Логотип exploitDog
source:"ubuntu"
Консоль
Логотип exploitDog

exploitDog

source:"ubuntu"

Количество 62 707

Количество 62 707

ubuntu логотип

CVE-2010-4764

почти 15 лет назад

Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2010-4763

почти 15 лет назад

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

CVSS2: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4762

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4761

почти 15 лет назад

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2010-4760

почти 15 лет назад

Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.

CVSS2: 3.5
EPSS: Низкий
ubuntu логотип

CVE-2010-4759

почти 15 лет назад

Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2010-4758

почти 15 лет назад

installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.

CVSS2: 1.9
EPSS: Низкий
ubuntu логотип

CVE-2010-4756

почти 15 лет назад

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2010-4744

почти 15 лет назад

Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4743

почти 15 лет назад

Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2010-4727

почти 15 лет назад

Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4726

почти 15 лет назад

Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4725

почти 15 лет назад

Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4724

почти 15 лет назад

Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4723

почти 15 лет назад

Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4722

почти 15 лет назад

Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2010-4710

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-4708

почти 15 лет назад

The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.

CVSS2: 7.2
EPSS: Низкий
ubuntu логотип

CVE-2010-4707

почти 15 лет назад

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

CVSS2: 4.9
EPSS: Низкий
ubuntu логотип

CVE-2010-4706

почти 15 лет назад

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-4764

Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.

CVSS2: 5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4763

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users to bypass intended ACL restrictions on the (1) Status, (2) Service, and (3) Queue via selections.

CVSS2: 6.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4762

Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4761

The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.

CVSS2: 4
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4760

Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.

CVSS2: 3.5
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4759

Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.

CVSS2: 4
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4758

installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.

CVSS2: 1.9
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4756

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

CVSS2: 4
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4744

Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.

CVSS2: 10
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4743

Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.

CVSS2: 6.8
4%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4727

Smarty before 3.0.0 beta 7 does not properly handle the <?php and ?> tags, which has unspecified impact and remote attack vectors.

CVSS2: 10
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4726

Unspecified vulnerability in the math plugin in Smarty before 3.0.0 RC1 has unknown impact and remote attack vectors. NOTE: this might overlap CVE-2009-1669.

CVSS2: 10
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4725

Smarty before 3.0.0 RC3 does not properly handle an on value of the asp_tags option in the php.ini file, which has unspecified impact and remote attack vectors.

CVSS2: 10
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4724

Multiple unspecified vulnerabilities in the parser implementation in Smarty before 3.0.0 RC3 have unknown impact and remote attack vectors.

CVSS2: 10
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4723

Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.

CVSS2: 9.3
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4722

Unspecified vulnerability in the fetch plugin in Smarty before 3.0.2 has unknown impact and remote attack vectors.

CVSS2: 10
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4710

Cross-site scripting (XSS) vulnerability in the addItem method in the Menu widget in YUI before 2.9.0 allows remote attackers to inject arbitrary web script or HTML via a field that is added to a menu, related to documentation that specifies this field as a text field rather than an HTML field, a similar issue to CVE-2010-4569 and CVE-2010-4570.

CVSS2: 4.3
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4708

The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check.

CVSS2: 7.2
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4707

The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file.

CVSS2: 4.9
0%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2010-4706

The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check.

CVSS2: 4.9
0%
Низкий
почти 15 лет назад

Уязвимостей на страницу