|
299461
|
- |
|
google
|
chrome
|
Google Chrome before 8.0.552.215 does not properly handle HTML5 databases, which allows attackers to cause a denial of service (application crash) via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4484
|
2024-11-21 10:21 |
2010-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299462
|
- |
|
google
|
chrome
|
Google Chrome before 8.0.552.215 does not properly restrict read access to videos derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially s…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4483
|
2024-11-21 10:21 |
2010-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299463
|
- |
|
google
|
chrome
|
Unspecified vulnerability in Google Chrome before 8.0.552.215 allows remote attackers to bypass the pop-up blocker via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2010-4482
|
2024-11-21 10:21 |
2010-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299464
|
- |
|
clamav
|
clamav
|
Unspecified vulnerability in pdf.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF d…
|
NVD-CWE-noinfo
|
CVE-2010-4479
|
2024-11-21 10:21 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299465
|
- |
|
openbsd
|
openssh
|
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared …
|
CWE-287
Improper Authentication
|
CVE-2010-4478
|
2024-11-21 10:21 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299466
|
6.1 |
MEDIUM
Network
|
vanillaforums
|
vanilla_forums
|
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
|
-
|
CVE-2010-4266
|
2024-11-21 10:20 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299467
|
6.1 |
MEDIUM
Network
|
vanillaforums
|
vanilla_forums
|
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
|
-
|
CVE-2010-4264
|
2024-11-21 10:20 |
2021-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299468
|
5.5 |
MEDIUM
Local
|
oracle fedoraproject
|
mysql-gui-tools fedora
|
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2010-4177
|
2024-11-21 10:20 |
2019-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299469
|
5.5 |
MEDIUM
Local
|
oracle fedoraproject
|
mysql-gui-tools fedora
|
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2010-4178
|
2024-11-21 10:20 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299470
|
5.9 |
MEDIUM
Network
|
mercurial
|
mercurial
|
Mercurial before 1.6.4 fails to verify the Common Name field of SSL certificates which allows remote attackers who acquire a certificate signed by a Certificate Authority to perform a man-in-the-midd…
|
CWE-295
Improper Certificate Validation
|
CVE-2010-4237
|
2024-11-21 10:20 |
2019-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|