Latest CVE Feed
-
9.3
HIGHCVE-2011-0912
Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL f... Read more
- Published: Feb. 08, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-1719
Multiple stack-based buffer overflows in the Web Viewer ActiveX controls in CA Output Management Web Viewer 11.0 and 11.5 allow remote attackers to execute arbitrary code via (1) a long SRC property value to the PPSViewer ActiveX control in PPSView.ocx be... Read more
- Published: Apr. 27, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2075
Unspecified vulnerability in Google Chrome 11.0.696.65 on Windows 7 SP1 allows remote attackers to execute arbitrary code via unknown vectors. NOTE: as of 20110510, the only disclosure is a vague advisory that possibly relates to multiple vulnerabilities... Read more
- Published: May. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2089
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 and GENESIS32 9.x before 9.22 allows remote attackers to execute arbitrary co... Read more
- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2160
The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-072... Read more
- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2594
Heap-based buffer overflow in KMPlayer 3.0.0.1441, and possibly other versions, allows remote attackers to execute arbitrary code via a playlist (.KPL) file with a long Title field.... Read more
Affected Products : kmplayer- Published: Sep. 02, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-4223
Unspecified vulnerability in Investintech.com Absolute PDF Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.... Read more
Affected Products : absolute_pdf_server- Published: Nov. 01, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-4854
The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not ensure that Content-Type HTTP headers match the corresponding Content-Type data in HTML META elements, which might allow remote attackers to have an unspecified impact by leveragi... Read more
- Published: Dec. 16, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0736
IBM Rational AppScan Enterprise 5.x and 8.x before 8.5.0.1 does not properly create scan jobs, which allows remote attackers to execute arbitrary code via a crafted web site.... Read more
Affected Products : rational_appscan- Published: May. 03, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-2611
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EHP1 and EHP2, when a certain Developer Trace configuration is enabled, allows remote attackers to execute a... Read more
Affected Products : netweaver- Published: May. 15, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-4353
Stack-based buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote attackers to execute arbitrary code via a crafted port-46824 TCP packet that triggers an incorrect file-open at... Read more
- Published: Aug. 19, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-4355
TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote attackers to execute arbitrary code via a port-46824 TCP packet with a crafted negative integer after the opcode, triggering incorrect fu... Read more
- Published: Aug. 19, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-4357
Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow remote attackers to execute arbitrary code by referencing, within a port-46824 TCP packet, an invalid file-pointer index that leads to exe... Read more
- Published: Aug. 19, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-5189
Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging read-only administrator privileges and establishing an H... Read more
Affected Products : sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 +6 more products- Published: Aug. 26, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-5006
Heap-based buffer overflow in npdjvu.dll in Caminova DjVu Browser Plug-in 6.1.4 Build 27351 and other versions before 6.1.4.27993 allows remote attackers to execute arbitrary code via a crafted Sjbz chunk in a djvu file.... Read more
Affected Products : djvu_browser_plug-in- Published: Sep. 19, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-6422
The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses weak permissions (0666) for /dev/exynos-mem, which allows attackers to read or write arbitrary physical memor... Read more
- Published: Dec. 18, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-6271
Adobe Shockwave Player through 11.6.8.638 allows remote attackers to trigger installation of arbitrary signed Xtras via a Shockwave movie that contains an Xtra URL, as demonstrated by a URL for an outdated Xtra.... Read more
Affected Products : shockwave_player- Published: Dec. 20, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-5937
Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execut... Read more
Affected Products : sterling_b2b_integrator sterling_file_gateway gentran_integration_suite sterling_integrator- Published: Apr. 12, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0685
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code or cause a denial of service (resource consumption) via unk... Read more
Affected Products : wonderware_information_server- Published: May. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-1115
Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra... Read more
Affected Products : webex_advanced_recording_format_player- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025