Latest CVE Feed
-
9.3
HIGHCVE-2008-0312
Stack-based buffer overflow in the AutoFix Support Tool ActiveX control 2.7.0.1 in SYMADATA.DLL in multiple Symantec Norton products, including Norton 360 1.0, AntiVirus 2006 through 2008, Internet Security 2006 through 2008, and System Works 2006 through... Read more
Affected Products : windows norton_system_works norton_360 norton_antivirus norton_internet_security- EPSS Score: %23.04
- Published: Apr. 08, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1860
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.... Read more
Affected Products : lokicms- EPSS Score: %4.65
- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1912
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.... Read more
Affected Products : divx_player- EPSS Score: %29.97
- Published: Apr. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-6255
Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.... Read more
- EPSS Score: %59.81
- Published: Apr. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1973
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.... Read more
Affected Products : subedit_player- EPSS Score: %9.20
- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2008
Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.... Read more
Affected Products : trillian- EPSS Score: %2.58
- Published: Apr. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2015
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in on... Read more
Affected Products : appscan- EPSS Score: %4.07
- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2069
Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.... Read more
Affected Products : groupwise- EPSS Score: %14.96
- Published: May. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2111
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.... Read more
Affected Products : yahoo_assistant- EPSS Score: %13.54
- Published: May. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2228
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.... Read more
Affected Products : cyberfolio- EPSS Score: %1.80
- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2283
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the ... Read more
- EPSS Score: %5.68
- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-0958
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioGrabber2 ActiveX control in NCTAudioGrabber2.dll allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : nctaudioeditor_activex_control- EPSS Score: %36.27
- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2547
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross... Read more
Affected Products : windows_installer- EPSS Score: %29.78
- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2551
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution of arbitrary files via a URL in the propDownloadUrl parameter with the propPostDownloadAction parameter set... Read more
Affected Products : instant_messenger- EPSS Score: %85.10
- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2635
Multiple directory traversal vulnerabilities in BitKinex 2.9.3 allow remote FTP and WebDAV servers to create or overwrite arbitrary files via a .. (dot dot) in (1) a response to a LIST command from the BitKinex FTP client and (2) a response to a PROPFIND ... Read more
Affected Products : bitkinex- EPSS Score: %0.15
- Published: Jun. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2702
Directory traversal vulnerability in the FTP client in ALTools ESTsoft ALFTP 4.1 beta 2 and 5.0 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. NOTE: t... Read more
Affected Products : alftp- EPSS Score: %6.34
- Published: Jun. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2894
Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.... Read more
Affected Products : nch_software_classic_ftp- EPSS Score: %2.48
- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2886
PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.... Read more
Affected Products : jamroom- EPSS Score: %5.13
- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2910
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting ... Read more
Affected Products : autoproducer- EPSS Score: %7.54
- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2959
Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.... Read more
Affected Products : visual_basic_enterprise_edition- EPSS Score: %34.70
- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025