Latest CVE Feed
-
9.3
HIGHCVE-2007-2648
Stack-based buffer overflow in the Clever Database Comparer 2.2 ActiveX control (comparerax.ocx) allows remote attackers to execute arbitrary code via a long argument to the ConnectToDatabase function.... Read more
Affected Products : clever_database_comparer- EPSS Score: %6.31
- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2667
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execute arbitrary code via a long LogFile parameter.... Read more
Affected Products : vimp_x- EPSS Score: %5.29
- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2758
Multiple buffer overflows in WinImage 8.0.8000 allow user-assisted remote attackers to execute arbitrary code via a FAT image that contains long directory names in a deeply nested directory structure, which triggers (1) a stack-based buffer overflow durin... Read more
Affected Products : winimage- EPSS Score: %11.87
- Published: May. 18, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2771
Stack-based buffer overflow in the LEAD Technologies LeadTools JPEG 2000 LEADJ2K.LEADJ2K.140 ActiveX control (LTJ2K14.ocx) 14.5.0.35 allows remote attackers to execute arbitrary code via a long BitmapDataPath property.... Read more
Affected Products : leadtools_jpeg_2000- EPSS Score: %29.83
- Published: May. 21, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2847
Multiple cross-site scripting (XSS) vulnerabilities in hlstats.php in HLstats 1.35, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) authusername or (2) authpassword parameter, different vectors than CVE-2007... Read more
Affected Products : hlstats- EPSS Score: %0.66
- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2856
Buffer overflow in the Dart Communications PowerTCP ZIP Compression ActiveX control in DartZip.dll 1.8.5.3, when Internet Explorer 6 is used, allows user-assisted remote attackers to execute arbitrary code via a long first argument to the QuickZip functio... Read more
- EPSS Score: %15.58
- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2981
Buffer overflow in a certain ActiveX control in LEAD Technologies LEADTOOLS Raster OCR Document Object Library (ltrdc14e.dll) 14.5.0.44 allows remote attackers to execute arbitrary code via a long DictionaryFileName property.... Read more
Affected Products : leadtools_raster_ocr_document_object_library- EPSS Score: %7.63
- Published: Jun. 01, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2505
Stack-based buffer overflow in InterVations MailCOPA 8.01 20070323 allows user-assisted remote attackers to execute arbitrary code via a long command line argument, as demonstrated by a long string in the subject field in a mailto URI. NOTE: some of thes... Read more
Affected Products : mailcopa- EPSS Score: %16.08
- Published: May. 04, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3071
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSellerate SDK allows user-assisted remote attackers to execute arbitrary code via a long first argument.... Read more
Affected Products : esellerate_sdk- EPSS Score: %6.28
- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-0068
IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.... Read more
Affected Products : lotus_domino- EPSS Score: %1.77
- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3150
Google Desktop allows user-assisted remote attackers to execute arbitrary programs via a man-in-the-middle attack that injects JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .ex... Read more
Affected Products : desktop- EPSS Score: %0.89
- Published: Jun. 11, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3186
Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, as demonstrated using a gopher URI.... Read more
Affected Products : safari- EPSS Score: %8.93
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3360
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data containing NICK and EXEC strings, which exceeds the bounds of a hash table, and injects an EXEC hook function that receives and executes sh... Read more
Affected Products : bitchx- EPSS Score: %6.86
- Published: Jun. 22, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3376
Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds t... Read more
- EPSS Score: %4.66
- Published: Jun. 25, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3435
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) BarCodeAx.dll 4.9 allows remote attackers to execute arbitrary code via a long argument.... Read more
Affected Products : barcode_activex- EPSS Score: %76.14
- Published: Jun. 27, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3489
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as dem... Read more
Affected Products : vpn-1_utm_edge- EPSS Score: %1.71
- Published: Jun. 29, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3512
Stack-based buffer overflow in Lhaca File Archiver before 1.22 allows user-assisted remote attackers to execute arbitrary code via a large LHA "Extended Header Size" value in an LZH archive, a different issue than CVE-2007-3375.... Read more
Affected Products : lhaca_file_archiver- EPSS Score: %9.61
- Published: Jul. 03, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3572
Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`"... Read more
- EPSS Score: %7.00
- Published: Jul. 05, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3786
Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable softw... Read more
Affected Products : instagate_ex2_utm- EPSS Score: %1.90
- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3825
Multiple stack-based buffer overflows in the RPC implementation in alert.exe before 8.0.255.0 in CA (formerly Computer Associates) Alert Notification Server, as used in Threat Manager for the Enterprise, Protection Suites, certain BrightStor ARCserve prod... Read more
- EPSS Score: %27.26
- Published: Jul. 18, 2007
- Modified: Apr. 09, 2025