|
305151
|
4.8 |
MEDIUM
Network
|
drupal
|
drupal
|
Locale module and dependent contributed modules in Drupal 6.x before 6.16 and 5.x before version 5.22 do not sanitize the display of language codes, native and English language names properly which c…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2472
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305152
|
6.1 |
MEDIUM
Network
|
drupal
|
drupal
|
Drupal 5.x and 6.x before 6.16 uses a user-supplied value in output during site installation which could allow an attacker to craft a URL and perform a cross-site scripting attack.
|
CWE-79
Cross-site Scripting
|
CVE-2010-2250
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305153
|
7.5 |
HIGH
Network
|
linux
|
linux_kernel
|
A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/curren…
|
CWE-20
Improper Input Validation
|
CVE-2010-2243
|
2024-11-21 10:16 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305154
|
6.1 |
MEDIUM
Network
|
drupal debian
|
drupal debian_linux
|
Drupal versions 5.x and 6.x has open redirection
|
CWE-601
Open Redirect
|
CVE-2010-2471
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305155
|
9.8 |
CRITICAL
Network
|
ruby-rbot
|
rbot
|
Rbot Reaction plugin allows command execution
|
CWE-20
Improper Input Validation
|
CVE-2010-2446
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305156
|
7.5 |
HIGH
Network
|
makepasswd_project
|
makepasswd
|
makepasswd 1.10 default settings generate insecure passwords
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2010-2247
|
2024-11-21 10:16 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305157
|
7.5 |
HIGH
Network
|
redhat
|
directory_server 389_directory_server
|
The _ger_parse_control function in Red Hat Directory Server 8 and the 389 Directory Server allows attackers to cause a denial of service (NULL pointer dereference) via a crafted search query.
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-2222
|
2024-11-21 10:16 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305158
|
9.1 |
CRITICAL
Network
|
redhat
|
icedtea6
|
IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files.
|
CWE-863
Incorrect Authorization
|
CVE-2010-2548
|
2024-11-21 10:16 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305159
|
6.5 |
MEDIUM
Network
|
mumble debian
|
mumble debian_linux
|
Mumble: murmur-server has DoS due to malformed client query
|
CWE-20
Improper Input Validation
|
CVE-2010-2490
|
2024-11-21 10:16 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305160
|
7.5 |
HIGH
Network
|
apache
|
derby
|
In Apache Derby 10.1.2.1, 10.2.2.0, 10.3.1.4, and 10.4.1.3, Export processing may allow an attacker to overwrite an existing file.
|
CWE-284
Improper Access Control
|
CVE-2010-2232
|
2024-11-21 10:16 |
2017-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|