Latest CVE Feed
-
9.3
HIGHCVE-2007-2585
Stack-based buffer overflow in the Verify function in the BarCodeWiz ActiveX control 2.0 and 2.52 (BarcodeWiz.dll) allows remote attackers to execute arbitrary code via a long argument.... Read more
Affected Products : barcode_activex_control- EPSS Score: %8.50
- Published: May. 10, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3296
The ThunderServer.webThunder.1 ActiveX control in xunlei Web Thunderbolt 1.7.3.109 allows remote attackers to download arbitrary files and conduct other unauthorized actions by invoking dangerous methods.... Read more
Affected Products : web_thunderbolt- EPSS Score: %0.62
- Published: Jun. 20, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3963
Multiple cross-site scripting (XSS) vulnerabilities in UseBB 1.0.7, and possibly other 1.0.x versions, allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (PHP_SELF) to (1) upgrade-0-2-3.php, (2) upgrade-0-3.php, or (3) upgrade... Read more
Affected Products : usebb- EPSS Score: %1.43
- Published: Jul. 25, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5248
Multiple format string vulnerabilities in the ID Software Doom 3 engine, as used by Doom 3 1.3.1 and earlier, Quake 4 1.4.2 and earlier, and Prey 1.3 and earlier, when Punkbuster (PB) is enabled, allow remote attackers to execute arbitrary code or cause a... Read more
- EPSS Score: %7.81
- Published: Oct. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5487
Stack-based buffer overflow in COWON America jetAudio Basic 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a long URL in an EXTM3U section of a .m3u file.... Read more
- EPSS Score: %7.97
- Published: Oct. 16, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-2163
Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors.... Read more
- EPSS Score: %0.51
- Published: May. 20, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-4473
Multiple heap-based buffer overflows in Adobe Flash CS3 Professional on Windows and Flash MX 2004 allow remote attackers to execute arbitrary code via an SWF file containing long control parameters.... Read more
- EPSS Score: %20.94
- Published: Oct. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4749
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, possibly 4.7.7, allow remote attackers to overwrite arbitrary files via (1) the LogFile property and ClearLogFile method, an... Read more
Affected Products : vimp_x- EPSS Score: %2.72
- Published: Oct. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5176
Multiple buffer overflows in Client Software WinCom LPD Total 3.0.2.623 and earlier allow remote attackers to execute arbitrary code via (1) a long 0x02 command to the remote administration service on TCP port 13500 or (2) a long invalid control filename ... Read more
Affected Products : wincom_mpd_total- EPSS Score: %8.20
- Published: Nov. 20, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-0632
Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the blog's root direct... Read more
Affected Products : lightblog- EPSS Score: %7.84
- Published: Feb. 06, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-6748
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.... Read more
Affected Products : megacubo- EPSS Score: %7.29
- Published: Apr. 24, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-4644
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an environment that intentionally does not support authentication, which allows remote attackers to (1) read arbitrary files via a management-c... Read more
Affected Products : splunk- EPSS Score: %6.66
- Published: Jan. 03, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-10572
mongodb-instance before 0.0.3 installs mongodb locally. mongodb-instance downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an... Read more
Affected Products : mongodb-instance- EPSS Score: %0.77
- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10688
Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested reso... Read more
Affected Products : haxe- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10691
windows-seleniumjar is a module that downloads the Selenium Jar file windows-seleniumjar downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requeste... Read more
Affected Products : windows-seleniumjar- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-1495
Integer overflow in the graphics drivers in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or g... Read more
- EPSS Score: %0.06
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2452
codecs/amrnb/dec/SoftAMR.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not validate buffer sizes, which allows attackers to gain privileges via a crafted applicatio... Read more
Affected Products : android- EPSS Score: %0.07
- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2466
The Qualcomm sound driver in Android before 2016-06-01 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka internal bug 27947307.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2481
The mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 mishandles a buffer count, which allows attackers to gain privileges via a crafted application, as demonstrated ... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2008-0311
Stack-based buffer overflow in the PGMWebHandler::parse_request function in the StarTeam Multicast Service component (STMulticastService) 6.4 in Borland CaliberRM 2006 allows remote attackers to execute arbitrary code via a large HTTP request.... Read more
Affected Products : caliberrm- EPSS Score: %65.00
- Published: Apr. 06, 2008
- Modified: Apr. 09, 2025