Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2010-07-22 CVE-2009-4952 Path Traversal vulnerability in Serge Gebhardt DIR Listing
Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.
network
low complexity
serge-gebhardt typo3 CWE-22
critical
10.0
2010-07-22 CVE-2010-2771 Code Injection vulnerability in IBM Soliddb
solid.exe in IBM solidDB before 6.5 FP2 allows remote attackers to execute arbitrary code via a long username field in the first handshake packet.
network
low complexity
ibm CWE-94
critical
10.0
2010-07-22 CVE-2010-1972 Configuration vulnerability in HP Client Automation Enterprise Infrastructure
The default configuration of HP Client Automation (HPCA) Enterprise Infrastructure (aka Radia) allows remote attackers to read log files, and consequently cause a denial of service or have unspecified other impact, via web requests.
network
low complexity
hp CWE-16
critical
9.0
2010-07-22 CVE-2009-4897 Buffer Errors vulnerability in Artifex products
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
network
artifex CWE-119
critical
9.3
2010-07-15 CVE-2010-1881 Code Injection vulnerability in Microsoft Access 2003
The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via an HTML document that references this control along with crafted persistent storage data, aka "ACCWIZ.dll Uninitialized Variable Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-07-15 CVE-2010-0814 Code Injection vulnerability in Microsoft Access 2003/2007
The Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-allocation approach used by Internet Explorer during instantiation, which allows remote attackers to execute arbitrary code via a web site that references multiple ActiveX controls, as demonstrated by the ImexGrid and FieldList controls, aka "Access ActiveX Control Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-07-15 CVE-2010-0266 Code Injection vulnerability in Microsoft Outlook 2002/2003/2007
Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted message, aka "Microsoft Outlook SMB Attachment Vulnerability."
network
microsoft CWE-94
critical
9.3
2010-07-13 CVE-2010-0907 Remote vulnerability in Oracle Secure Backup 10.3.0.1
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0899, CVE-2010-0904, and CVE-2010-0906.
network
low complexity
oracle
critical
10.0
2010-07-13 CVE-2010-0906 Remote vulnerability in Oracle Secure Backup 10.3.0.1
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
network
low complexity
oracle
critical
9.0
2010-07-13 CVE-2010-0899 Remote Secure Backup vulnerability in Oracle Secure Backup 10.3.0.1
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2010-0898, CVE-2010-0907, and CVE-2010-0906.
network
low complexity
oracle microsoft
critical
9.0