LiveActive security incident?Get immediate response
CVE archive

June 2010

Browse CVE records published in June 2010, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 471 matching CVEs · Page 4 of 10.

Unknown · CVSS Not scored

CVE-2010-2343: Stack-based buffer overflow in D.R.

Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.

Published Jun 21, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2322: Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remot...

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

Published Jun 18, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2332: Impact Financials, Inc.

Impact Financials, Inc. Impact PDF Reader 2.0, 1.2, and other versions for iPhone and iPod touch allows remote attackers to cause a denial of service (server crash) via a "..." body in a POST request.

Published Jun 18, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2313: Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10,...

Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter to index.php. NOTE: some of these details are obtained from third party information.

Published Jun 17, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2302: Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attacker...

Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow DOM trees, aka rdar problem 8007953. NOTE: this might overlap CVE-2010-1771.

Published Jun 15, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2307: Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E...

Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request.

Published Jun 16, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2300: Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in...

Use-after-free vulnerability in the Element::normalizeAttributes function in dom/Element.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to handlers for DOM mutation events, aka rdar problem 7948784. NOTE: this might overlap CVE-2010-1759.

Published Jun 15, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2264: The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 throu...

The Cascading Style Sheets (CSS) implementation in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, does not properly handle the :visited pseudo-class, which allows remote attackers to obtain sensitive information about visited web pages via a crafted HTML document.

Published Jun 11, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2295: page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a ch...

page/EventHandler.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 does not properly handle a change of the focused frame during the dispatching of keydown, which allows user-assisted remote attackers to redirect keystrokes via a crafted HTML document, aka rdar problem 7018610. NOTE: this might overlap CVE-2010-1422.

Published Jun 15, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-2299: The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 doe...

The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitrary code via vectors involving crafted data from the renderer process, related to a "Type Confusion" issue.

Published Jun 15, 2010 · Updated Aug 7, 2024