Latest CVE Feed
-
9.3
HIGHCVE-2021-0481
In onActivityResult of EditUserPhotoController.java, there is a possible access of unauthorized files due to an unexpected URI handler. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ne... Read more
Affected Products : android- Published: Jun. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-8306
Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers t... Read more
- Published: Jan. 12, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7861
Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 windows_server_2016 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player +4 more products- Published: Nov. 08, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7855
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player mac_os_x +2 more products- Actively Exploited
- Published: Nov. 01, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8042
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.... Read more
Affected Products : android linux_kernel flash_player mac_os_x iphone_os windows air air_sdk air_sdk_\&_compiler- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7273
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Remote Code Execution Vulnerability."... Read more
- Published: Dec. 20, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7231
Microsoft Excel 2007 SP3, Excel for Mac 2011, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7184
The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8024
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) 9.3.x before 9.3.2MR19, 9.4.x before 9.4.2MR9, and 9.5.x before 9.5.0MR8, when configured to use Active Directory ... Read more
Affected Products : mcafee_enterprise_security_manager- Published: Dec. 02, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7923
Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.... Read more
Affected Products : weos- Published: Jan. 30, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4750
S2 Camera in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4698
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2021-0340
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed... Read more
Affected Products : android- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-4276
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2021-0339
In loadAnimation of WindowContainer.java, there is a possible way to keep displaying a malicious app while a target app is brought to the foreground. This could lead to local escalation of privilege with no additional execution privileges needed. User int... Read more
Affected Products : android- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-4177
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via unspecified vectors, a ... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Jul. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4156
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs list... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation macos flash_player_desktop_runtime +6 more products- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2021-0325
In ih264d_parse_pslice of ih264d_parse_pslice.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Pr... Read more
Affected Products : android- Published: Feb. 10, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0851
Microsoft Office 2007 SP2, Microsoft Office Word Viewer, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1 and RT SP1, Microsoft Office 2016, and Microsoft Office 2016 Click-to-Run (C2R) allow a remote code execution vulnerability, due to how Office ha... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-7754
Juniper ScreenOS before 6.3.0r21, when ssh-pka is configured and enabled, allows remote attackers to cause a denial of service (system crash) or execute arbitrary code via crafted SSH negotiation.... Read more
Affected Products : screenos- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025