Latest CVE Feed
-
9.3
HIGHCVE-2011-5158
Multiple untrusted search path vulnerabilities in the DMTGUI2.EXE and DvInesLogFileViewer.Exe components in DATEV Grundpaket Basis CD23.20 allow local users to gain privileges via a Trojan horse (1) DVBSKNLANG101.dll or (2) DvZediTermSrvInfo004.dll file i... Read more
Affected Products : grundpaket_basis- EPSS Score: %0.56
- Published: Sep. 07, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-0449
In btm_sec_disconnected of btm_sec.cc, there is a possible memory corruption due to a use after free. This could lead to remote code execution in the Bluetooth server with no additional execution privileges needed. User interaction is needed for exploitat... Read more
Affected Products : android- EPSS Score: %0.29
- Published: Nov. 10, 2020
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-48974
The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a co... Read more
Affected Products :- Published: Nov. 14, 2024
- Modified: Nov. 15, 2024
-
9.3
HIGHCVE-2012-6558
Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the size value for a string in the resource section of a Portable Executable (PE) file.... Read more
Affected Products : pe_explorer- EPSS Score: %7.76
- Published: May. 23, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4265
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to execute arbitrary code via a long Computer value in an .ipj project file.... Read more
Affected Products : ideal_administration_2009- EPSS Score: %67.07
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2012-0204
Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileg... Read more
- EPSS Score: %0.66
- Published: Jan. 31, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0224
Untrusted search path vulnerability in 7-Technologies (7T) AQUIS 1.5 and earlier allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2012-0223.... Read more
Affected Products : aquis- EPSS Score: %0.49
- Published: Feb. 21, 2012
- Modified: Apr. 11, 2025
-
9.3
CRITICALCVE-2024-5328
A Server-Side Request Forgery (SSRF) vulnerability exists in the lunary-ai/lunary application, specifically within the endpoint '/auth/saml/tto/download-idp-xml'. The vulnerability arises due to the application's failure to validate user-supplied URLs bef... Read more
Affected Products : lunary- Published: Jun. 06, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2013-0113
Nuance PDF Reader 7.0 and PDF Viewer Plus 7.1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document.... Read more
- EPSS Score: %3.57
- Published: Feb. 24, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2017-8142
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user... Read more
- EPSS Score: %0.20
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2009-4676
Stack-based buffer overflow in JetCast.exe 2.0.4.1109 in jetAudio 7.5.2 and 7.5.3.15 allows remote attackers to execute arbitrary code via a long title in a FLAC file. NOTE: the provenance of this information is unknown; the details are obtained solely f... Read more
- EPSS Score: %5.61
- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2014-9869
drivers/media/platform/msm/camera_v2/isp/msm_isp_stats_util.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain index values, which allows attackers to gain privileges via a crafted applicati... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Aug. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2007-1787
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir pa... Read more
Affected Products : time-assistant- EPSS Score: %7.19
- Published: Mar. 31, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4720
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) page/forums/bottom.php and (2) page/forums/category.php.... Read more
Affected Products : gemini_portal- EPSS Score: %1.30
- Published: Oct. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-0427
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.... Read more
Affected Products : html_help_workshop- EPSS Score: %53.91
- Published: Jan. 23, 2007
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2022-31512
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : flask-mvc- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31518
The JustAnotherSoftwareDeveloper/Python-Recipe-Database repository through 2021-03-31 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : python-recipe-database- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-0134
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector... Read more
Affected Products : easy_grid_control- EPSS Score: %5.64
- Published: Jan. 16, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2024-24986
Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products : ethernet_800_series_controllers_driver- Published: Aug. 14, 2024
- Modified: Sep. 06, 2024
-
9.3
CRITICALCVE-2022-31577
The longmaoteamtf/audio_aligner_app repository through 2020-01-10 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : audio_aligner_app- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024