Show filters
133 Total Results
Displaying 91-100 of 133
Sort by:
Attacker Value
Unknown

CVE-2010-2008

Disclosure Date: July 13, 2010 (last updated October 04, 2023)
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain directories to the server data directory.
0
Attacker Value
Unknown

CVE-2010-0832

Disclosure Date: July 12, 2010 (last updated October 04, 2023)
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before 1.1.1-2ubuntu5 in PAM on Ubuntu 10.04 LTS allows local users to change the ownership of arbitrary files via a symlink attack on .cache in a user's home directory, related to "user file stamps" and the motd.legal-notice file.
0
Attacker Value
Unknown

CVE-2010-2647

Disclosure Date: July 06, 2010 (last updated October 04, 2023)
Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an invalid SVG document.
0
Attacker Value
Unknown

CVE-2010-2648

Disclosure Date: July 06, 2010 (last updated October 04, 2023)
The implementation of the Unicode Bidirectional Algorithm (aka Bidi algorithm or UBA) in Google Chrome before 5.0.375.99 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2010-1205

Disclosure Date: June 30, 2010 (last updated October 04, 2023)
Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.
Attacker Value
Unknown

CVE-2010-2249

Disclosure Date: June 30, 2010 (last updated October 04, 2023)
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
Attacker Value
Unknown

CVE-2010-2067

Disclosure Date: June 24, 2010 (last updated October 04, 2023)
Stack-based buffer overflow in the TIFFFetchSubjectDistance function in tif_dirread.c in LibTIFF before 3.9.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long EXIF SubjectDistance field in a TIFF file.
0
Attacker Value
Unknown

CVE-2010-1770

Disclosure Date: June 11, 2010 (last updated October 04, 2023)
WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted HTML document containing a BR element, related to a "type checking issue."
0
Attacker Value
Unknown

CVE-2010-0395

Disclosure Date: June 10, 2010 (last updated October 04, 2023)
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
0
Attacker Value
Unknown

CVE-2010-1321

Disclosure Date: May 19, 2010 (last updated October 04, 2023)
The kg_accept_krb5 function in krb5/accept_sec_context.c in the GSS-API library in MIT Kerberos 5 (aka krb5) through 1.7.1 and 1.8 before 1.8.2, as used in kadmind and other applications, does not properly check for invalid GSS-API tokens, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via an AP-REQ message in which the authenticator's checksum field is missing.
0