Total
5449 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2010-1067 | 1 Hasmir Alic | 1 E-membres | 2024-11-21 | N/A |
E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/bdEMembres.mdb. | ||||
CVE-2010-1066 | 1 The-ghost | 1 Ar Web Content Manager | 2024-11-21 | N/A |
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php. | ||||
CVE-2010-1065 | 1 Lebisoft | 1 Ziyaretci Defteri | 2024-11-21 | N/A |
Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/lebisoft.mdb. | ||||
CVE-2010-1064 | 1 Aspindir | 1 Erolife Ajxgaleri Vt | 2024-11-21 | N/A |
Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/ajxgaleri.mdb. | ||||
CVE-2010-0984 | 1 Acidcat | 1 Acidcat Cms | 2024-11-21 | N/A |
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for databases/acidcat_3.mdb. | ||||
CVE-2010-0978 | 1 Kmsoft | 1 Guestbook | 2024-11-21 | N/A |
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb. | ||||
CVE-2010-0977 | 1 Pordus | 1 Pd Portal | 2024-11-21 | N/A |
PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/db.mdb. | ||||
CVE-2010-0976 | 1 Acidcat | 1 Acidcat Cms | 2024-11-21 | N/A |
Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation process and have unspecified other impact via requests to install.asp and other install_*.asp scripts. NOTE: the final installation screen states "Important: you must now delete all files beginning with 'install' from the root directory." | ||||
CVE-2010-0965 | 1 Jevci.net | 1 Jevci Siparis Formu Scripti | 2024-11-21 | N/A |
Jevci Siparis Formu Scripti stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for siparis.mdb. | ||||
CVE-2010-0962 | 1 Apple | 3 Airport Express, Airport Extreme, Time Capsule | 2024-11-21 | N/A |
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command. | ||||
CVE-2010-0939 | 1 Visialis | 1 Abb Forum | 2024-11-21 | N/A |
Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb. | ||||
CVE-2010-0935 | 1 Perforce | 1 Perforce Server | 2024-11-21 | N/A |
Perforce Server 2009.2 and earlier, when the protection table is empty, allows remote authenticated users to obtain super privileges via a "p4 protect" command. | ||||
CVE-2010-0825 | 1 Gnu | 1 Emacs | 2024-11-21 | N/A |
lib-src/movemail.c in movemail in emacs 22 and 23 allows local users to read, modify, or delete arbitrary mailbox files via a symlink attack, related to improper file-permission checks. | ||||
CVE-2010-0812 | 1 Microsoft | 5 Windows 2003 Server, Windows Server 2003, Windows Server 2008 and 2 more | 2024-11-21 | N/A |
Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended IPv4 source-address restrictions via a mismatched IPv6 source address in a tunneled ISATAP packet, aka "ISATAP IPv6 Source Address Spoofing Vulnerability." | ||||
CVE-2010-0791 | 1 Ncpfs | 1 Ncpfs | 2024-11-21 | N/A |
The (1) ncpmount, (2) ncpumount, and (3) ncplogin programs in ncpfs 2.2.6 do not properly create lock files, which allows local users to cause a denial of service (application failure) via unspecified vectors that trigger the creation of a /etc/mtab~ file that persists after the program exits. | ||||
CVE-2010-0774 | 1 Ibm | 1 Websphere Application Server | 2024-11-21 | N/A |
The (1) JAX-RPC WS-Security 1.0 and (2) JAX-WS runtime implementations in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.41, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 do not properly handle WebServices PKCS#7 and PKIPath tokens, which allows remote attackers to bypass intended access restrictions via unspecified vectors. | ||||
CVE-2010-0765 | 1 Fipsasp | 1 Fipsforum | 2024-11-21 | N/A |
fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for _database/forumFips.mdb. | ||||
CVE-2010-0752 | 2 Drupal, Earl Dunovant | 2 Drupal, Week | 2024-11-21 | N/A |
The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restrictions when constructing SQL queries, which allows remote attackers to read restricted node listings via unspecified vectors. | ||||
CVE-2010-0734 | 2 Curl, Redhat | 2 Libcurl, Enterprise Linux | 2024-11-21 | N/A |
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit. | ||||
CVE-2010-0729 | 1 Redhat | 1 Enterprise Linux | 2024-11-21 | N/A |
A certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 4 on the ia64 platform allows local users to use ptrace on an arbitrary process, and consequently gain privileges, via vectors related to a missing ptrace_check_attach call. |