Latest CVE Feed
-
9.3
HIGHCVE-2022-32252
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, gran... Read more
Affected Products : sinema_remote_connect_server- EPSS Score: %0.13
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2020-6238
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.... Read more
- EPSS Score: %0.41
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-7922
Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more
- EPSS Score: %0.12
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-31588
The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more
Affected Products : testplatform- EPSS Score: %0.41
- Published: Jul. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-10750
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'staticGet <node_name attr>' function and cause ... Read more
- EPSS Score: %0.97
- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-3842
Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.... Read more
Affected Products : android- EPSS Score: %0.46
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2023-0606
Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.... Read more
Affected Products : ampache- EPSS Score: %0.14
- Published: Feb. 01, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-5279
Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.... Read more
- EPSS Score: %18.33
- Published: Oct. 09, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-8936
The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.... Read more
- EPSS Score: %0.60
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0679
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument t... Read more
Affected Products : chemview- EPSS Score: %73.24
- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-9232
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.... Read more
- EPSS Score: %0.19
- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-3400
The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.... Read more
- EPSS Score: %6.42
- Published: Jun. 26, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-9490
In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Pro... Read more
Affected Products : android- EPSS Score: %0.32
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9521
In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is... Read more
Affected Products : android- EPSS Score: %0.48
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9571
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ex... Read more
Affected Products : android- EPSS Score: %0.37
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9577
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is nee... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9574
In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed fo... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-4723
Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.... Read more
Affected Products : smarty- EPSS Score: %0.43
- Published: Feb. 03, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0742
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory entry name in an XPS file.... Read more
Affected Products : pdf_fusion- EPSS Score: %76.06
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-3027
Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.... Read more
Affected Products : lotus_domino- EPSS Score: %4.40
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025