Latest CVE Feed
-
10.0
HIGHCVE-2006-6605
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41, and 2.35 and earlier before ME-10026 allows remote attackers to execute arbitrary code via a long argumen... Read more
- Published: Dec. 19, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5815
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably authenticated, to cause a denial of service and execute arbitrary code, as demonstrated by vd_proftpd.pm, a "ProFTPD remote exploit."... Read more
Affected Products : proftpd- Published: Nov. 08, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2000-0762
The default installation of eTrust Access Control (formerly SeOS) uses a default encryption key, which allows remote attackers to spoof the eTrust administrator and gain privileges.... Read more
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0431
Vulnerability in iPlanet Web Server Enterprise Edition 4.x.... Read more
Affected Products : iplanet_web_server- Published: Jul. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1868
Dispair 0.1 and 0.2 allows remote attackers to execute arbitrary shell commands via certain form fields.... Read more
Affected Products : dispair- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1520
The CLI interface for WatchGuard Firebox Vclass 3.2 and earlier, and RSSA Appliance 3.0.2, does not properly close the SSH connection when a -N option is provided during authentication, which allows remote attackers to access CLI with administrator privil... Read more
- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0304
one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to create administrator accounts by directly calling the install.php Helpdesk Installation script.... Read more
Affected Products : oneorzero_helpdesk- Published: Jun. 09, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0450
Format string vulnerability in the printlog function in log2mail before 0.2.5.2 allows local users or remote attackers to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.... Read more
Affected Products : log2mail- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0332
Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.... Read more
Affected Products : extremail- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-5370
Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS06 for Oracle CRM Gateway for Mobile Devices and (2) APPS08 for Oracle iStore.... Read more
Affected Products : e-business_suite- Published: Oct. 18, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-3893
Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML ... Read more
- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-2137
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a lo... Read more
Affected Products : tivoli_monitoring_express- Published: Apr. 22, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-3500
Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.... Read more
Affected Products : xeforum- Published: Jun. 29, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-3624
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.... Read more
Affected Products : sap_message_server- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-4121
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password... Read more
- Published: Aug. 01, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6638
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.... Read more
Affected Products : 3204_dvr- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4429
Unspecified vulnerability in SOURCENEXT Virus Security ZERO 9.5.0173 and earlier and Virus Security 9.5.0173 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via malformed compressed files. NOTE: ... Read more
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4801
Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 th... Read more
Affected Products : tivoli_storage_manager tivoli_storage_manager_client tivoli_storage_manager_express- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5284
The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allo... Read more
- Published: Nov. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1012
Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidenti... Read more
Affected Products : bea_product_suite- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025