2010 CVE Vulnerabilities

5,249 CVEs published in 2010.

CVE IDSeverityCVSSDescription
CVE-2010-3877The get_name function in net/tipc/socket.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain structure...
CVE-2010-3876net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, whi...
CVE-2010-3875The ax25_getname function in net/ax25/af_ax25.c in the Linux kernel before 2.6.37-rc2 does not initialize a certain stru...
CVE-2010-3873The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote atta...
CVE-2010-3448drivers/platform/x86/thinkpad_acpi.c in the Linux kernel before 2.6.34 on ThinkPad devices, when the X.Org X server is u...
CVE-2010-1677MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed wit...
CVE-2010-4642Cross-site scripting (XSS) vulnerability in XWiki Enterprise before 2.5 allows remote attackers to inject arbitrary web ...
CVE-2010-4641SQL injection vulnerability in XWiki Enterprise before 2.5 allows remote attackers to execute arbitrary SQL commands via...
CVE-2010-4640Multiple cross-site scripting (XSS) vulnerabilities in XWiki Watch 1.0 allow remote attackers to inject arbitrary web sc...
CVE-2010-4639SQL injection vulnerability in index.php in MySource Matrix allows remote attackers to execute arbitrary SQL commands vi...
CVE-2010-4638SQL injection vulnerability in the submitSurvey function in controller.php in JQuarks4s (com_jquarks4s) component 1.0.0 ...
CVE-2010-4637Cross-site scripting (XSS) vulnerability in feedlist/handler_image.php in the FeedList plugin 2.61.01 for WordPress allo...
CVE-2010-4636SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary ...
CVE-2010-4635SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execut...
CVE-2010-4634Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in ...
CVE-2010-4633SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via ...
CVE-2010-4632Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL command...
CVE-2010-4631Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary...
CVE-2010-4630Cross-site scripting (XSS) vulnerability in pages/admin/surveys/create.php in the WP Survey And Quiz Tool plugin 1.2.1 f...
CVE-2010-4629MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows rem...
CVE-2010-4628member.php in MyBB (aka MyBulletinBoard) before 1.4.12 makes a certain superfluous call to the SQL COUNT function, which...
CVE-2010-4627Cross-site request forgery (CSRF) vulnerability in usercp2.php in MyBB (aka MyBulletinBoard) before 1.4.12 allows remote...
CVE-2010-4626The my_rand function in functions.php in MyBB (aka MyBulletinBoard) before 1.4.12 does not properly use the PHP mt_rand ...
CVE-2010-4625MyBB (aka MyBulletinBoard) before 1.4.12 does not properly handle a configuration with a visible forum that contains hid...
CVE-2010-4624MyBB (aka MyBulletinBoard) before 1.4.12 allows remote authenticated users to bypass intended restrictions on the number...

Check if your code is affected by 2010 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now