Latest CVE Feed
-
9.3
HIGHCVE-2012-4710
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with... Read more
Affected Products : wonderware_win-xml_exporter- EPSS Score: %0.46
- Published: Apr. 04, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-6447
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.... Read more
Affected Products : easymail_mailstore_object- EPSS Score: %8.66
- Published: Mar. 09, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4755
Multiple stack-based buffer overflows in Mercury Audio Player 1.21 allow remote attackers to execute arbitrary code via a long string in a malformed (1) .b4s or (2) .pls playlist file.... Read more
Affected Products : audio_player- EPSS Score: %7.01
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4759
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .BMX file.... Read more
Affected Products : bmxplay- EPSS Score: %4.97
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4769
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabl... Read more
Affected Products : httpdx- EPSS Score: %62.14
- Published: Apr. 20, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4841
Heap-based buffer overflow in the SonicMediaPlayer ActiveX control in SonicMediaPlayer.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the DiskType method. NOTE: this might overlap CVE-2007-1559.... Read more
Affected Products : cineplayer- EPSS Score: %4.74
- Published: May. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-6734
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the action parameter.... Read more
Affected Products : kwa- EPSS Score: %1.87
- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-6461
March Hare WINCVS before 2.8.01 build 6610, and CVS Suite before 2009R2 build 6610, contains an Insecure Library Loading vulnerability in the wincvs2.exe or wincvs.exe file, which may allow local users to gain privileges via a Trojan horse Python or TCL D... Read more
- EPSS Score: %0.13
- Published: Feb. 05, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-7070
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE:... Read more
Affected Products : kvirc- EPSS Score: %3.33
- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-7168
Insecure method vulnerability in the UUSee UUUpgrade ActiveX control (UUUpgrade.ocx 3.0.2.12) allows remote attackers to force the download and overwrite of arbitrary files via crafted arguments to the Update method, as exploited in the wild in June 2009.... Read more
- EPSS Score: %2.32
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-0555
Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a specially crafted file.... Read more
- EPSS Score: %0.45
- Published: Apr. 09, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-3088
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua1316... Read more
Affected Products : anyconnect_secure_mobility_client- EPSS Score: %0.48
- Published: Sep. 16, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-0175
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in an invalid .mp3 file.... Read more
Affected Products : mp3_trackmaker- EPSS Score: %7.86
- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-0181
Buffer overflow in VUPlayer allows user-assisted attackers to have an unknown impact via a long file, as demonstrated by a file composed entirely of 'A' characters.... Read more
Affected Products : vuplayer- EPSS Score: %0.34
- Published: Jan. 20, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-9427
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. P... Read more
Affected Products : android- EPSS Score: %3.06
- Published: Nov. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9550
In CAacDecoder_Init of aacdecoder.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: An... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Dec. 06, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0465
The SaveDoc method in the All_In_The_Box.AllBox ActiveX control in ALL_IN_THE_BOX.OCX in Synactis ALL In-The-Box ActiveX 3 allows remote attackers to create and overwrite arbitrary files via an argument ending in a '\0' character, which bypasses the inten... Read more
Affected Products : all_in_the_box.ocx- EPSS Score: %6.77
- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-11285
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429,... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd845_firmware mdm9650_firmware msm8909w_firmware sd210_firmware sd625_firmware sd835_firmware sdx20_firmware sd205_firmware +54 more products- EPSS Score: %0.10
- Published: Sep. 20, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0569
Buffer overflow in Becky! Internet Mail 2.48.02 and earlier allows remote attackers to execute arbitrary code via a mail message with a crafted return receipt request.... Read more
Affected Products : becky\!_internet_mail- EPSS Score: %11.68
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-11551
AXON PBX 2.02 contains a DLL hijacking vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on a targeted system. The vulnerability exists because a DLL file is loaded by 'pbxsetup.exe' improperly.... Read more
Affected Products : axon_pbx- EPSS Score: %1.43
- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024