Latest CVE Feed
-
9.3
HIGHCVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information... Read more
Affected Products : core_ftp- Published: Sep. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-1636
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows oper... Read more
Affected Products : webex_teams- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-4182
Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, a... Read more
- Published: Nov. 04, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2019-14684
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687... Read more
Affected Products : password_manager- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-25214
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.... Read more
Affected Products : overwolf- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-7914
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.... Read more
Affected Products : moduweb_vision- Published: Feb. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3865
The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.... Read more
Affected Products : android- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3916
camera/src/camera_metadata.c in the Camera service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 307417... Read more
Affected Products : android- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3928
The MediaTek video driver in Android before 2016-10-05 allows attackers to gain privileges via a crafted application, aka Android internal bug 30019362 and MediaTek internal bug ALPS02829384.... Read more
Affected Products : android- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3939
drivers/video/msm/mdss/mdss_debug.c in the Qualcomm video driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 30874196 and Qual... Read more
Affected Products : android- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2019-1772
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
Affected Products : webex_meetings_server webex_meetings_online webex_business_suite webex_business_suite_lockdown- Published: May. 15, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-27277
Delta Electronics DOPSoft Version 4.0.8.21 and prior has a null pointer dereference issue while processing project files, which may allow an attacker to execute arbitrary code.... Read more
- Published: Jan. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2253
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : toolbar- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2019-1989
In ih264d_fmt_conv_420sp_to_420p of ih264d_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploi... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2014
In rw_t3t_handle_get_sc_poll_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitati... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2015
In rw_t3t_act_handle_check_rsp of rw_t3t.cc, there is a possible out-of-bound write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2213
Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : semidynaexe- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2019-2134
In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ex... Read more
Affected Products : android- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-0099
In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is need... Read more
Affected Products : android- Published: Dec. 14, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGH- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024