2010 CVE Vulnerabilities

5,249 CVEs published in 2010.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2010-10010MEDIUM6.1A vulnerability classified as problematic has been found in Stars Alliance PsychoStats up to 3.2.2a. This affects an unk...
CVE-2010-10008MEDIUM5.4** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in simplesamlphp simplesamlphp-module-openidprovider up to 0.8...
CVE-2010-10004MEDIUM6.1A vulnerability was found in Information Cards Module on simpleSAMLphp and classified as problematic. This issue affects...
CVE-2010-10002MEDIUM6.1** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in SimpleSAMLphp simplesamlphp-...
CVE-2010-10001MEDIUM5.5A vulnerability, which was classified as problematic, was found in Shemes GrabIt up to 1.7.2 Beta 4. This affects the co...
CVE-2010-2496MEDIUM5.5stonith-ng in pacemaker and cluster-glue passed passwords as commandline parameters, making it possible for local attack...
CVE-2010-4266MEDIUM6.1It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
CVE-2010-4264MEDIUM6.1It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitra...
CVE-2010-3300MEDIUM5.9It was found that all OWASP ESAPI for Java up to version 2.0 RC2 are vulnerable to padding oracle attacks.
CVE-2010-4658MEDIUM5.3statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
CVE-2010-3917MEDIUM6.5Google Chrome before 3.0 does not properly handle XML documents, which allows remote attackers to obtain sensitive infor...
CVE-2010-4662MEDIUM6.1PmWiki before 2.2.21 has XSS.
CVE-2010-4659MEDIUM6.1Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
CVE-2010-4817MEDIUM5.5pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2010-4653MEDIUM6.5An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
CVE-2010-4532MEDIUM5.9offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which...
CVE-2010-4177MEDIUM5.5mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connecte...
CVE-2010-3857MEDIUM6.1JBoss BRMS before 5.1.0 has a XSS vulnerability via asset=UUID parameter.
CVE-2010-3440MEDIUM5.5babiloo 2.0.9 before 2.0.11 creates temporary files with predictable names when downloading and unpacking dictionary fil...
CVE-2010-3299MEDIUM6.5The encrypt/decrypt functions in Ruby on Rails 2.3 are vulnerable to padding oracle attacks.
CVE-2010-3292MEDIUM5.5The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encrypti...
CVE-2010-3095MEDIUM4.7mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temp...
CVE-2010-3439MEDIUM6.5It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid ...
CVE-2010-3359MEDIUM4.8If LD_LIBRARY_PATH is undefined in gargoyle-free before 2009-08-25, the variable will point to the current directory. Th...
CVE-2010-2449MEDIUM6.5Gource through 0.26 logs to a predictable file name (/tmp/gource-$UID.tmp), enabling attackers to overwrite an arbitrary...

Check if your code is affected by 2010 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now