Latest CVE Feed
-
9.3
HIGHCVE-2013-3482
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS f... Read more
Affected Products : erdas_er_viewer- EPSS Score: %65.74
- Published: Jan. 19, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-4979
Buffer overflow in the gldll32.dll module in EPS Viewer 3.2 and earlier allows remote attackers to execute arbitrary code via a crafted EPS file.... Read more
Affected Products : eps_viewer- EPSS Score: %11.71
- Published: Jan. 31, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-6949
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.... Read more
Affected Products : wemo_home_automation_firmware- EPSS Score: %0.62
- Published: Feb. 22, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2014-2087
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code v... Read more
Affected Products : free_download_manager- EPSS Score: %46.39
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-0733
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .jp... Read more
- EPSS Score: %7.88
- Published: Jun. 05, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-3911
Samsung iPOLiS Device Manager before 1.8.7 allow remote attackers to execute arbitrary code via unspecified values to the (1) Start, (2) ChangeControlLocalName, (3) DeleteDeviceProfile, (4) FrameAdvanceReader, or other unknown method in the XNSSDKDEVICE.X... Read more
Affected Products : ipolis_device_manager- EPSS Score: %11.41
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-7178
Enalean Tuleap before 7.5.99.6 allows remote attackers to execute arbitrary commands via the User-Agent header, which is provided to the passthru PHP function.... Read more
Affected Products : tuleap- EPSS Score: %10.01
- Published: Nov. 28, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-6119
IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.1 iFix 003, and 9.0.1 before 9.0.1 iFix 001 allows remote attackers to execute arbitrary code via a crafte... Read more
- EPSS Score: %9.94
- Published: Dec. 23, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-5295
Buffer overflow in the Download method in a certain ActiveX control in MDIEEx.dll in Gogago YouTube Video Converter 1.1.6 allows remote attackers to execute arbitrary code via a long argument.... Read more
Affected Products : gogago_youtube_video_converter- EPSS Score: %13.24
- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3837
The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data during serialization and deserialization, which allows attackers to execute arbitrary code via an applica... Read more
Affected Products : android- EPSS Score: %0.79
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3858
The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an authorization check, which allows attackers to bypass an intended user-confirmation requirement for SMS shor... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3863
Multiple integer overflows in the Blob class in keystore/keystore.cpp in Keystore in Android before 5.1.1 LMY48M allow attackers to execute arbitrary code and read arbitrary Keystore keys via an application that uses a crafted blob in an insert operation,... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3876
libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.... Read more
Affected Products : android- EPSS Score: %4.56
- Published: Oct. 02, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6606
The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 2230178... Read more
Affected Products : android- EPSS Score: %0.89
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7361
FortiOS 5.2.3, when configured to use High Availability (HA) and the dedicated management interface is enabled, does not require authentication for access to the ZebOS shell on the HA dedicated management interface, which allows remote attackers to obtain... Read more
Affected Products : fortios- EPSS Score: %0.74
- Published: Oct. 15, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6612
libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 23540426.... Read more
Affected Products : android- EPSS Score: %7.72
- Published: Nov. 03, 2015
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2018-3971
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially crafted IRP request can cause the driver to write data under controlled by an attacker address, resulting in m... Read more
Affected Products : hitmanpro.alert- EPSS Score: %0.06
- Published: Oct. 25, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9575
In impd_parse_dwnmix_instructions of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exp... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1640
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
- EPSS Score: %0.30
- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1991
In btif_dm_data_copy of btif_core.cc, there is a possible out of bounds write due to a buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android.... Read more
Affected Products : android- EPSS Score: %1.00
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024