Latest CVE Feed
-
9.3
HIGHCVE-2017-0700
A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-35639138.... Read more
Affected Products : android- EPSS Score: %0.27
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0702
A remote code execution vulnerability in the Android system ui. Product: Android. Versions: 7.1.1, 7.1.2. Android ID: A-36621442.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0703
A elevation of privilege vulnerability in the Android system ui. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-33123882.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2021-39702
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to install certificates without user approval due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges n... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-39706
In onResume of CredentialStorage.java, there is a possible way to cleanup content of credentials storage due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2232
Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : shinseiyo_sogo_soft- EPSS Score: %0.14
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0340
An elevation of privilege vulnerability in the NVIDIA Libnvparser component due to a memcpy into a fixed sized buffer with a user-controlled size could lead to a memory corruption and possible remote code execution. This issue is rated as High. Product: A... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2022-25364
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed anonymous write access. If this was not manually changed, a malicious actor with network access to the build cache could potentially populate it with manipulated ... Read more
Affected Products : enterprise- EPSS Score: %0.30
- Published: Mar. 17, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-1000034
Akka versions <=2.4.16 and 2.5-M1 are vulnerable to a java deserialization attack in its Remoting component resulting in remote code execution in the context of the ActorSystem.... Read more
Affected Products : akka- EPSS Score: %9.55
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2247
Untrusted search path vulnerability in Self-extracting archive files created by Lhaz version 2.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : lhaz- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2269
Untrusted search path vulnerability in FileCapsule Deluxe Portable Ver.2.0.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : filecapsule_deluxe_portable- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2270
Untrusted search path vulnerability in Encrypted files in self-decryption format created by FileCapsule Deluxe Portable Ver.2.0.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : filecapsule_deluxe_portable- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10402
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.... Read more
Affected Products : antivirus- EPSS Score: %1.61
- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2019-6834
A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successf... Read more
Affected Products : software_update- EPSS Score: %0.28
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22797
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could cause malicious script to be deployed in an unauthorized location and may result in code execution on the engineering workstation when ... Read more
- EPSS Score: %0.45
- Published: Apr. 13, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2279
Untrusted search path vulnerability in Tween Ver1.6.6.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : tween- EPSS Score: %0.14
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2286
Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for ... Read more
Affected Products : nfc_port_firmware pc\/sc_activator_for_type_b sfcard_viewer_2 nfc_net_installer rc-s310 rc-s320 rc-s330 rc-s370 rc-s380 rc-s380\/s +2 more products- EPSS Score: %0.14
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2288
Untrusted search path vulnerability in LhaForge Ver.1.6.5 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : lhaforge- EPSS Score: %0.14
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2221
Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : baidu_ime- EPSS Score: %0.14
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-12581
GitHub Electron before 1.6.8 allows remote command execution because of a nodeIntegration bypass vulnerability. This also affects all applications that bundle Electron code equivalent to 1.6.8 or earlier. Bypassing the Same Origin Policy (SOP) is a precon... Read more
- EPSS Score: %1.17
- Published: Aug. 06, 2017
- Modified: Apr. 20, 2025