|
302991
|
- |
|
adobe
|
flash_player
|
An unspecified ActiveX control in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 (Flash10h.ocx) on Windows allows remote attackers to execute arbitrary code or cause a denial of serv…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-3637
|
2024-11-21 10:19 |
2010-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302992
|
- |
|
adobe
|
flash_player
|
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris, and 10.1.95.1 on Android, does not properly handle unspecified encodings during the parsing o…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3636
|
2024-11-21 10:19 |
2010-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302993
|
- |
|
justsystems
|
ichitaro
|
Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3915.
|
NVD-CWE-noinfo
|
CVE-2010-3916
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302994
|
- |
|
justsystems
|
ichitaro
|
Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than CVE-2010-3916.
|
NVD-CWE-noinfo
|
CVE-2010-3915
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302995
|
- |
|
redhat
|
luci
|
The default configuration of Luci 0.22.4 and earlier in Red Hat Conga uses "[INSERT SECRET HERE]" as its secret key for cookies, which makes it easier for remote attackers to bypass repoze.who authen…
|
CWE-287
Improper Authentication
|
CVE-2010-3852
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302996
|
- |
|
poppler foolabs kde glyphandcog
|
poppler xpdf kdegraphics xpdfreader
|
The FoFiType1::parse function in fofi/FoFiType1.cc in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, kdegraphics, and possibly other products allows co…
|
CWE-20
Improper Input Validation
|
CVE-2010-3704
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302997
|
- |
|
poppler
|
poppler
|
The PostScriptFunction::PostScriptFunction function in poppler/Function.cc in the PDF parser in poppler 0.8.7 and possibly other versions up to 0.15.1, and possibly other products, allows context-dep…
|
CWE-20
Improper Input Validation
|
CVE-2010-3703
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302998
|
- |
|
freedesktop xpdfreader apple fedoraproject opensuse suse debian redhat canonical
|
poppler xpdf cups fedora opensuse linux_enterprise_server debian_linux enterprise_linux_server enterprise_linux_workstation enterprise_linux_desktop ubuntu_linux
|
The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent atta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-3702
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302999
|
- |
|
transware
|
active\!_mail
|
CRLF injection vulnerability in TransWARE Active! mail 6 build 6.40.010047750 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unsp…
|
CWE-94
Code Injection
|
CVE-2010-3913
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303000
|
- |
|
jsecurity apache
|
jsecurity shiro
|
Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restric…
|
CWE-22
Path Traversal
|
CVE-2010-3863
|
2024-11-21 10:19 |
2010-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|