Latest CVE Feed
-
9.3
HIGHCVE-2008-5406
Stack-based buffer overflow in Apple QuickTime Player 7.5.5 and iTunes 8.0.2.20 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a MOV file with "long arguments," related to an "off by one ov... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5409
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Server 6.0.08.1118 allows remote attackers to cause a denial of service (appli... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5492
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these detail... Read more
Affected Products : verydoc_pdf_viewer- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5521
Avira AntiVir 7.9.0.36 and possibly 7.8.1.28, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (... Read more
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5523
avast! antivirus 4.8.1281.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5542
Sunbelt VIPRE 3.1.1832.2 and possibly 3.1.1633.1, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to ha... Read more
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5543
Symantec AntiVirus (SAV) 10, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5546
VirusBlokAda VBA32 3.12.8.5, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, ... Read more
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5754
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bps file (aka Session-File) with a long second line, possibly a related issue to CVE-2008-5753.... Read more
Affected Products : bulletproof_ftp_client- Published: Dec. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0174
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in the HREF attribute of a REF element in a .asx file.... Read more
Affected Products : vuplayer- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0246
Stack-based buffer overflow in easyHDR PRO 1.60.2 allows user-assisted attackers to execute arbitrary code via an invalid Radiance RGBE (aka .hdr) file.... Read more
Affected Products : easyhdr- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0262
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : media_player- Published: Jan. 23, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0259
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploi... Read more
Affected Products : openoffice.org- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0389
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attackers to (1) create and overwrite arbitrary files via the WriteIniFileString method, (2) execute arbitrary programs via the ShellExecute... Read more
Affected Products : web_on_windows_activex- Published: Feb. 02, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0731
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the template parameter.... Read more
Affected Products : free_arcade_script- Published: Feb. 24, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1028
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file.... Read more
Affected Products : ezip_wizard- Published: Mar. 20, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1054
Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.... Read more
- Published: Mar. 24, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1092
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments.... Read more
Affected Products : liveaudio_activex_control- Published: Mar. 25, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-6563
Buffer overflow in the XML parser in Trillian 3.1.9.0, and possibly earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DTD file.... Read more
Affected Products : trillian- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-13249
In impeg2d_api_set_display_frame of impeg2d_api_main.c, there is an out of bound write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Pro... Read more
Affected Products : android- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024