Latest CVE Feed
-
9.3
HIGHCVE-2018-5846
A Use After Free condition can occur in the IPA driver whenever the IPA IOCTLs IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_ADD/IPA_IOC_NOTIFY_WAN_UPSTREAM_ROUTE_DEL/IPA_IOC_NOTIFY_WAN_EMBMS_CONNECTED are called in all Android releases from CAF (Android for MSM, Fir... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-6318
In Sophos Tester Tool 3.2.0.7 Beta, the driver loads (in the context of the application used to test an exploit or ransomware) the DLL using a payload that runs from NTDLL.DLL (so, it's run in userland), but the driver doesn't perform any validation of th... Read more
Affected Products : sophos_tester- EPSS Score: %0.05
- Published: Feb. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-7937
In Huawei HiRouter-CD20-10 with the versions before 1.9.6 and WS5200-10 with the versions before 1.9.6, there is a plug-in signature bypass vulnerability due to insufficient plug-in verification. An attacker may tamper with a legitimate plug-in to build a... Read more
- EPSS Score: %0.07
- Published: Sep. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-8930
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3.... Read more
- EPSS Score: %0.60
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0350
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's tooltip. NOTE: some of these details are obtained from third party informa... Read more
Affected Products : media_player- EPSS Score: %7.86
- Published: Jan. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-9553
In MasteringMetadata::Parse of mkvparser.cc there is a possible double free due to an insecure default value. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: An... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-5520
AhnLab V3 2008.12.4.1 and possibly 2008.9.13.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-6247
An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High due to the possibility of local arbitrary code execution ... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-5524
CAT-QuickHeal 10.00 and possibly 9.50, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no e... Read more
- EPSS Score: %0.29
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-8209
The driver of honor 5C,honor 6x Huawei smart phones with software of versions earlier than NEM-AL10C00B356, versions earlier than Berlin-L21HNC432B360 have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user ... Read more
- EPSS Score: %0.18
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8237
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists while loading a firmware image.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2019-11957
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.... Read more
Affected Products : intelligent_management_center- EPSS Score: %2.38
- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1597
Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on a... Read more
- EPSS Score: %0.25
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2876
Heap-based buffer overflow in atas32.dll in the Cisco WebEx WRF Player 26.x before 26.49.32 (aka T26SP49EP32) for Windows, 27.x before 27.10.x (aka T27SP10) for Windows, 26.x before 26.49.35 for Mac OS X and Linux, and 27.x before 27.11.8 for Mac OS X and... Read more
Affected Products : webex- EPSS Score: %2.52
- Published: Dec. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1675
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 227 reply to a PASV command.... Read more
Affected Products : 32bit_ftp- EPSS Score: %5.53
- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1792
The system.openURL function in StoneTrip Ston3D StandalonePlayer (aka S3DPlayer StandAlone) 1.6.2.4 and 1.7.0.1 and WebPlayer (aka S3DPlayer Web) 1.6.0.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the first argument ... Read more
- EPSS Score: %1.61
- Published: May. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-6596
mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a different vulnerability than CVE-2015-7717.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-2583
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to ... Read more
Affected Products : ssl-vpn_end-point_interrogator\/installer_activex_control- EPSS Score: %7.76
- Published: Nov. 03, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-15573
An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /goform/edit_lf_process with file content in the lfdata para... Read more
Affected Products : reprise_license_manager- EPSS Score: %0.26
- Published: Aug. 20, 2018
- Modified: Apr. 30, 2025
-
9.3
HIGHCVE-2019-15295
An Untrusted Search Path vulnerability in the ServiceInstance.dll library versions 1.0.15.119 and lower, as used in Bitdefender Antivirus Free 2020 versions prior to 1.0.15.138, allows an attacker to load an arbitrary DLL file from the search path.... Read more
Affected Products : antivirus_2020- EPSS Score: %0.16
- Published: Aug. 21, 2019
- Modified: Nov. 21, 2024