Latest CVE Feed
-
10.0
HIGHCVE-2018-6000
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch a... Read more
Affected Products : asuswrt- EPSS Score: %90.65
- Published: Jan. 22, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-1636
Heap-based buffer overflow in the WvTFTPServer::new_connection function in wvtftpserver.cc for WvTftp 0.9 allows remote attackers to execute arbitrary code via a long option string in a TFTP packet.... Read more
Affected Products : wvtftp- EPSS Score: %6.82
- Published: Oct. 26, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-6577
Nortel MG1000S, Signaling Server, and Call Server on the Communications Server 1000 (CS1K) 4.50.x contain multiple unspecified hard-coded accounts and passwords, which allows remote attackers to gain privileges.... Read more
Affected Products : cs1000- EPSS Score: %2.28
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-6578
Multiple unspecified vulnerabilities in Nortel Communication Server 1000 4.50.x allow remote attackers to execute arbitrary commands to gain privileges, obtain sensitive information, or cause a denial of service via unknown vectors.... Read more
Affected Products : cs1000- EPSS Score: %2.18
- Published: Apr. 01, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-19067
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~... Read more
Affected Products : c2 i5_application_firmware i5_system_firmware c2_application_firmware c2_system_firmware i5- EPSS Score: %1.22
- Published: Nov. 07, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-7493
CactusVPN through 6.0 for macOS suffers from a root privilege escalation vulnerability in its privileged helper tool. The privileged helper tool implements an XPC interface, which allows arbitrary applications to execute system commands as root.... Read more
- EPSS Score: %0.36
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-7573
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with the FTP 220 response code to crash the application; after this overflow, one can run arbitrary code on the victim machine. This is simil... Read more
Affected Products : ftpshell_client- EPSS Score: %78.38
- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-5864
These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.... Read more
- EPSS Score: %15.42
- Published: Nov. 23, 2012
- Modified: Jul. 08, 2025
-
10.0
HIGHCVE-2018-7716
PrivateVPN 2.0.31 for macOS suffers from a root privilege escalation vulnerability with its com.privat.vpn.helper privileged helper tool. This privileged helper tool implements an XPC service that allows arbitrary installed applications to connect and sen... Read more
Affected Products : privatevpn- EPSS Score: %0.73
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-7232
Buffer overflow in the report function in xtacacsd 4.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted CONNECT TACACS command.... Read more
Affected Products : xtacacsd- EPSS Score: %55.75
- Published: Sep. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2018-1000651
Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially cr... Read more
Affected Products : stroom- EPSS Score: %0.24
- Published: Aug. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-0210
Buffer overflow in the MLF application in AREVA e-terrahabitat 5.7 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service (system crash) via unspecified vectors, aka PD28578.... Read more
Affected Products : e-terrahabitat- EPSS Score: %2.46
- Published: Feb. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-9143
On Samsung mobile devices with M(6.0) and N(7.x) software, a heap overflow in the sensorhub binder service leads to code execution in a privileged process, aka SVE-2017-10991.... Read more
Affected Products : samsung_mobile- EPSS Score: %1.13
- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-0595
Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 has a default password for the administrative... Read more
- EPSS Score: %2.44
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-0410
Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a... Read more
Affected Products : groupwise- EPSS Score: %17.50
- Published: Feb. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2017-6714
A vulnerability in the AutoIT service of Cisco Ultra Services Framework Staging Server could allow an unauthenticated, remote attacker to execute arbitrary shell commands as the Linux root user. The vulnerability is due to improper shell invocations. An a... Read more
Affected Products : ultra_services_framework_staging_server- EPSS Score: %1.90
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2010-0998
Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI,... Read more
Affected Products : free_download_manager- EPSS Score: %20.07
- Published: May. 17, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-11629
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision... Read more
Affected Products : stanza_firmware radiora_2_firmware homeworks_qs_firmware stanza radiora_2 homeworks_qs- EPSS Score: %2.26
- Published: Jun. 02, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-7637
QNAP NAS application Proxy Server through version 1.2.0 allows remote attackers to run arbitrary OS commands against the system with root privileges.... Read more
Affected Products : nas_proxy_server- EPSS Score: %3.42
- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-10586
Filling media attribute tag names without validating the destination buffer size which can result in the buffer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdra... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware msm8996au_firmware apq8096au_firmware mdm9150_firmware qcs605_firmware sdx24_firmware apq8009_firmware mdm9650_firmware +96 more products- EPSS Score: %0.36
- Published: Mar. 05, 2020
- Modified: Nov. 21, 2024