Latest CVE Feed
-
9.3
HIGHCVE-2010-3126
Untrusted search path vulnerability in avast! Free Antivirus version 5.0.594 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse mfc90loc.dll that is located in the ... Read more
Affected Products : avast_antivirus_free- EPSS Score: %1.70
- Published: Aug. 26, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2021-22369
There is a Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability in Huawei Smartphone. Successful exploitation of these vulnerabilities may escalate the permission to that of the root user.... Read more
- EPSS Score: %0.16
- Published: Jun. 30, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-3611
admin.php in VRNews 1.1.1, and possibly other 1.x versions, does not require authentication, which allows remote attackers to perform certain administrative actions via a direct request with a (1) edit, (2) add, (3) config, or (4) del value in the act par... Read more
Affected Products : vrnews- EPSS Score: %1.89
- Published: Jul. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-17109
HEVC Video Extensions Remote Code Execution Vulnerability... Read more
Affected Products : hevc_video_extensions- EPSS Score: %7.89
- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-0340
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0... Read more
- EPSS Score: %47.35
- Published: May. 04, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-0819
The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 25364034.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-0403
Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located... Read more
Affected Products : imgburn- EPSS Score: %5.70
- Published: Jan. 11, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2007-1332
Multiple cross-site request forgery (CSRF) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers to perform unspecified restricted actions in the context of certain accounts by bypassing the client-side protection scheme.... Read more
Affected Products : eportfolio- EPSS Score: %0.65
- Published: Mar. 07, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2021-38305
23andMe Yamale before 3.0.8 allows remote attackers to execute arbitrary code via a crafted schema file. The schema parser uses eval as part of its processing, and tries to protect from malicious expressions by limiting the builtins that are passed to the... Read more
Affected Products : yamale- EPSS Score: %0.64
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-1999-0766
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.... Read more
- EPSS Score: %6.50
- Published: Oct. 21, 1999
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2007-0912
Cross-Site Request Forgery (CSRF) vulnerability in admin/admin.adm.php in Jportal 2.3.1, and possibly earlier, allows remote attackers to perform privileged actions as administrators by tricking the admin into accessing a URL with modified arguments to ad... Read more
Affected Products : jportal_web_server- EPSS Score: %0.72
- Published: Feb. 13, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1017
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the newsordner parameter.... Read more
Affected Products : vs-news-system- EPSS Score: %10.32
- Published: Feb. 21, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2062
Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary code via a long FILE argument in a CUE file.... Read more
Affected Products : vcdgear- EPSS Score: %6.84
- Published: Apr. 18, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2585
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument.... Read more
Affected Products : barcode_activex_control- EPSS Score: %8.50
- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3296
The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by invoking dangerous methods.... Read more
Affected Products : web_thunderbolt- EPSS Score: %0.62
- Published: Jun. 20, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3963
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade... Read more
Affected Products : usebb- EPSS Score: %1.43
- Published: Jul. 25, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5248
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a... Read more
- EPSS Score: %7.81
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5487
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an EXTM3U section of a .m3u file.... Read more
- EPSS Score: %7.97
- Published: Oct. 16, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-2163
Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors.... Read more
- EPSS Score: %0.51
- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-4473
Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.... Read more
- EPSS Score: %20.94
- Published: Oct. 17, 2008
- Modified: Apr. 09, 2025