Latest CVE Feed
-
9.3
HIGHCVE-2017-6264
An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used as a function pointer could lead to code execution in the kernel.This issue is rated as high because it cou... Read more
- EPSS Score: %0.40
- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2009-3364
Stack-based buffer overflow in FTPShell Client 4.1 RC2 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.... Read more
Affected Products : ftpshell- EPSS Score: %6.22
- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5155
mail2sms.sh in smsclient 2.0.8z allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/header.##### or (2) /tmp/body.##### temporary file, or append data to arbitrary files via a symlink attack on the (3) /tmp/sms.log temporary... Read more
Affected Products : smsclient- EPSS Score: %0.16
- Published: Nov. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3670
Stack-based buffer overflow in KSP Sound Player 2009 R2 and R2.1 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file.... Read more
Affected Products : ksp_sound_player- EPSS Score: %5.82
- Published: Oct. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5495
Unspecified vulnerability in the GungHo LoadPrgAx ActiveX control 1.0.0.6 and earlier allows remote attackers to execute arbitrary Java applications via unknown vectors.... Read more
Affected Products : loadprgax_control- EPSS Score: %1.76
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-6995
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-5530
Ewido Security Suite 4.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2)... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5547
HAURI ViRobot 2008.12.4.1499 and possibly 2008.9.12.1375, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filena... Read more
Affected Products : virobot- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4186
Stack consumption vulnerability in Apple Safari 4.0.3 on Windows allows remote attackers to cause a denial of service (application crash) via a long URI value (aka url) in the Cascading Style Sheets (CSS) background property.... Read more
- EPSS Score: %4.30
- Published: Dec. 03, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-5406
The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perform sensitive acti... Read more
- EPSS Score: %16.60
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-2211
Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : patchjgd- EPSS Score: %0.14
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2012-4858
IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 does not properly validate Java serialized input, which allows remote attackers to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %1.95
- Published: Mar. 05, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-5846
A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Fir... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-6318
In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payload that runs from NTDLL.DLL (so, it's run in userland), but the driver doesn't perform any validation of th... Read more
Affected Products : sophos_tester- EPSS Score: %0.05
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-7937
In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a... Read more
- EPSS Score: %0.07
- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8930
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3.... Read more
- EPSS Score: %0.60
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0350
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party informa... Read more
Affected Products : media_player- EPSS Score: %7.86
- Published: Jan. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-9553
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: An... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-5520
AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-6247
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of local arbitrary code execution ... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025