|
304971
|
- |
|
winfrigate
|
frigate_3
|
Directory traversal vulnerability in WinFrigate Frigate 3 FTP client 3.36 and earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.
|
CWE-22
Path Traversal
|
CVE-2010-3097
|
2024-11-21 10:18 |
2010-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304972
|
- |
|
softx
|
ftp_client
|
Directory traversal vulnerability in SoftX FTP Client 3.3 and possibly earlier allows remote FTP servers to write arbitrary files via "..\" (dot dot backslash) sequences in a filename.
|
CWE-22
Path Traversal
|
CVE-2010-3096
|
2024-11-21 10:18 |
2010-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304973
|
7.5 |
HIGH
Network
|
cisco
|
unified_personal_communicator
|
Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of servi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2010-3048
|
2024-11-21 10:17 |
2020-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304974
|
9.1 |
CRITICAL
Network
|
redhat
|
icedtea6
|
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services.
|
CWE-200
Information Exposure
|
CVE-2010-2783
|
2024-11-21 10:17 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304975
|
6.5 |
MEDIUM
Network
|
cisco
|
ios
|
Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot).
|
CWE-20
Improper Input Validation
|
CVE-2010-3050
|
2024-11-21 10:17 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304976
|
5.5 |
MEDIUM
Local
|
cisco
|
ios
|
Cisco IOS before 12.2(33)SXI allows local users to cause a denial of service (device reboot).
|
CWE-20
Improper Input Validation
|
CVE-2010-3049
|
2024-11-21 10:17 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304977
|
- |
|
mediawiki
|
mediawiki
|
PHP remote file inclusion vulnerability in MediaWikiParserTest.php in MediaWiki 1.16 beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via unspecified vect…
|
CWE-94
Code Injection
|
CVE-2010-2789
|
2024-11-21 10:17 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304978
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in profileinfo.php in MediaWiki before 1.15.5, when wgEnableProfileInfo is enabled, allows remote attackers to inject arbitrary web script or HTML via the fil…
|
CWE-79
Cross-site Scripting
|
CVE-2010-2788
|
2024-11-21 10:17 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304979
|
- |
|
mediawiki
|
mediawiki
|
api.php in MediaWiki before 1.15.5 does not prevent use of public caching headers for private data, which allows remote attackers to bypass intended access restrictions and obtain sensitive informati…
|
CWE-200
Information Exposure
|
CVE-2010-2787
|
2024-11-21 10:17 |
2011-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304980
|
- |
|
vmware
|
vcenter_server
|
The vCenter Tomcat Management Application in VMware vCenter Server 4.1 before Update 1 stores log-on credentials in a configuration file, which allows local users to gain privileges by reading this f…
|
CWE-255
Credentials Management
|
CVE-2010-2928
|
2024-11-21 10:17 |
2011-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|