Show filters
122 Total Results
Displaying 111-120 of 122
Sort by:
Attacker Value
Unknown
CVE-2010-3113
Disclosure Date: August 24, 2010 (last updated October 04, 2023)
Google Chrome before 5.0.375.127, and webkitgtk before 1.2.5, does not properly handle SVG documents, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors related to state changes when using DeleteButtonController.
0
Attacker Value
Unknown
CVE-2010-3114
Disclosure Date: August 24, 2010 (last updated October 04, 2023)
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLineBreakCommand.cpp, or (3) InsertParagraphSeparatorCommand.cpp in WebCore/editing/.
0
Attacker Value
Unknown
CVE-2010-2008
Disclosure Date: July 13, 2010 (last updated October 04, 2023)
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
0
Attacker Value
Unknown
CVE-2010-2647
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.
0
Attacker Value
Unknown
CVE-2010-2648
Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown
CVE-2010-1770
Disclosure Date: June 11, 2010 (last updated October 04, 2023)
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."
0
Attacker Value
Unknown
CVE-2010-1624
Disclosure Date: May 14, 2010 (last updated October 04, 2023)
The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote authenticated users to cause a denial of service (NULL pointer dereference and application crash) via a custom emoticon in a malformed SLP message.
0
Attacker Value
Unknown
CVE-2010-0050
Disclosure Date: March 15, 2010 (last updated February 03, 2024)
Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.
0
Attacker Value
Unknown
CVE-2010-0650
Disclosure Date: February 18, 2010 (last updated October 04, 2023)
WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.
0
Attacker Value
Unknown
CVE-2009-4484
Disclosure Date: December 30, 2009 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.
0