

gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2010-2446

почти 7 лет назад

Rbot Reaction plugin allows command execution

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2010-2445

около 16 лет назад

freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2010-2444

около 16 лет назад

parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2443

около 16 лет назад

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2442

около 16 лет назад

Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2010-2441

около 16 лет назад

WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2440

около 16 лет назад

Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2439

около 16 лет назад

Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2438

около 16 лет назад

SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2437

около 16 лет назад

Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2436

около 16 лет назад

SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2010-2435

около 16 лет назад

Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-2434

около 16 лет назад

Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2433

около 16 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-2452

Directory traversal vulnerability in the DCC functionality in KVIrc 3.4 and 4.0 allows remote attackers to overwrite arbitrary files via unknown vectors.

CVSS2: 9.3
4%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2451

Multiple format string vulnerabilities in the DCC functionality in KVIrc 3.4 and 4.0 have unspecified impact and remote attack vectors.

CVSS2: 10
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2450

The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES private key which is placed in sp-key.pm. It relies on the root umask (default 22) instead of chmoding the resulting file itself, so the generated private key is world readable by default.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2449

Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary file via a symlink attack.

CVSS3: 6.5
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2448

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

CVSS2: 3.5
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2447

gitolite before 1.4.1 does not filter src/ or hooks/ from path names.

CVSS3: 9.8
2%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2446

Rbot Reaction plugin allows command execution

CVSS3: 9.8
3%
Низкий
почти 7 лет назад
nvd логотип
CVE-2010-2445

freeciv 2.2 before 2.2.1 and 2.3 before 2.3.0 allows attackers to read arbitrary files or execute arbitrary commands via a scenario that contains Lua functionality, related to the (1) os, (2) io, (3) package, (4) dofile, (5) loadfile, (6) loadlib, (7) module, and (8) require modules or functions.

CVSS2: 10
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2444

parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2443

The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with undefined strip offsets, related to the TIFFVGetField function.

CVSS2: 5
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2442

Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."

CVSS2: 4.3
12%
Средний
около 16 лет назад
nvd логотип
CVE-2010-2441

WebKit does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets," a different vulnerability than CVE-2010-1126, CVE-2010-1422, and CVE-2010-2295.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2440

Stack-based buffer overflow in st-wizard.exe in Subtitle Translation Wizard 3.0 allows user-assisted remote attackers to execute arbitrary code via a crafted SRT file with a long line after a time range. NOTE: some of these details are obtained from third party information.

CVSS2: 9.3
6%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2439

Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list (.maf file).

CVSS2: 9.3
6%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2438

SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang parameter to the default URI, probably index.php.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2437

Cross-site scripting (XSS) vulnerability in class/tools.class.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the comment variable to modules/blog/index.php.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2436

SQL injection vulnerability in modules/blog/index.php in AneCMS Blog 1.3 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO.

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2435

Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection HTTP header, and possibly other headers.

CVSS2: 5
6%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2434

Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.

CVSS2: 9.3
5%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2433

Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow remote attackers to inject arbitrary web script or HTML via an RTS URL to (1) explore/explore.jsp, (2) compose/compose.jsp, or (3) home.jsp in faces/.

CVSS2: 4.3
1%
Низкий
около 16 лет назад

Уязвимостей на страницу