|
299661
|
- |
|
openssl fedoraproject debian canonical suse opensuse f5
|
openssl fedora debian_linux ubuntu_linux linux_enterprise_desktop opensuse linux_enterprise_server linux_enterprise nginx
|
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows r…
|
NVD-CWE-noinfo
|
CVE-2010-4180
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299662
|
- |
|
andy_armstrong
|
cgi.pm
|
Unspecified vulnerability in CGI.pm 3.50 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unknown vectors. NOTE: this issue exists…
|
NVD-CWE-noinfo
|
CVE-2010-4411
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299663
|
- |
|
andy_armstrong
|
cgi.pm cgi-simple
|
CRLF injection vulnerability in the header function in (1) CGI.pm before 3.50 and (2) Simple.pm in CGI::Simple 1.112 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct H…
|
CWE-94
Code Injection
|
CVE-2010-4410
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299664
|
- |
|
vmware
|
movie_decoder workstation player server
|
The frame decompression functionality in the VMnc media codec in VMware Movie Decoder before 6.5.5 build 328052 and 7.x before 7.1.2 build 301548, VMware Workstation 6.5.x before 6.5.5 build 328052 a…
|
CWE-94
Code Injection
|
CVE-2010-4294
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299665
|
- |
|
php
|
php
|
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows context-dependent attackers to cause a denial of service (application crash) via an…
|
CWE-189
Numeric Errors
|
CVE-2010-4409
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299666
|
- |
|
apache
|
archiva
|
Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which mak…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4408
|
2024-11-21 10:20 |
2010-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299667
|
- |
|
mono novell
|
mono moonlight
|
Mono, when Moonlight before 2.3.0.1 or 2.99.x before 2.99.0.10 is used, does not properly validate arguments to generic methods, which allows remote attackers to bypass generic constraints, and possi…
|
CWE-20
Improper Input Validation
|
CVE-2010-4254
|
2024-11-21 10:20 |
2010-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299668
|
- |
|
alberto_pittoni
|
alguest
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AlGuest 1.1c-patched allow remote attackers to inject arbitrary web script or HTML via the (1) nome (nickname), (2) messaggio (mess…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4407
|
2024-11-21 10:20 |
2010-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299669
|
- |
|
brunetton
|
littlephpgallery
|
Directory traversal vulnerability in gallery.php in Brunetton LittlePhpGallery 1.0.2, when magic_quotes_gpc is disabled, allows remote attackers to list, include, and execute arbitrary local files vi…
|
CWE-22
Path Traversal
|
CVE-2010-4406
|
2024-11-21 10:20 |
2010-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299670
|
- |
|
anything-digital
|
sh404sef
|
Cross-site scripting (XSS) vulnerability in the Yannick Gaultier sh404SEF component before 2.1.8.777 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2010-4405
|
2024-11-21 10:20 |
2010-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|