Latest CVE Feed
-
10.0
HIGHCVE-2013-7404
GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system... Read more
- EPSS Score: %0.57
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2003-1503
Buffer overflow in AOL Instant Messenger (AIM) 5.2.3292 allows remote attackers to execute arbitrary code via an aim:getfile URL with a long screen name.... Read more
Affected Products : instant_messenger- EPSS Score: %6.26
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1509
Real Networks RealOne Enterprise Desktop 6.0.11.774, RealOne Player 2.0, and RealOne Player 6.0.11.818 through RealOne Player 6.0.11.853 allows remote attackers to execute arbitrary script in the local security zone by embedding script in a temp file befo... Read more
- EPSS Score: %0.72
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3461
Unspecified vulnerability in PeopleTools in Oracle PeopleSoft Enterprise 8.42 up to 8.45.17 has unknown impact and attack vectors, as identified by Oracle Vuln# PSE01.... Read more
Affected Products : peoplesoft_enterprise- EPSS Score: %1.72
- Published: Nov. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2014-10050
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MSM8996, MSM8939, MSM8976, MSM8917, SDM845, and SDM660, access control collision vulnerability when accessing the replay protected memory block.... Read more
Affected Products : android sdm660_firmware msm8976_firmware sdm845_firmware msm8917_firmware msm8996_firmware msm8939_firmware msm8917 msm8976 msm8939 +3 more products- EPSS Score: %0.18
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-1849
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifyi... Read more
Affected Products : ip_camera_firmware- EPSS Score: %24.33
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0405
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesti... Read more
- EPSS Score: %1.26
- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-4898
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.... Read more
Affected Products : novabackup_datacenter- EPSS Score: %4.48
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-5080
Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow), on a system running ... Read more
Affected Products : asn1c- EPSS Score: %40.64
- Published: Jul. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0550
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.... Read more
Affected Products : steamcast- EPSS Score: %68.16
- Published: Feb. 01, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0315
Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.... Read more
Affected Products : voice- EPSS Score: %3.18
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0338
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.... Read more
Affected Products : invision_board- EPSS Score: %0.42
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0377
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.... Read more
- EPSS Score: %10.19
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3957
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.... Read more
Affected Products : dotclear- EPSS Score: %0.45
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-0647
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the... Read more
- EPSS Score: %7.15
- Published: Feb. 07, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6536
The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a handle parameter value.... Read more
- EPSS Score: %0.80
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6598
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. ... Read more
Affected Products : track-it\!- EPSS Score: %36.87
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-7112
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more
- EPSS Score: %0.52
- Published: Sep. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0735
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.... Read more
Affected Products : auracms- EPSS Score: %0.35
- Published: Feb. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0636
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.... Read more
Affected Products : instant_messenger- EPSS Score: %78.52
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025