Latest CVE Feed
-
9.8
CRITICALCVE-2021-29936
An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via the FromIterator implementation for Vector and Matrix.... Read more
Affected Products : adtensor- Published: Apr. 01, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29998
An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.... Read more
Affected Products : scalance_x408_firmware scalance_x300_firmware vxworks scalance_x201-3p_irt_firmware scalance_x201-3p_irt_pro_firmware scalance_x202-2p_irt_firmware scalance_x202-2p_irt_pro_firmware scalance_xf201-3p_irt_firmware scalance_xf202-2p_irt_firmware scalance_xf204-2ba_irt_firmware +61 more products- Published: Apr. 13, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-6814
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an... Read more
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-6293
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause... Read more
Affected Products : international_components_for_unicode- Published: Jul. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5769
Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecif... Read more
Affected Products : php- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5734
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted s... Read more
Affected Products : phpmyadmin- Published: Jul. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5254
Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) ... Read more
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5003
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.... Read more
Affected Products : ws-xmlrpc- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4564
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and appli... Read more
Affected Products : imagemagick- Published: Jun. 04, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-29417
gitjacker before 0.1.0 allows remote attackers to execute arbitrary code via a crafted .git directory because of directory traversal.... Read more
Affected Products : gitjacker- Published: Mar. 29, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29377
Pear Admin Think through 2.1.2 has an arbitrary file upload vulnerability that allows attackers to execute arbitrary code remotely. A .php file can be uploaded via admin.php/index/upload because app/common/service/UploadService.php mishandles fileExt.... Read more
Affected Products : pearadmin_think- Published: Aug. 12, 2021
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29396
Systemic Insecure Permissions in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to use various functionalities without authentication.... Read more
Affected Products : northstar_club_management- Published: Feb. 04, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-3132
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.... Read more
Affected Products : php- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2177
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging un... Read more
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2008
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : data_protector- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1908
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding priv... Read more
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1901
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.... Read more
- Published: Jan. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2021-29215
A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the TEZ MapR ecosystem component was discovered in version(s): Prior to Tez-0.8: mapr-tez-0.8.201907081100-1.noarch; prior to Tez-0.9: mapr-... Read more
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-29281
File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik Web UI plugin which is affected by CVE-2014-2217, and CVE-2017-11317.... Read more
Affected Products : archiver- Published: Jul. 07, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-28958
Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.... Read more
Affected Products : manageengine_adselfservice_plus- Published: Jun. 25, 2021
- Modified: Nov. 21, 2024