Latest CVE Feed
-
9.3
HIGHCVE-2008-4547
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows remote attackers to execute arbitrary code via a long second argument to the TimeSpanFormat method.... Read more
Affected Products : dvrstation_cms- EPSS Score: %12.37
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4719
PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the oe_classpath parameter, a different vector tha... Read more
Affected Products : openengine- EPSS Score: %1.01
- Published: Oct. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4922
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.... Read more
- EPSS Score: %67.09
- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5089
Multiple insecure method vulnerabilities in the DDActiveReportsViewer2.ARViewer2 ActiveX control (arview2.ocx) in Data Dynamics ActiveReports 2.5.0.1314 allow remote attackers to overwrite arbitrary files via a call to the (1) Pages.Save, (2) PrintReport,... Read more
Affected Products : activereports- EPSS Score: %0.86
- Published: Nov. 14, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5167
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the gConf[dir][layouts] parameter.... Read more
Affected Products : orca- EPSS Score: %1.52
- Published: Nov. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4391
Stack-based buffer overflow in the SetSource method in the NetCamPlayerWeb11gv2 ActiveX control in NetCamPlayerWeb11gv2.ocx on the Cisco Linksys WVC54GC wireless video camera before firmware 1.25 allows remote attackers to execute arbitrary code via long ... Read more
Affected Products : wvc54gc- EPSS Score: %5.23
- Published: Dec. 09, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5406
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one ov... Read more
- EPSS Score: %6.12
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5409
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (appli... Read more
- EPSS Score: %21.88
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5492
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these detail... Read more
Affected Products : verydoc_pdf_viewer- EPSS Score: %70.18
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5521
Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5523
avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- EPSS Score: %0.31
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5526
DrWeb Anti-virus 4.44.0.09170, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension... Read more
- EPSS Score: %0.31
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5531
Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension,... Read more
- EPSS Score: %0.31
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5537
PC Tools AntiVirus 4.4.2.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (... Read more
- EPSS Score: %0.31
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5542
Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to ha... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5543
Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- EPSS Score: %0.53
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5546
VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5544
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filena... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5735
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code via a large PlaylistSkin value in a skin file.... Read more
Affected Products : coolplayer- EPSS Score: %17.69
- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5754
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.... Read more
Affected Products : bulletproof_ftp_client- EPSS Score: %7.72
- Published: Dec. 30, 2008
- Modified: Apr. 09, 2025