Total
10666 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-0601 | 1 Cisco | 1 Pgw 2200 Softswitch | 2010-05-21 | 7.8 HIGH | N/A |
The MGCP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S11 allows remote attackers to cause a denial of service (device crash) via a malformed packet, aka Bug ID CSCsl39126. | |||||
CVE-2010-1189 | 1 Mediawiki | 1 Mediawiki | 2010-05-20 | 5.0 MEDIUM | N/A |
MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue." | |||||
CVE-2010-0603 | 1 Cisco | 1 Pgw 2200 Softswitch | 2010-05-20 | 7.8 HIGH | N/A |
The SIP implementation on the Cisco PGW 2200 Softswitch with software before 9.7(3)S10 allows remote attackers to cause a denial of service (device crash) via a malformed session attribute, aka Bug ID CSCsk40030. | |||||
CVE-2010-0101 | 1 Lexmark | 61 25xxn, C510, C52x and 58 more | 2010-05-07 | 7.8 HIGH | N/A |
The embedded HTTP server in multiple Lexmark laser and inkjet printers and MarkNet devices, including X94x, W840, T656, N4000, E462, C935dn, 25xxN, and other models, allows remote attackers to cause a denial of service (operating system halt) via a malformed HTTP Authorization header. | |||||
CVE-2010-1592 | 1 Sisoftware | 1 Sandra | 2010-04-29 | 6.9 MEDIUM | N/A |
sandra.sys 15.18.1.1 and earlier in the Sandra Device Driver in SiSoftware Sandra 16.10.2010.1 and earlier allows local users to gain privileges or cause a denial of service (system crash) via unspecified vectors involving "Model-Specific Registers." | |||||
CVE-2010-0686 | 1 Vmware | 3 Esx Server, Server, Virtualcenter | 2010-04-28 | 7.5 HIGH | N/A |
WebAccess in VMware VirtualCenter 2.0.2 and 2.5, VMware Server 2.0, and VMware ESX 3.0.3 and 3.5 allows remote attackers to leverage proxy-server functionality to spoof the origin of requests via unspecified vectors, related to a "URL forwarding vulnerability." | |||||
CVE-2010-1544 | 2 Acme, Rca | 2 Micro Httpd, Digital Cable Modem | 2010-04-27 | 5.0 MEDIUM | N/A |
micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | |||||
CVE-2009-4810 | 1 Samhain Labs | 1 Samhain | 2010-04-26 | 7.5 HIGH | N/A |
The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input. | |||||
CVE-2010-1226 | 1 Apple | 2 Iphone, Iphone Os | 2010-04-02 | 5.0 MEDIUM | N/A |
The HTTP client functionality in Apple iPhone OS 3.1 on the iPhone 2G and 3.1.3 on the iPhone 3GS allows remote attackers to cause a denial of service (Safari, Mail, or Springboard crash) via a crafted innerHTML property of a DIV element, related to a "malformed character" issue. | |||||
CVE-2010-0500 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-03-31 | 7.8 HIGH | N/A |
Event Monitor in Apple Mac OS X before 10.6.3 does not properly validate hostnames of SSH clients, which allows remote attackers to cause a denial of service (arbitrary client blacklisting) via a crafted DNS PTR record, related to a "plist injection issue." | |||||
CVE-2010-0931 | 1 Perforce | 1 Perforce Server | 2010-03-08 | 5.0 MEDIUM | N/A |
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data, possibly involving a large sndbuf value. | |||||
CVE-2010-0929 | 1 Perforce | 1 Perforce Server | 2010-03-08 | 5.0 MEDIUM | N/A |
The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff. | |||||
CVE-2010-0932 | 1 Perforce | 1 Perforce Server | 2010-03-08 | 5.0 MEDIUM | N/A |
The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command. | |||||
CVE-2009-3305 | 1 Pps.jussieu | 1 Polipo | 2010-02-26 | 5.0 MEDIUM | N/A |
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors. | |||||
CVE-2008-5248 | 1 Xine | 1 Xine-lib | 2009-11-24 | 4.3 MEDIUM | N/A |
xine-lib before 1.1.15 allows remote attackers to cause a denial of service (crash) via "MP3 files with metadata consisting only of separators." | |||||
CVE-2009-2835 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2009-11-17 | 4.6 MEDIUM | N/A |
The kernel in Apple Mac OS X before 10.6.2 does not properly handle task state segments, which allows local users to gain privileges, cause a denial of service (system crash), or obtain sensitive information via unspecified vectors. | |||||
CVE-2009-3287 | 1 Macournoyer | 1 Thin | 2009-09-22 | 7.5 HIGH | N/A |
lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header. | |||||
CVE-2009-1371 | 1 Clamav | 1 Clamav | 2009-09-16 | 5.0 MEDIUM | N/A |
The CLI_ISCONTAINED macro in libclamav/others.h in ClamAV before 0.95.1 allows remote attackers to cause a denial of service (application crash) via a malformed file with UPack encoding. | |||||
CVE-2009-1272 | 1 Php | 1 Php | 2009-09-16 | 5.0 MEDIUM | N/A |
The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction. | |||||
CVE-2007-6263 | 1 Netkit-ftp | 1 Netkit Ftp | 2009-09-15 | 9.3 HIGH | N/A |
The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP over SSL protocol behavior, as demonstrated by breaking a passive FTP DATA connection in a way that triggers an error in the server's SSL_accept function. NOTE: the netkit ftp issue is covered by CVE-2007-5769. |