Latest CVE Feed
-
9.3
HIGHCVE-2007-0879
Buffer overflow in SmidgeonSoft PEBrowse Professional 8.2.1.0 allows user-assisted remote attackers to execute arbitrary code via certain executable files in PE format. NOTE: the provenance of this information is unknown; the details are obtained solely ... Read more
Affected Products : pebrowse- EPSS Score: %4.14
- Published: Feb. 12, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1784
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.... Read more
- EPSS Score: %3.71
- Published: Mar. 31, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2004-1875
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) ... Read more
Affected Products : cpanel- EPSS Score: %15.32
- Published: Mar. 30, 2004
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2007-3924
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Netscape installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metac... Read more
- EPSS Score: %7.82
- Published: Jul. 21, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5213
Multiple cross-site request forgery (CSRF) vulnerabilities in the AXIS 2100 Network Camera 2.02 with firmware 2.43 and earlier allow remote attackers to perform actions as administrators, as demonstrated by (1) an SMTP server change through the conf_SMTP_... Read more
- EPSS Score: %0.75
- Published: Oct. 04, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-5687
Multiple buffer overflows in the rich text processing functionality in JustSystems Ichitaro 2004 through 2007, 11 through 13, and other versions allow remote attackers to execute arbitrary code via a long (1) pard field or (2) font name in the fcharset0 f... Read more
- EPSS Score: %17.53
- Published: Oct. 28, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-6254
Stack-based buffer overflow in the SAP Business Objects BusinessObjects RptViewerAX ActiveX control in RptViewerAX.dll in Business Objects 6.5 before CHF74 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %20.11
- Published: Mar. 20, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-6278
Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the FLAC image file in a crafted .FLAC file.... Read more
Affected Products : libflac- EPSS Score: %1.14
- Published: Dec. 07, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3595
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter.... Read more
Affected Products : txtsql- EPSS Score: %1.21
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5696
Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations.... Read more
- EPSS Score: %2.49
- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-0228
Cross-site request forgery (CSRF) vulnerability in apply.cgi in the Linksys WRT54GL Wireless-G Broadband Router with firmware 4.30.9 allows remote attackers to perform actions as administrators.... Read more
- EPSS Score: %1.15
- Published: Jan. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-4005
Cross-site request forgery (CSRF) vulnerability in the Services Ready Platform Configuration Utility web interface on the Cisco Small Business SRP521W, SRP526W, and SRP527W with firmware before 1.1.24 and the Small Business SRP541W, SRP546W, and SRP547W w... Read more
- EPSS Score: %0.22
- Published: Nov. 03, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-4030
The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publishable, which allows remote attackers to access sub-objects via unspecified vectors, a different vulnerabili... Read more
- EPSS Score: %1.07
- Published: Oct. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-1093
Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan hor... Read more
- EPSS Score: %0.85
- Published: Sep. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1259
The Zyxel P-2602HW-D1A router with 3.40(AJZ.1) firmware maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a user who previously authenticated within t... Read more
Affected Products : p-2602hw-d1a- EPSS Score: %0.27
- Published: Mar. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2016-10570
pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requeste... Read more
Affected Products : pngcrush-installer- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10589
selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested bi... Read more
Affected Products : selenium-binaries- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10583
closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary wit... Read more
- EPSS Score: %1.64
- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2013-7136
The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.... Read more
Affected Products : ireland_cisco_epc2425- EPSS Score: %14.36
- Published: Dec. 19, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2014-1202
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.... Read more
- EPSS Score: %19.60
- Published: Jan. 25, 2014
- Modified: Apr. 11, 2025