Latest CVE Feed
-
9.3
HIGHCVE-2008-3033
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php... Read more
Affected Products : rss_aggregator- EPSS Score: %1.86
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-3831
Buffer overflow in the readAt function in BpMediaHTTPConnection in media/libmedia/IMediaHTTPConnection.cpp in the mediaserver service in Android before 5.1.1 LMY48I allows attackers to execute arbitrary code via a crafted application, aka internal bug 194... Read more
Affected Products : android- EPSS Score: %0.46
- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-10338
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10681
roslib-socketio - The standard ROS Javascript Library fork for add support to socket.io roslib-socketio downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping o... Read more
Affected Products : roslibjs- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-4396
Multiple CRLF injection vulnerabilities in (1) ixmmsa.pl 0.3, (2) l33tmusic.pl 2.00, (3) mpg123.pl 0.01, (4) ogg123.pl 0.01, (5) xmms.pl 2.0, (6) xmms2.pl 1.1.3, and (7) xmmsinfo.pl 1.1.1.1 scripts for irssi before 0.8.11 allow user-assisted remote attack... Read more
Affected Products : irssi- EPSS Score: %1.65
- Published: Aug. 18, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2004-1441
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary web script or HTML via the action parameter.... Read more
Affected Products : board_power- EPSS Score: %3.30
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2008-3879
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open me... Read more
Affected Products : ultra_office_control- EPSS Score: %7.47
- Published: Sep. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3956
orgchart.exe in Microsoft Organization Chart 2.00 allows user-assisted attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted .opx file.... Read more
Affected Products : organization_chart- EPSS Score: %33.60
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3971
Heap-based buffer overflow in the open_man_file function in callbacks.c in gmanedit 0.4.1 allows remote attackers to execute arbitrary code via a crafted man page, which is not properly handled during utf8 conversion. NOTE: another overflow was reported ... Read more
Affected Products : gmanedit- EPSS Score: %4.25
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-5014
IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.... Read more
Affected Products : cognos_disclosure_management- EPSS Score: %0.47
- Published: Oct. 26, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2017-14743
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.... Read more
- EPSS Score: %0.45
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2009-2362
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.0.0.215 allows remote attackers to execute arbitrary code via a long string in a (1) .lst or (2) .m3u playlist file.... Read more
Affected Products : audioplus- EPSS Score: %24.34
- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2014-9962
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9964
In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2009-2617
Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.... Read more
Affected Products : storm- EPSS Score: %6.69
- Published: Jul. 27, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3176
Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professi... Read more
Affected Products : iprint- EPSS Score: %5.40
- Published: Sep. 11, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-6223
Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerabilities in the ping functionality that could allow local authenticated users to execute arbitrary privileg... Read more
- EPSS Score: %1.24
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-5175
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.... Read more
Affected Products : aceftp- EPSS Score: %1.60
- Published: Nov. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3691
Multiple integer overflows in setnet32.exe 3.50.0.13752 in IBM Informix Client SDK 3.0 and 3.50 and Informix Connect Runtime 3.x allow remote attackers to execute arbitrary code via a .nfx file with a crafted (1) HostSize, and possibly (2) ProtoSize and (... Read more
- EPSS Score: %20.48
- Published: Oct. 13, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-5534
ESET NOD32 Antivirus 3662 and possibly 3440, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1... Read more
- EPSS Score: %0.31
- Published: Dec. 12, 2008
- Modified: Apr. 09, 2025