2010 CVE Vulnerabilities

5,249 CVEs published in 2010.

CVE IDSeverityCVSSDescription
CVE-2010-4532MEDIUM5.9offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which...
CVE-2010-4177MEDIUM5.5mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connecte...
CVE-2010-3857MEDIUM6.1JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
CVE-2010-3844HIGH8.8An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-size...
CVE-2010-3440MEDIUM5.5babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary fil...
CVE-2010-3305HIGH8.8Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin pass...
CVE-2010-3299MEDIUM6.5The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
CVE-2010-3292MEDIUM5.5The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encrypti...
CVE-2010-3095MEDIUM4.7mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temp...
CVE-2010-3439MEDIUM6.5It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid ...
CVE-2010-3438CRITICAL9.8libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbi...
CVE-2010-2488HIGH7.5NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connec...
CVE-2010-3359MEDIUM4.8If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. Th...
CVE-2010-2476CRITICAL9.8syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and se...
CVE-2010-2450HIGH7.5The keygen.sh script in Shibboleth SP 2.0 (located in /usr/local/etc/shibboleth by default) uses OpenSSL to create a DES...
CVE-2010-2449MEDIUM6.5Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary...
CVE-2010-2447CRITICAL9.8gitolite before 1.4.1 does not filter src/ or hooks/ from path names.
CVE-2010-2473MEDIUM6.5Drupal 6.x before 6.16 and 5.x before version 5.22 does not properly block users under certain circumstances. A user wit...
CVE-2010-2472MEDIUM4.8Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize th...
CVE-2010-2250MEDIUM6.1Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attack...
CVE-2010-2243HIGH7.5A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems ...
CVE-2010-4178MEDIUM5.5MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
CVE-2010-2471MEDIUM6.1Drupal versions 5.x and 6.x has open redirection
CVE-2010-2446CRITICAL9.8Rbot Reaction plugin allows command execution
CVE-2010-2247HIGH7.5makepasswd 1.10 default settings generate insecure passwords

Check if your code is affected by 2010 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now