Latest CVE Feed
-
9.3
HIGHCVE-2006-0884
The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in... Read more
Affected Products : thunderbird- Published: Feb. 24, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0010
Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open... Read more
Affected Products : windows_2000 windows_2003_server windows_xp windows_98 windows_nt windows_98se windows_me- Published: Jan. 10, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-2780
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via "jsstr tagify," which leads to memory corruption.... Read more
- Published: Jun. 02, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2006-0033
Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via a crafted PNG image that triggers memory corruption when it is parsed.... Read more
Affected Products : office- Published: Jul. 11, 2006
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2004-1029
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict access between Javascript and Java applets during data transfer, which allows remote attackers to load unsafe ... Read more
Affected Products : hp-ux jre enterprise_firewall gateway_security_5400 jdk linux linux java_sdk-rte- Published: Mar. 01, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2001-0537
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when local authorization is being used, by specifying a high access level in the URL.... Read more
Affected Products : ios- Published: Jul. 21, 2001
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2018-1000118
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their ... Read more
Affected Products : electron- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0861
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0920
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-... Read more
Affected Products : excel- Published: Apr. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0834
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". Th... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0798
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerabil... Read more
- Actively Exploited
- Published: Jan. 10, 2018
- Modified: Mar. 26, 2025
-
9.3
HIGHCVE-2018-0849
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote ... Read more
- Published: Jan. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0797
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".... Read more
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0796
Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnera... Read more
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0858
ChakraCore allows remote code execution, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2018-0835, CVE-2018-0836, CVE-2018-0837, C... Read more
Affected Products : chakracore- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0848
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote ... Read more
- Published: Jan. 22, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0794
Microsoft Word in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerabi... Read more
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0792
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.... Read more
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0804
Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote ... Read more
- Published: Jan. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0598
Untrusted search path vulnerability in Self-extracting archive files created by IExpress bundled with Microsoft Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : windows- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024