CVE-2010-5108
- EPSS 0.31%
- Veröffentlicht 13.11.2019 23:15:10
- Zuletzt bearbeitet 21.11.2024 01:22:31
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of tickets without having proper permissions.
CVE-2010-4664
- EPSS 0.2%
- Veröffentlicht 13.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:28
In ConsoleKit before 0.4.2, an intended security policy restriction bypass was found. This flaw allows an authenticated system user to escalate their privileges by initiating a remote VNC session.
CVE-2010-4817
- EPSS 0.25%
- Veröffentlicht 13.11.2019 22:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:50
pithos before 0.3.5 allows overwrite of arbitrary files via symlinks.
CVE-2010-4657
- EPSS 1.57%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
PHP5 before 5.4.4 allows passing invalid utf-8 strings via the xmlTextWriterWriteAttribute, which are then misparsed by libxml2. This results in memory leak into the resulting output.
CVE-2010-4661
- EPSS 0.15%
- Veröffentlicht 13.11.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 01:21:27
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
CVE-2010-4653
- EPSS 0.78%
- Veröffentlicht 13.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:27
An integer overflow condition in poppler before 0.16.3 can occur when parsing CharCodes for fonts.
CVE-2010-4654
- EPSS 0.47%
- Veröffentlicht 13.11.2019 20:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:27
poppler before 0.16.3 has malformed commands that may cause corruption of the internal stack.
CVE-2010-4533
- EPSS 0.28%
- Veröffentlicht 13.11.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:09
offlineimap before 6.3.4 added support for SSL server certificate validation but it is still possible to use SSL v2 protocol, which is a flawed protocol with multiple security deficiencies.
CVE-2010-4532
- EPSS 0.23%
- Veröffentlicht 13.11.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 01:21:09
offlineimap before 6.3.2 does not check for SSL server certificate validation when "ssl = yes" option is specified which can allow man-in-the-middle attacks.
CVE-2012-4385
- EPSS 0.23%
- Veröffentlicht 13.11.2019 17:15:13
- Zuletzt bearbeitet 21.11.2024 01:42:46
letodms 3.3.6 has CSRF via change password