|
303041
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal
|
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2250
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303042
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/curren…
|
CWE-20
Improper Input Validation
|
CVE-2010-2243
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303043
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal versions 5.x and 6.x has open redirection
|
CWE-601
Open Redirect
|
CVE-2010-2471
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303044
|
9.8 |
CRITICAL
Network
|
ruby-rbot
|
rbot
|
Rbot Reaction plugin allows command execution
|
CWE-20
Improper Input Validation
|
CVE-2010-2446
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303045
|
7.5 |
HIGH
Network
|
makepasswd_project
|
makepasswd
|
makepasswd 1.10 default settings generate insecure passwords
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2010-2247
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303046
|
7.5 |
HIGH
Network
|
redhat
|
directory_server 389_directory_server
|
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-2222
|
2024-11-21 10:16 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303047
|
9.1 |
CRITICAL
Network
|
redhat
|
icedtea6
|
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
|
CWE-863
Incorrect Authorization
|
CVE-2010-2548
|
2024-11-21 10:16 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303048
|
6.5 |
MEDIUM
Network
|
mumble debian
|
mumble debian_linux
|
Mumble: murmur-server has DoS due to malformed client query
|
CWE-20
Improper Input Validation
|
CVE-2010-2490
|
2024-11-21 10:16 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303049
|
7.5 |
HIGH
Network
|
apache
|
derby
|
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
|
CWE-284
Improper Access Control
|
CVE-2010-2232
|
2024-11-21 10:16 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303050
|
7.4 |
HIGH
Network
|
apache
|
wink
|
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service via a crafted XML document.
|
CWE-611
XXE
|
CVE-2010-2245
|
2024-11-21 10:16 |
2017-08-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|