2010 CVE Vulnerabilities

5,249 CVEs published in 2010.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2010-3782HIGH8.8obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
CVE-2010-5108HIGH7.5Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker...
CVE-2010-4664HIGH8.8In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated ...
CVE-2010-4661HIGH7.8udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2010-4657HIGH7.5PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by ...
CVE-2010-4654HIGH7.8poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
CVE-2010-3844HIGH8.8An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-size...
CVE-2010-3305HIGH8.8Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin pass...
CVE-2010-2488HIGH7.5NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connec...
CVE-2010-2450HIGH7.5The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES...
CVE-2010-2243HIGH7.5A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems ...
CVE-2010-2247HIGH7.5makepasswd 1.10 default settings generate insecure passwords
CVE-2010-2222HIGH7.5The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a d...
CVE-2010-3668HIGH7.5TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows Header Injection in the secur...
CVE-2010-3663HIGH8.8TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 contains an insecure default value o...
CVE-2010-3662HIGH8.8TYPO3 before 4.1.14, 4.2.x before 4.2.13, 4.3.x before 4.3.4 and 4.4.x before 4.4.1 allows SQL Injection on the backend.
CVE-2010-0747HIGH7.8drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-37...
CVE-2010-0737HIGH8A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permiss...
CVE-2010-2064HIGH7.1rpcbind 0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /tmp/portmap...
CVE-2010-2061HIGH7.8rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attac...
CVE-2010-1678HIGH7.5Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
CVE-2010-4241HIGH8.8Tiki Wiki CMS Groupware 5.2 has CSRF
CVE-2010-5335HIGH7.5IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of...
CVE-2010-5334HIGH7.5IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of...
CVE-2010-5331HIGH7.8In the Linux kernel before 2.6.34, a range check issue in drivers/gpu/drm/radeon/atombios.c could cause an off by one (b...

Check if your code is affected by 2010 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now