NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11976  CVE-2010-0420  libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.    4.3  Medium  2017-01-18  2013-11-02  View
12232  CVE-2010-0685  The design of the dialplan functionality in Asterisk Open Source 1.2.x, 1.4.x, and 1.6.x; and Asterisk Business Edition B.x.x and C.x.x, when using the ${EXTEN} channel variable and wildcard pattern matches, allows context-dependent attackers to inject strings into the dialplan using metacharacters that are injected when the variable is expanded, as demonstrated using the Dial application to process a crafted SIP INVITE message that adds an unintended outgoing channel leg. NOTE: it could be argued that this is not a vulnerability in Asterisk, but a class of vulnerabilities that can occur in any program that uses this feature without the associated filtering functionality that is already available.    Medium  2017-01-18  2010-04-08  View
77768  CVE-2001-0290  Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.    4.6  Medium  2017-01-05  2008-09-05  View
12488  CVE-2010-0952  SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an elite action.    6.8  Medium  2017-01-18  2010-03-10  View
13000  CVE-2010-1473  Directory traversal vulnerability in the Advertising (com_advertising) component 0.25 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.    6.8  Medium  2017-01-18  2010-06-11  View

Page 15689 of 17672, showing 5 records out of 88360 total, starting on record 78441, ending on 78445

Actions