Latest CVE Feed
-
9.3
HIGHCVE-2018-9571
In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ex... Read more
Affected Products : android- EPSS Score: %0.37
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9577
In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is nee... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9574
In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed fo... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-4723
Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.... Read more
Affected Products : smarty- EPSS Score: %0.43
- Published: Feb. 03, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0742
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory entry name in an XPS file.... Read more
Affected Products : pdf_fusion- EPSS Score: %76.06
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-3027
Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.... Read more
Affected Products : lotus_domino- EPSS Score: %4.40
- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-4321
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command.... Read more
Affected Products : flashget_ftp- EPSS Score: %36.20
- Published: Sep. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-13259
A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to ins... Read more
- EPSS Score: %1.04
- Published: Sep. 16, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-5760
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP... Read more
Affected Products : ht802_firmware ht801_firmware ht812_firmware ht814_firmware ht818_firmware ht813_firmware ht802 ht801 ht812 ht814 +2 more products- EPSS Score: %3.94
- Published: Jul. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9083
In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.... Read more
- EPSS Score: %0.36
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2006-7046
PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter. NOTE: the provenance of this information is unknown; the d... Read more
Affected Products : clan_manager_pro- EPSS Score: %0.69
- Published: Feb. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-0604
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent ... Read more
Affected Products : android- EPSS Score: %0.04
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
CRITICALCVE-2020-13536
An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewServic... Read more
Affected Products : mxview- EPSS Score: %0.03
- Published: Nov. 05, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2006-7185
PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a URL in the relative_root parameter.... Read more
Affected Products : cmsmelborp- EPSS Score: %4.16
- Published: Mar. 30, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-0675
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0684
A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2007-0020
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.... Read more
Affected Products : panic_transmit- EPSS Score: %7.34
- Published: Jan. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-13806
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD D... Read more
Affected Products : td_keypad_designer- EPSS Score: %0.23
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-9166
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.... Read more
Affected Products :- Published: Sep. 26, 2024
- Modified: Sep. 30, 2024
-
9.3
HIGHCVE-2013-0654
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.... Read more
- EPSS Score: %0.73
- Published: Jan. 27, 2013
- Modified: Apr. 11, 2025