Vulnerabilities (CVE)

Total 93723 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-0704 1 Fedoraproject 1 389 Directory Server 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request.
CVE-2011-0544 2 Debian, Phpbb 2 Debian Linux, Phpbb 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
phpbb 3.0.x-3.0.6 has an XSS vulnerability via the [flash] BB tag.
CVE-2011-0428 1 Ikiwiki 1 Ikiwiki 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) in ikiwiki before 3.20110122 could allow remote attackers to insert arbitrary JavaScript due to insufficient checking in comments.
CVE-2011-0220 1 Apple 1 Bonjour 2024-11-21 4.9 MEDIUM 5.5 MEDIUM
Apple Bonjour before 2011 allows a crash via a crafted multicast DNS packet.
CVE-2010-5340 1 Icewarp 1 Webclient 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
CVE-2010-5339 1 Icewarp 1 Webclient 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.
CVE-2010-5338 1 Icewarp 1 Webclient 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.
CVE-2010-5337 1 Icewarp 1 Webclient 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.
CVE-2010-5336 1 Icewarp 1 Webclient 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.
CVE-2010-5332 1 Linux 1 Linux Kernel 2024-11-21 4.6 MEDIUM 5.6 MEDIUM
In the Linux kernel before 2.6.37, an out of bounds array access happened in drivers/net/mlx4/port.c. When searching for a free entry in either mlx4_register_vlan() or mlx4_register_mac(), and there is no free entry, the loop terminates without updating the local variable free thus causing out of array bounds access.
CVE-2010-4817 2 Debian, Pithos Project 2 Debian Linux, Pithos 2024-11-21 3.6 LOW 5.5 MEDIUM
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2010-4662 1 Pmwiki 1 Pmwiki 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
PmWiki before 2.2.21 has XSS.
CVE-2010-4659 1 Status 1 Statusnet 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in statusnet through 2010 in error message contents.
CVE-2010-4658 1 Status 1 Statusnet 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
statusnet through 2010 allows attackers to spoof syslog messages via newline injection attacks.
CVE-2010-4653 2 Debian, Freedesktop 2 Debian Linux, Poppler 2024-11-21 4.3 MEDIUM 6.5 MEDIUM
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
CVE-2010-4532 2 Debian, Offlineimap 2 Debian Linux, Offlineimap 2024-11-21 4.3 MEDIUM 5.9 MEDIUM
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
CVE-2010-4266 1 Vanillaforums 1 Vanilla Forums 2024-11-21 5.8 MEDIUM 6.1 MEDIUM
It was found in vanilla forums before 2.0.10 a potential linkbait vulnerability in dispatcher.
CVE-2010-4264 1 Vanillaforums 1 Vanilla Forums 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
It was found in vanilla forums before 2.0.10 a cross-site scripting vulnerability where a filename could contain arbitrary code to execute on the client side.
CVE-2010-4245 1 Translatehouse 1 Pootle 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
pootle 2.0.5 has XSS via 'match_names' parameter
CVE-2010-4240 1 Tiki 1 Tikiwiki Cms\/groupware 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Tiki Wiki CMS Groupware 5.2 has XSS