LiveActive security incident?Get immediate response
CVE archive

October 2010

Browse CVE records published in October 2010, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 578 matching CVEs · Page 5 of 12.

Unknown · CVSS Not scored

CVE-2010-4120: Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-b...

Multiple cross-site scripting (XSS) vulnerabilities in the TAM console in IBM Tivoli Access Manager for e-business 6.1.0 before 6.1.0-TIV-TAM-FP0006 allow remote attackers to inject arbitrary web script or HTML via (1) the parm1 parameter to ivt/ivtserver, or the method parameter to (2) acl, (3) domain, (4) group, (5) gso, (6) gsogroup, (7) os, (8) pop, (9) rule, (10) user, or (11) webseal in ibm/wpm/.

Published Oct 28, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-4045: Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and...

Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers to spoof the Address Bar, conduct cross-site scripting (XSS) attacks, and possibly execute arbitrary code by leveraging the ability of a script to interact with a web page from (1) a different domain or (2) a different security context.

Published Oct 21, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-4056: solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain functi...

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing a single integer field, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a TCP session on port 1315.

Published Oct 22, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-4086: dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause...

dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Director (.dir) media file with an invalid element size, a different vulnerability than CVE-2010-2581, CVE-2010-2880, CVE-2010-4084, CVE-2010-4085, and CVE-2010-4088.

Published Oct 29, 2010 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2010-4057: solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain functi...

solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon receiving packet data containing many integer fields with two different values, which allows remote attackers to cause a denial of service (invalid memory access and daemon crash) via a TCP session on port 1315.

Published Oct 22, 2010 · Updated Aug 7, 2024