Latest CVE Feed
-
9.3
HIGHCVE-2020-15529
An issue was discovered in GOG Galaxy Client 2.0.17. Local escalation of privileges is possible when a user installs a game or performs a verify/repair operation. The issue exists because of weak file permissions and can be exploited by using opportunisti... Read more
Affected Products : galaxy- EPSS Score: %0.08
- Published: Jul. 05, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-6761
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to ... Read more
- EPSS Score: %0.15
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8234
In all Android releases from CAF using the Linux kernel, an out of bounds access can potentially occur in a camera function.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8253
In all Qualcomm products with Android releases from CAF using the Linux kernel, kernel memory can potentially be overwritten if an invalid master is sent from userspace.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
CRITICALCVE-2021-43052
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains an easily exploitable vulnerability that allows authentication bypass due to a hard coded secret ... Read more
Affected Products : ftl- EPSS Score: %0.22
- Published: Jan. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-5288
Multiple buffer overflows in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allow remote attackers to execute arbitrary code via a long argument to the (1) cmdExport, (2) cmdImport, (3) cmdOpen, or (4) cmd... Read more
Affected Products : threedify_designer- EPSS Score: %13.24
- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2023-6038
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installati... Read more
Affected Products : h2o- EPSS Score: %57.45
- Published: Nov. 16, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-8204
The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has t... Read more
- EPSS Score: %0.17
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
CRITICALCVE-2024-1485
A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archiv... Read more
- EPSS Score: %0.81
- Published: Feb. 14, 2024
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-17110
HEVC Video Extensions Remote Code Execution Vulnerability... Read more
Affected Products : hevc_video_extensions- EPSS Score: %8.06
- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-7074
Format string vulnerability in MemeCode Software i.Scribe 1.88 through 2.00 before Beta9 allows remote SMTP servers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a server response, which is not pr... Read more
Affected Products : i.scribe- EPSS Score: %9.12
- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-7079
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long entry in a .M3U playlist file. NOTE: this issue might be related to CVE-2008-0619.... Read more
Affected Products : showtime- EPSS Score: %8.46
- Published: Aug. 25, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-0543
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- EPSS Score: %0.29
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2009-0885
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in a (1) M3U, (2) M3l, (3) TXT, and (4) LRC playlist file.... Read more
Affected Products : media_commands- EPSS Score: %35.59
- Published: Mar. 12, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-0833
A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62896384.... Read more
Affected Products : android- EPSS Score: %0.96
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
CRITICALCVE-2019-6741
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to January 2019 Security Update (SMR-JAN-2019 - SVE-2018-13467). User interaction is required to exploit this vulnerability in that... Read more
- EPSS Score: %1.15
- Published: Jun. 03, 2019
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-33257
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.... Read more
Affected Products : aqt1000_firmware qam8295p_firmware qca6390_firmware qca6391_firmware qca6420_firmware qca6426_firmware qca6430_firmware qca6436_firmware qca6574au_firmware qca6595au_firmware +270 more products- EPSS Score: %0.04
- Published: Mar. 10, 2023
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-25331
DIR-822 Rev. B Firmware v2.02KRB09 and DIR-822-CA Rev. B Firmware v2.03WWb01 suffer from a LAN-Side Unauthenticated Remote Code Execution (RCE) vulnerability elevated from HNAP Stack-Based Buffer Overflow.... Read more
Affected Products :- Published: Mar. 12, 2024
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-0990
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.... Read more
- EPSS Score: %0.27
- Published: Apr. 04, 2022
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-55978
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WalletStation.com Code Generator Pro allows SQL Injection.This issue affects Code Generator Pro: from n/a through 1.2.... Read more
Affected Products :- Published: Dec. 16, 2024
- Modified: Dec. 16, 2024