|
301131
|
- |
|
nullsoft
|
winamp
|
Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allocation of memory for NSV metadata, a different vul…
|
CWE-189
Numeric Errors
|
CVE-2010-4372
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301132
|
- |
|
nullsoft
|
winamp
|
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-4371
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301133
|
- |
|
nullsoft
|
winamp
|
Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI file that triggers a buffer overflow.
|
CWE-189
Numeric Errors
|
CVE-2010-4370
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301134
|
- |
|
awstats
|
awstats
|
Directory traversal vulnerability in AWStats before 7.0 allows remote attackers to have an unspecified impact via a crafted LoadPlugin directory.
|
CWE-22
Path Traversal
|
CVE-2010-4369
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301135
|
- |
|
awstats
|
awstats
|
awstats.cgi in AWStats before 7.0 on Windows accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located at a UNC sh…
|
CWE-94
Code Injection
|
CVE-2010-4368
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301136
|
- |
|
awstats
|
awstats
|
awstats.cgi in AWStats before 7.0 accepts a configdir parameter in the URL, which allows remote attackers to execute arbitrary commands via a crafted configuration file located on a (1) WebDAV server…
|
CWE-94
Code Injection
|
CVE-2010-4367
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301137
|
- |
|
phpmyadmin
|
phpmyadmin
|
Cross-site scripting (XSS) vulnerability in the PMA_linkOrButton function in libraries/common.lib.php in the database (db) search script in phpMyAdmin 2.11.x before 2.11.11.1 and 3.x before 3.3.8.1 a…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4329
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301138
|
- |
|
mit
|
kerberos_5
|
The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.7 does not properly restrict the use of TGT credentials for armoring TGS requests, which might allow remote authenticated users to imp…
|
CWE-264 CWE-16
Permissions, Privileges, and Access Controls Configuration
|
CVE-2010-4021
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301139
|
6.3 |
MEDIUM
Network
|
mit
|
kerberos_5
|
MIT Kerberos 5 (aka krb5) 1.8.x through 1.8.3 does not reject RC4 key-derivation checksums, which might allow remote authenticated users to forge a (1) AD-SIGNEDPATH or (2) AD-KDC-ISSUED signature, a…
|
CWE-310
Cryptographic Issues
|
CVE-2010-4020
|
2024-11-21 10:20 |
2010-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
301140
|
- |
|
abk-soft
|
chameleon_social_networking
|
Multiple cross-site scripting (XSS) vulnerabilities in forum_new_topic.php in Chameleon Social Networking allow remote attackers to inject arbitrary web script or HTML via the (1) thread_title and (2…
|
CWE-79
Cross-site Scripting
|
CVE-2010-4366
|
2024-11-21 10:20 |
2010-12-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|