Latest CVE Feed
-
9.3
HIGHCVE-2017-8268
In all Qualcomm products with Android releases from CAF using the Linux kernel, the camera application can possibly request frame/command buffer processing with invalid values leading to the driver performing a heap buffer over-read.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2013-0655
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data str... Read more
- Published: Jan. 21, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0686
Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document co... Read more
Affected Products : wonderware_information_server- Published: May. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0726
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file.... Read more
Affected Products : erdas_er_viewer- Published: May. 05, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0723
Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a crafted spreadsheet file.... Read more
Affected Products : spreadsheets_2012- Published: Jul. 29, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-1598
Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on acc... Read more
Affected Products : chrome- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1639
Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file.... Read more
Affected Products : kernel_recovery- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1644
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.... Read more
Affected Products : streaming_audio_player- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1666
Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, relate... Read more
Affected Products : cycloscopelite- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-14923
A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.... Read more
Affected Products : ezplayer- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-3041
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitra... Read more
- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3134
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz fi... Read more
Affected Products : earth- Published: Aug. 26, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3143
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .conta... Read more
- Published: Aug. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information... Read more
Affected Products : core_ftp- Published: Sep. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-1636
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows oper... Read more
Affected Products : webex_teams- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-4182
Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, a... Read more
- Published: Nov. 04, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2019-14684
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687... Read more
Affected Products : password_manager- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-25214
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.... Read more
Affected Products : overwolf- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-7914
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.... Read more
Affected Products : moduweb_vision- Published: Feb. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-3865
The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 28799389.... Read more
Affected Products : android- Published: Sep. 11, 2016
- Modified: Apr. 12, 2025