Latest CVE Feed
-
10.0
HIGHCVE-2014-1849
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifyi... Read more
Affected Products : ip_camera_firmware- EPSS Score: %20.85
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0405
Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesti... Read more
- EPSS Score: %1.26
- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-4898
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.... Read more
Affected Products : novabackup_datacenter- EPSS Score: %4.48
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-5080
Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow), on a system running ... Read more
Affected Products : asn1c- EPSS Score: %40.64
- Published: Jul. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0550
Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.... Read more
Affected Products : steamcast- EPSS Score: %68.16
- Published: Feb. 01, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0315
Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.... Read more
Affected Products : voice- EPSS Score: %3.18
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0338
SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.... Read more
Affected Products : invision_board- EPSS Score: %0.42
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0377
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.... Read more
- EPSS Score: %10.19
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-3957
Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.... Read more
Affected Products : dotclear- EPSS Score: %0.45
- Published: Dec. 01, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-0647
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the... Read more
- EPSS Score: %7.15
- Published: Feb. 07, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6536
The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a handle parameter value.... Read more
- EPSS Score: %0.80
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6598
BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. ... Read more
Affected Products : track-it\!- EPSS Score: %36.87
- Published: Jan. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-7112
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more
- EPSS Score: %0.52
- Published: Sep. 06, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0735
SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.... Read more
Affected Products : auracms- EPSS Score: %0.35
- Published: Feb. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0636
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.... Read more
Affected Products : instant_messenger- EPSS Score: %78.52
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2015-1845
Buffer overflow in the EntrReadArch function in unzoo might allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : unzoo- EPSS Score: %10.96
- Published: May. 19, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-8364
An issue was discovered in IBHsoftec S7-SoftPLC prior to 4.12b. Object memory can read a network packet that is larger than the space that is available, a Heap-based Buffer Overflow.... Read more
Affected Products : s7-softplc- EPSS Score: %0.65
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8440
Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747.... Read more
- EPSS Score: %0.53
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-2767
Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."... Read more
Affected Products : triton_ap_email- EPSS Score: %0.38
- Published: Mar. 27, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-3116
Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.... Read more
- EPSS Score: %5.10
- Published: Jul. 10, 2008
- Modified: Apr. 09, 2025