Latest CVE Feed
-
9.3
HIGHCVE-2011-4141
Untrusted search path vulnerability in EMC RSA SecurID Software Token 4.1 before 4.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a Software Token file.... Read more
Affected Products : securid- Published: Dec. 17, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-3691
Untrusted search path vulnerability in Foxit Reader before 5.0.2.0718 allows local users to gain privileges via a Trojan horse dwmapi.dll, dwrite.dll, or msdrm.dll in the current working directory.... Read more
- Published: Sep. 27, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-3397
The Microsoft Time component in DATIME.DLL in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted web site that leverages an unspecified "binary behavior" in Internet Explorer, aka "Microsof... Read more
- Published: Dec. 14, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-2086
Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.ho... Read more
- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-2426
Stack-based buffer overflow in the ActionScript Virtual Machine (AVM) component in Adobe Flash Player before 10.3.183.10 on Windows, Mac OS X, Linux, and Solaris, and before 10.3.186.7 on Android, allows remote attackers to execute arbitrary code via unsp... Read more
- Published: Sep. 22, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2101
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X do not properly restrict script, which allows attackers to execute arbitrary code via a crafted document, related to a "cross document script execution... Read more
- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-1991
Multiple untrusted search path vulnerabilities in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allow local users to gain privileges via a Trojan horse DLL... Read more
Affected Products : windows_7 windows_server_2008 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Sep. 15, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-1388
The Blueberry FlashBack ActiveX control in BB FlashBack Recorder.dll in Blueberry BB FlashBack, as used in IBM Rational Rhapsody before 7.6.1 and other products, does not properly implement the TestCompatibilityRecordMode method, which allows remote attac... Read more
- Published: Dec. 23, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0563
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than ... Read more
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0475
Use-after-free vulnerability in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a PDF document.... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0170
Heap-based buffer overflow in ImageIO in CoreGraphics in Apple iTunes before 10.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted International Color Consortium (ICC) profile in a... Read more
- Published: Mar. 03, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-0852
The parse_picture_segment function in libavcodec/pgssubdec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted RLE data, which triggers an out-of-bounds array access.... Read more
Affected Products : ffmpeg- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-5082
Untrusted search path vulnerability in colorcpl.exe 6.0.6000.16386 in the Color Control Panel in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges via a Trojan horse sti.dll file in the current working directory, as d... Read more
Affected Products : windows_server_2008- Published: Jan. 17, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3954
Microsoft Publisher 2002 SP3, 2003 SP3, and 2010 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Publisher file, aka "Microsoft Publisher Memory Corruption Vulnerability."... Read more
Affected Products : publisher- Published: Dec. 16, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3630
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors.... Read more
- Published: Oct. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3629
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to execute arbitrary code via a crafted image, a different vulnerability than CVE-2010-3620.... Read more
- Published: Oct. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3214
Stack-based buffer overflow in Microsoft Word 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Word Viewer; Offic... Read more
Affected Products : office word word_viewer office_web_apps open_xml_file_format_converter office_compatibility_pack word_web_app- Published: Oct. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3174
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.14, Thunderbird before 3.0.9, and SeaMonkey before 2.0.9 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute... Read more
- Published: Oct. 21, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2017-18641
In LXC 2.0, many template scripts download code over cleartext HTTP, and omit a digital-signature check, before running it to bootstrap containers.... Read more
Affected Products : lxc- Published: Feb. 10, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-2882
DIRAPI.dll in Adobe Shockwave Player before 11.5.8.612 does not properly parse .dir files, which allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via a malformed file containing an invalid value, as demons... Read more
Affected Products : shockwave_player- Published: Aug. 26, 2010
- Modified: Apr. 11, 2025