Latest CVE Feed
-
9.3
HIGHCVE-2016-8385
An exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF to XML a stack variable will be left uninitialized which will later be used to fetch a leng... Read more
Affected Products : argus- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2018-10731
All Phoenix Contact managed FL SWITCH 3xxx, 4xxx, 48xx products running firmware version 1.0 to 1.33 are prone to buffer overflows when handling very large cookies (a different vulnerability than CVE-2018-10728).... Read more
Affected Products : fl_switch_3005_firmware fl_switch_3005t_firmware fl_switch_3004t-fx_firmware fl_switch_3004t-fx_st_firmware fl_switch_3008_firmware fl_switch_3008t_firmware fl_switch_3006t-2fx_firmware fl_switch_3006t-2fx_st_firmware fl_switch_3012e-2sfx_firmware fl_switch_3016e_firmware +48 more products- Published: May. 17, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-2244
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.... Read more
- Published: Apr. 25, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2016-8432
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-2821
Directory traversal vulnerability in the FTP client in Glub Tech Secure FTP before 2.5.16 on Windows allows remote FTP servers to create or overwrite arbitrary files via a ..\ (dot dot backslash) in a response to a LIST command, a related issue to CVE-200... Read more
- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2010-2702
Buffer overflow in the UGameEngine::UpdateConnectingMessage function in the Unreal engine 1, 2, and 2.5, as used in multiple games including Unreal Tournament 2004, Unreal tournament 2003, Postal 2, Raven Shield, and SWAT4, when downloads are enabled, all... Read more
Affected Products : unreal_engine postal_2 raven_shield swat_4 unreal_tournament_2003 unreal_tournament_2004- Published: Jul. 12, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2019-2003
In addLinks of Linkify.java, there is a possible phishing vector due to an unusual root cause. This could lead to remote code execution or misdirection of clicks with no additional execution privileges needed. User interaction is needed for exploitation.P... Read more
Affected Products : android- Published: Jun. 19, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-6639
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.... Read more
Affected Products : android- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2018-15416
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
Affected Products : webex_meetings_server webex_meetings_online webex_business_suite_32 webex_business_suite_33- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-1552
IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file ... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- Published: Nov. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-34078
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.... Read more
Affected Products : lifion-verifiy-dependencies- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-10887
Untrusted search path vulnerability in BOOK WALKER for Windows Ver.1.2.9 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
CRITICALCVE-2022-31584
The stonethree/s3label repository through 2019-08-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : s3label- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2020-15271
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on t... Read more
Affected Products : lookatme- Published: Oct. 26, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-40157
A user may be tricked into opening a malicious FBX file which may exploit an Untrusted Pointer Dereference vulnerability in FBX’s Review version 1.5.0 and prior causing it to run arbitrary code on the system.... Read more
Affected Products : fbx_review- Published: Sep. 15, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2014-9799
The makefile in the Qualcomm components in Android before 2016-07-05 on Nexus 5 and 7 (2013) devices omits the -fno-strict-overflow option to gcc, which might allow attackers to gain privileges via a crafted application that leverages incorrect compiler o... Read more
Affected Products : android- Published: Jul. 11, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2476
mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or S... Read more
Affected Products : android- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2018-16364
A serialization vulnerability in Zoho ManageEngine Applications Manager before build 13740 allows for remote code execution on Windows via a payload on an SMB share.... Read more
- Published: Sep. 26, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-14591
Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary code on a system running the impacted software.... Read more
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2007-2283
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.... Read more
Affected Products : freshview- Published: Apr. 26, 2007
- Modified: Apr. 09, 2025