|
304531
|
- |
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The tcf_act_police_dump function in net/sched/act_police.c in the actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc4 does not properly initialize certa…
|
CWE-399
Resource Management Errors
|
CVE-2010-3477
|
2024-11-21 10:18 |
2010-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304532
|
- |
|
drupal
|
drupal
|
Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.18 allow remote authenticated users with certain privileges to inject arbitrary web script or HTML via (1) an action descrip…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3094
|
2024-11-21 10:18 |
2010-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304533
|
- |
|
drupal
|
drupal
|
The comment module in Drupal 5.x before 5.23 and 6.x before 6.18 allows remote authenticated users with certain privileges to bypass intended access restrictions and reinstate removed comments via a …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3093
|
2024-11-21 10:18 |
2010-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304534
|
- |
|
drupal
|
drupal
|
The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configuration, which allows remote authenticated users to by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3092
|
2024-11-21 10:18 |
2010-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304535
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) 2.3.x before 2.3.6 and 2.4.x before 2.4.8 does not properly handle the matching of Perl regular expressions against HTML e-mail messages, which allows remote attacke…
|
CWE-20
Improper Input Validation
|
CVE-2010-3476
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304536
|
- |
|
ibm
|
db2
|
IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3475
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304537
|
- |
|
ibm
|
db2
|
IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners, which allows remote authenticated users to bypas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-3474
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304538
|
- |
|
ibm
|
filenet_p8_application_engine
|
Open redirect vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allows remote attackers to redirect users to arbitrary web sites and…
|
CWE-20
Improper Input Validation
|
CVE-2010-3473
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304539
|
- |
|
ibm
|
filenet_p8_application_engine
|
Multiple cross-site scripting (XSS) vulnerabilities in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-021 allow remote attackers to inject arbitrary w…
|
CWE-79
Cross-site Scripting
|
CVE-2010-3472
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304540
|
- |
|
ibm
|
filenet_p8_application_engine
|
Session fixation vulnerability in the Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.7-P8AE-FP007 allows remote attackers to hijack web sessions via uns…
|
CWE-287
Improper Authentication
|
CVE-2010-3471
|
2024-11-21 10:18 |
2010-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|