Latest CVE Feed
-
10.0
HIGHCVE-2011-2963
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, which allows remote attackers to obtain sensitive information, delete files, execute arbitrary programs, or cause a denial of service (cra... Read more
Affected Products : movicon- EPSS Score: %9.93
- Published: Jul. 29, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-5404
Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged f... Read more
Affected Products : flexcell_grid_control- EPSS Score: %3.42
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-3136
Unspecified vulnerability in the Management Console in IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.0 before 6.2.0.9 has unknown impact and attack vectors, aka APAR I... Read more
Affected Products : tivoli_federated_identity_manager tivoli_federated_identity_manager_business_gateway- EPSS Score: %0.47
- Published: Aug. 12, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-0012
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-200... Read more
- EPSS Score: %14.80
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-3420
Multiple unspecified vulnerabilities in Google Chrome before 14.0.835.157 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more
- EPSS Score: %0.57
- Published: Sep. 12, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-3494
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a long StyleTemplate element in a QUO, SUM or POR file, which triggers a stack-based buffer overflow, or (... Read more
Affected Products : esignal- EPSS Score: %72.44
- Published: Sep. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-3498
Heap-based buffer overflow in Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long request.... Read more
- EPSS Score: %64.48
- Published: Sep. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-4214
OneOrZero Action & Information Management System (AIMS) 2.7.0 allows remote attackers to bypass authentication and obtain administrator privileges via a crafted oozimsrememberme cookie.... Read more
Affected Products : aims- EPSS Score: %1.53
- Published: Nov. 01, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-6703
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decomp... Read more
Affected Products : s.t.a.l.k.e.r.\- EPSS Score: %17.20
- Published: Apr. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-4548
Multiple unspecified vulnerabilities in Google Chrome before 16.0.912.44 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more
- EPSS Score: %0.35
- Published: Nov. 24, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-1242
The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated us... Read more
Affected Products : f5d7230-4- EPSS Score: %4.23
- Published: Mar. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-4752
SmarterTools SmarterStats 6.2.4100 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving frmCustomReport.aspx and certain other files... Read more
Affected Products : smarterstats- EPSS Score: %1.75
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-4762
Parallels Plesk Small Business Panel 10.2.0 sends incorrect Content-Type headers for certain resources, which might allow remote attackers to have an unspecified impact by leveraging an interpretation conflict involving smb/app/top-categories-data/ and ce... Read more
Affected Products : parallels_plesk_small_business_panel- EPSS Score: %1.75
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-5323
GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or ... Read more
Affected Products : centricity_pacs-iw- EPSS Score: %0.57
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2012-0245
Multiple stack-based buffer overflows in RobNetScanHost.exe in ABB Robot Communications Runtime before 5.14.02, as used in ABB Interlink Module, IRC5 OPC Server, PC SDK, PickMaster 3 and 5, RobView 5, RobotStudio, WebWare SDK, and WebWare Server, allow re... Read more
- EPSS Score: %27.46
- Published: Mar. 09, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-7282
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware 5.07.36_NIS01 allows remote attackers to bypass authentication via a "Cookie: :language=en" HTTP header.... Read more
- EPSS Score: %5.00
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2014-6434
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.... Read more
- EPSS Score: %3.36
- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2003-1507
Planet Technology WGSD-1020 and WSW-2401 Ethernet switches use a default "superuser" account with the "planet" password, which allows remote attackers to gain administrative access.... Read more
- EPSS Score: %0.84
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2014-6626
Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows remote attackers to bypass authentication and execute administrative actions via unknown vectors.... Read more
Affected Products : clearpass- EPSS Score: %3.95
- Published: Nov. 19, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2003-1525
Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.... Read more
Affected Products : my_photo_gallery- EPSS Score: %0.33
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025