NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
14811  CVE-2010-3426  Directory traversal vulnerability in jphone.php in the JPhone (com_jphone) component 1.0 Alpha 3 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the controller parameter to index.php.    7.5  High  2017-01-18  2010-09-17  View
14812  CVE-2010-3427  Multiple cross-site scripting (XSS) vulnerabilities in Open Classifieds 1.7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) desc, (2) price, (3) title, and (4) place parameters to index.php and the (5) subject parameter to contact.htm, related to content/contact.php.    4.3  Medium  2017-01-18  2010-09-17  View
14813  CVE-2010-3428  SQL injection vulnerability in modules/notes/json.php in Intermesh Group-Office 3.5.9 allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a category action.    7.5  High  2017-01-18  2010-09-17  View
14814  CVE-2010-3429  flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."    6.8  Medium  2017-01-18  2011-10-25  View
14815  CVE-2010-3430  The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack on the .pam_environment file in a user"s home directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-3435.    4.7  Medium  2017-01-18  2012-07-23  View

Page 2963 of 17672, showing 5 records out of 88360 total, starting on record 14811, ending on 14815

Actions