Latest CVE Feed
-
9.3
HIGHCVE-2016-2435
The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27297988.... Read more
- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2440
libs/binder/IPCThreadState.cpp in Binder in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 mishandles object references, which allows attackers to gain privileges via a crafted application, aka internal bug 272... Read more
Affected Products : android- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2478
mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles pointers, which allows attackers to gain privileges via a crafted application, as dem... Read more
Affected Products : android- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2480
The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate certain OMX parameter data structures, which allows attackers to gain privileges via a crafted... Read more
Affected Products : android- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-2620
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.... Read more
Affected Products : open-ftpd- Published: Jul. 02, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3098
Directory traversal vulnerability in IoRush Software FTP Rush 1.1.3 and possibly earlier allows remote FTP servers to overwrite arbitrary files via a "..\" (dot dot backslash) in a filename.... Read more
Affected Products : ftprush- Published: Aug. 20, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-3680
Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (crash) or possibly gain priv... Read more
- Published: May. 26, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2019-5242
There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker... Read more
Affected Products : pcmanager- Published: Jun. 06, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-6539
Several heap-based buffer overflow vulnerabilities in WECON LeviStudioU version 1.8.56 and prior have been identified, which may allow arbitrary code execution. Mat Powell, Ziad Badawi, and Natnael Samson working with Trend Micro's Zero Day Initiative, re... Read more
Affected Products : levistudiou- Published: Feb. 13, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-8724
Multiple issues in ld64 in the Xcode toolchains were addressed by updating to version ld64-507.4. This issue is fixed in Xcode 11.0. Compiling code without proper input validation could lead to arbitrary code execution with user privilege.... Read more
Affected Products : xcode- Published: Dec. 18, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2434
The Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to download an arbitrary library file onto a client system via a "custom update server" argument. NOTE: this can be leveraged for code e... Read more
- Published: Dec. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-2729
The boot loaders in Honor 5A smart phones with software Versions earlier than CAM-TL00C01B193,Versions earlier than CAM-TL00HC00B193,Versions earlier than CAM-UL00C00B193 have a buffer overflow vulnerability. An attacker with the root privilege of an Andr... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9003
In TrustZone a cryptographic issue can potentially occur in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6042
IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability ... Read more
Affected Products : security_appscan- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2020-5242
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all command... Read more
Affected Products : openhab- Published: Feb. 20, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-3189
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on... Read more
Affected Products : dotcms- Published: Jul. 24, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-1033
Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET ENVIRONMENT statement.... Read more
Affected Products : informix_dynamic_server- Published: Feb. 15, 2011
- Modified: Apr. 11, 2025
-
9.3
CRITICALCVE-2019-13412
A service which is hosted on port 3097 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).... Read more
- Published: Oct. 17, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-1528
Integer overflow in the native_handle_create function in libcutils/native_handle.c in Android before 5.1.1 LMY48M allows attackers to obtain a different application's privileges or cause a denial of service (Binder heap memory corruption) via a crafted ap... Read more
Affected Products : android- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2019-1924
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024