Latest CVE Feed
-
9.3
HIGHCVE-2008-4321
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command.... Read more
Affected Products : flashget_ftp- Published: Sep. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-13259
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to ins... Read more
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-5760
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP... Read more
Affected Products : ht802_firmware ht801_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware ht802 ht801 ht812 ht814 +2 more products- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9083
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.... Read more
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-0604
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent ... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0675
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.... Read more
Affected Products : android- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0684
A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.... Read more
Affected Products : android- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2007-0020
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.... Read more
Affected Products : panic_transmit- Published: Jan. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-13806
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD D... Read more
Affected Products : td_keypad_designer- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-9166
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
9.3
HIGHCVE-2019-1641
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-2348
Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.... Read more
Affected Products : batch_audio_converter- Published: Jun. 21, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-5109
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.... Read more
Affected Products : ripper- Published: Dec. 25, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-1260
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.... Read more
Affected Products : ultraiso- Published: Apr. 07, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-0509
Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.... Read more
Affected Products : maklerplus- Published: Jan. 26, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2010-2434
Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.... Read more
Affected Products : explzh- Published: Jun. 25, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-2590
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion propert... Read more
Affected Products : crystal_reports- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2007-3210
Stack-based buffer overflow in nptoken.mox in the Cellosoft Tokens Object 2.0.0.6 extension for Vitalize! allows remote attackers to execute arbitrary code via a long string argument to the RemoveChr method. NOTE: the provenance of this information is un... Read more
Affected Products : cellosoft_tokens_object- Published: Jun. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2864
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.... Read more
- Published: Jun. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2016-1894
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.... Read more
Affected Products : oncommand_workflow_automation- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025