Latest CVE Feed
-
9.3
HIGHCVE-2009-1598
Google Chrome executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on acc... Read more
Affected Products : chrome- EPSS Score: %0.31
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1639
Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Novell 4.03 allows user-assisted attackers to execute arbitrary code via a crafted .NKNT file.... Read more
Affected Products : kernel_recovery- EPSS Score: %1.32
- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1641
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.... Read more
Affected Products : ripper- EPSS Score: %65.93
- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1644
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via a crafted .pla file.... Read more
Affected Products : streaming_audio_player- EPSS Score: %8.65
- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1666
Multiple unspecified vulnerabilities in CycloMedia CycloScopeLite 2.50.3.0 allow remote attackers to execute arbitrary code via the ReturnConnection method in (1) CM_ADOConnection.dll, (2) CM_AddressInfoDBC.dll, and (3) CM_RecordingLocationDBC.dll, relate... Read more
Affected Products : cycloscopelite- EPSS Score: %1.85
- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-14923
A vulnerability in uniview EZPlayer 1.0.6 could allow an attacker to execute arbitrary code on a targeted system via video playback.... Read more
Affected Products : ezplayer- EPSS Score: %0.23
- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1815
Stack-based buffer overflow in Sonic Spot Audioactive Player 1.93b allows remote attackers to execute arbitrary code via a long string in a playlist file, as demonstrated by a long .mp3 URL in a .m3u file.... Read more
Affected Products : audioactive_player- EPSS Score: %9.71
- Published: May. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2016-2437
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27436822.... Read more
- EPSS Score: %0.04
- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2470
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27662174.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2479
The mm-video-v4l2 vdec component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrated ... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2505
mpeg2ts/ATSParser.cpp in libstagefright in mediaserver in Android 6.x before 2016-07-01 does not validate a certain section length, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted medi... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jul. 11, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2008-4652
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remote attackers to execute arbitrary code via a long SecretKey property.... Read more
Affected Products : powertcp_ftp_for_activex- EPSS Score: %11.43
- Published: Oct. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2010-3041
Multiple buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitra... Read more
- EPSS Score: %10.94
- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3132
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) mf... Read more
Affected Products : dreamweaver- EPSS Score: %3.17
- Published: Aug. 26, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3134
Untrusted search path vulnerability in Google Earth 5.1.3535.3218 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse quserex.dll that is located in the same folder as a .kmz fi... Read more
Affected Products : earth- EPSS Score: %1.47
- Published: Aug. 26, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3143
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wab32res.dll that is located in the same folder as a .conta... Read more
Affected Products : windows- EPSS Score: %11.37
- Published: Aug. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3154
Untrusted search path vulnerability in Adobe Extension Manager CS5 5.0.298 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a... Read more
Affected Products : extension_manager_cs5- EPSS Score: %3.34
- Published: Aug. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-2435
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.... Read more
- EPSS Score: %23.98
- Published: Dec. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code via a long hostname in an FTP server entry in a site backup file. NOTE: some of these details are obtained from third party information... Read more
Affected Products : core_ftp- EPSS Score: %7.38
- Published: Sep. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-1636
A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows oper... Read more
Affected Products : webex_teams- EPSS Score: %7.50
- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024