Latest CVE Feed
-
9.3
HIGHCVE-2013-1119
Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT ... Read more
Affected Products : webex_recording_format_player- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-2503
The Qualcomm GPU driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28084795 and Qualcomm internal bug CR1006067.... Read more
Affected Products : android- Published: Jul. 11, 2016
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2020-7819
A SQL-Injection vulnerability in the nTracker USB Enterprise(secure USB management solution) allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information.... Read more
- Published: Sep. 07, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-3209
Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control Activ... Read more
Affected Products : black_ice_document_imaging_sdk- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2014-9961
In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write protection.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9967
In all Android releases from CAF using the Linux kernel, an untrusted pointer dereference vulnerability exists in WideVine DRM.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9924
In 1x in all Android releases from CAF using the Linux kernel, a Signed to Unsigned Conversion Error could potentially occur.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-8319
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, a... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2009-2011
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a plug-in for Firefox, does not restrict access to the shell.execute JavaScript API method, which allows remote attackers to execute arbit... Read more
- Published: Jun. 16, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5764
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the lang parameter.... Read more
Affected Products : worksimple- Published: Dec. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3773
Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators.... Read more
Affected Products : generic_youtube_clone_script- Published: Jul. 15, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2013-2602
Multiple array index errors in the MyHeritage SEQueryObject ActiveX control (SearchEngineQuery.dll) 1.0.2.0 allow remote attackers to execute arbitrary code via the (1) seTokensArray, or (2) seTokensValuesArray parameter to the AddTokens method; (3) seLas... Read more
Affected Products : sequeryobject_activex_control- Published: Jun. 06, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-2691
Stack-based buffer overflow in the JetMPG.ax module in jetAudio 8.0.17 allows remote attackers to execute arbitrary code via a crafted MPEG2-TS video file, related to the MPEG2 transport stream.... Read more
Affected Products : jetaudio- Published: Feb. 05, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-8939
drivers/video/msm/mdp4_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not validate r stages, g stages, or b stages data, which allows attackers to gain privileges via a crafted application, aka Android intern... Read more
Affected Products : android- Published: Aug. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-9028
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-1861
The client in Jetro COCKPIT Secure Browsing (JCSB) 4.3.1 and 4.3.3 does not validate the FileName element in an RDP_FILE_TRANSFER document, which allows remote JCSB servers to execute arbitrary programs by providing a .EXE extension.... Read more
Affected Products : jetro_cockpit_secure_browsing- Published: Feb. 18, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2021-22369
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.... Read more
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-17109
HEVC Video Extensions Remote Code Execution Vulnerability... Read more
Affected Products : hevc_video_extensions- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-0340
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0... Read more
- Published: May. 04, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-0819
The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 25364034.... Read more
Affected Products : android- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025