|
299911
|
- |
|
horde
|
imp groupware
|
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3695
|
2024-11-21 10:19 |
2011-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299912
|
- |
|
openslp vmware
|
openslp esxi esx
|
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.…
|
NVD-CWE-noinfo
|
CVE-2010-3609
|
2024-11-21 10:19 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299913
|
- |
|
apache
|
tomcat
|
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write …
|
NVD-CWE-Other
|
CVE-2010-3718
|
2024-11-21 10:19 |
2011-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299914
|
- |
|
modxcms
|
evolution
|
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE…
|
CWE-22
Path Traversal
|
CVE-2010-3930
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299915
|
- |
|
modxcms
|
evolution
|
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
|
CWE-89
SQL Injection
|
CVE-2010-3929
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299916
|
- |
|
apache
|
couchdb
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3854
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299917
|
- |
|
symantec
|
im_manager
|
Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified param…
|
CWE-94
Code Injection
|
CVE-2010-3719
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299918
|
- |
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current…
|
CWE-22
Path Traversal
|
CVE-2010-3689
|
2024-11-21 10:19 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299919
|
- |
|
lunascape
|
lunascape
|
Untrusted search path vulnerability in Lunascape before 6.4.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
|
NVD-CWE-Other
|
CVE-2010-3927
|
2024-11-21 10:19 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299920
|
- |
|
linux-pam
|
linux-pam
|
pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might …
|
NVD-CWE-Other
|
CVE-2010-3853
|
2024-11-21 10:19 |
2011-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|