2010 CVE Vulnerabilities

5,249 CVEs published in 2010.

CVE IDSeverityCVSSDescription
CVE-2010-3843HIGH7.8The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file...
CVE-2010-5116Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2010-5115Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2010-5114Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2010-5113Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2010-5112Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2010-4658MEDIUM5.3statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
CVE-2010-3917MEDIUM6.5Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive infor...
CVE-2010-5304HIGH7.5A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A ...
CVE-2010-4815CRITICAL9.8Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
CVE-2010-4662MEDIUM6.1PmWiki before 2.2.21 has XSS.
CVE-2010-3295Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2010-3048HIGH7.5Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform ...
CVE-2010-3282LOW3.3389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, whe...
CVE-2010-3782HIGH8.8obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
CVE-2010-4659MEDIUM6.1Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
CVE-2010-4660CRITICAL9.8Unspecified vulnerability in statusnet through 2010 due to the way addslashes are used in SQL string escapes..
CVE-2010-5108HIGH7.5Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker...
CVE-2010-4817MEDIUM5.5pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2010-4664HIGH8.8In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated ...
CVE-2010-4661HIGH7.8udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2010-4657HIGH7.5PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by ...
CVE-2010-4654HIGH7.8poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
CVE-2010-4653MEDIUM6.5An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
CVE-2010-4533CRITICAL9.8offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 prot...

Check if your code is affected by 2010 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now