Latest CVE Feed
-
9.3
CRITICALCVE-2024-8752
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 20, 2024
-
9.3
HIGHCVE-2020-4724
IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute a... Read more
Affected Products : i2_analysts_notebook- Published: Oct. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9496
In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitatio... Read more
Affected Products : android- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2013-3248
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.... Read more
Affected Products : pdf_fusion- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0517
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.... Read more
Affected Products : winlog_pro- Published: Jan. 20, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-3599
userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html.... Read more
Affected Products : coursemill_learning_management_system- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on ... Read more
Affected Products : tika- Published: Apr. 25, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2020-13540
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via WIN-911 Account Change Utility. Depending on the vector chosen, an attacker can overwrite various executa... Read more
- Published: Jan. 05, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-0797
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.... Read more
Affected Products : android- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0806
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-6467
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.... Read more
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-0855
Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Lossless Audio Codec (ALAC) data, which triggers an out-of-... Read more
Affected Products : ffmpeg- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-6620
libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.... Read more
Affected Products : android- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2019-1988
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. ... Read more
Affected Products : android- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1567
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreat... Read more
Affected Products : uploader_activex_control- Published: Dec. 03, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-5554
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot,... Read more
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8479
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-7162
Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.... Read more
Affected Products : hero_super_player_3000- Published: Sep. 04, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-6033
Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.... Read more
Affected Products : iq_panel- Published: Oct. 31, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2018-15418
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more
- Published: Oct. 05, 2018
- Modified: Nov. 21, 2024