|
299741
|
- |
|
microsoft
|
.net_framework
|
The x86 JIT compiler in Microsoft .NET Framework 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 does not properly compile function calls, which allows remote attackers to execute arbitrary code via (1) a crafted X…
|
CWE-20
Improper Input Validation
|
CVE-2010-3958
|
2024-11-21 10:19 |
2011-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299742
|
- |
|
horde
|
groupware dynamic_imp
|
Cross-site scripting (XSS) vulnerability in Horde Dynamic IMP (DIMP) before 1.1.5, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3693
|
2024-11-21 10:19 |
2011-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299743
|
- |
|
horde
|
imp groupware
|
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Edition before 1.2.7, allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3695
|
2024-11-21 10:19 |
2011-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299744
|
- |
|
openslp vmware
|
openslp esxi esx
|
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Service Location Protocol daemon (SLPD) in VMware ESX 4.0 and 4.1 and ESXi 4.0 and 4.…
|
NVD-CWE-noinfo
|
CVE-2010-3609
|
2024-11-21 10:19 |
2011-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299745
|
- |
|
apache
|
tomcat
|
Apache Tomcat 7.0.0 through 7.0.3, 6.0.x, and 5.5.x, when running within a SecurityManager, does not make the ServletContext attribute read-only, which allows local web applications to read or write …
|
NVD-CWE-Other
|
CVE-2010-3718
|
2024-11-21 10:19 |
2011-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299746
|
- |
|
modxcms
|
evolution
|
Directory traversal vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to read arbitrary files via unspecified vectors related to AjaxSearch, a different vulnerability than CVE…
|
CWE-22
Path Traversal
|
CVE-2010-3930
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299747
|
- |
|
modxcms
|
evolution
|
SQL injection vulnerability in MODx Evolution 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via unknown vectors related to AjaxSearch.
|
CWE-89
SQL Injection
|
CVE-2010-3929
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299748
|
- |
|
apache
|
couchdb
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration interface (aka Futon) in Apache CouchDB 0.8.0 through 1.0.1 allow remote attackers to inject arbitrary web script or HTML…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3854
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299749
|
- |
|
symantec
|
im_manager
|
Eval injection vulnerability in IMAdminSchedTask.asp in the administrative interface for Symantec IM Manager 8.4.16 and earlier allows remote attackers to execute arbitrary code via unspecified param…
|
CWE-94
Code Injection
|
CVE-2010-3719
|
2024-11-21 10:19 |
2011-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299750
|
- |
|
apache debian canonical
|
openoffice debian_linux ubuntu_linux
|
soffice in OpenOffice.org (OOo) 3.x before 3.3 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current…
|
CWE-22
Path Traversal
|
CVE-2010-3689
|
2024-11-21 10:19 |
2011-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|