Latest CVE Feed
-
9.3
HIGHCVE-2016-10576
Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attac... Read more
Affected Products : fuseki- Published: Jun. 01, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-27058
Microsoft Office ClickToRun Remote Code Execution Vulnerability... Read more
Affected Products : 365_apps- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10566
install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swappi... Read more
Affected Products : install-nw- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10636
grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an atta... Read more
Affected Products : grunt-ccompiler- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10590
cue-sdk-node is a Corsair Cue SDK wrapper for node.js. cue-sdk-node downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested zip file with an at... Read more
Affected Products : cue-sdk-node- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9715
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Aug. 19, 2020
- Modified: May. 05, 2025
-
9.3
HIGHCVE-2020-9569
Adobe Bridge versions 10.0.1 and earlier version have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Jun. 26, 2020
- Modified: May. 05, 2025
-
9.3
HIGHCVE-2016-10432
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 410/12, SD 425, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 820, and SD 820A, TOCTOU vulnerabilities may occur while sanitizing users... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_410_firmware sd_412_firmware sd_425_firmware sd_430_firmware sd_650_firmware sd_652_firmware +12 more products- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10409
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile and Snapdragon Mobile SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 820A, and SD 835, TOCTOU vulnerability may occur while composing the RPMB request us... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sd_425_firmware sd_430_firmware sd_650_firmware sd_652_firmware sd_425 +8 more products- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10402
Avira Antivirus engine versions before 8.3.36.60 allow remote code execution as NT AUTHORITY\SYSTEM via a section header with a very large relative virtual address in a PE file, causing an integer overflow and heap-based buffer underflow.... Read more
Affected Products : antivirus- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10417
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware mdm9650_firmware msm8909w_firmware sdx20_firmware ipq4019_firmware mdm9206_firmware mdm9607_firmware +54 more products- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-3904
Multiple memory corruption issues were addressed with improved state management. This issue is fixed in macOS Catalina 10.15.4. A malicious application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-3827
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. Viewing a maliciously crafted JPEG file may lead to arbitrary code execution.... Read more
- Published: Feb. 27, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10389
In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10342
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a syscall handler.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2020-3573
Multiple vulnerabilities in Cisco Webex Network Recording Player for Windows and Cisco Webex Player for Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elem... Read more
- Published: Nov. 06, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10338
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10320
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.... Read more
Affected Products : textract- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10340
In all Android releases from CAF using the Linux kernel, an integer underflow leading to buffer overflow vulnerability exists in a syscall handler.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10274
An elevation of privilege vulnerability in the MediaTek touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent d... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025