Latest CVE Feed
-
9.3
HIGHCVE-2020-9928
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-7289
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have a hardcoded administrator password derived from a serial number, which makes it easier for remote attackers to obtain access via the web management inte... Read more
- Published: Nov. 21, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7283
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.... Read more
- Published: Dec. 31, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3331
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (... Read more
- Published: May. 27, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2735
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.... Read more
- Published: Jul. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2545
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Microsoft Office Malformed EPS File Vulnerability."... Read more
Affected Products : office- Actively Exploited
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2541
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2485 and CVE... Read more
Affected Products : internet_explorer- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2443
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- Published: Aug. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2020-9830
A memory corruption issue was addressed with improved state management. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5. An application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-1696
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows ... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-1675
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows ... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_8 windows_rt- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2020-9790
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. Pr... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9815
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9791
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Catalina 10.15.5, tvOS 13.4.5, watchOS 6.2.5. Processing a maliciously crafted audio file may lead to arbitrary code execution.... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9746
Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious string... Read more
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9722
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9693
Adobe Acrobat and Reader versions 2020.009.20074 and earlier, 2020.001.30002, 2017.011.30171 and earlier, and 2015.006.30523 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Aug. 19, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-0067
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-0063
Microsoft Excel 2007 SP3; the proofing tools in Office 2010 SP2; Excel 2010 SP2; Excel 2013 Gold, SP1, and RT; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption... Read more
- Published: Feb. 11, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-7112
The IOHIDFamily API in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vu... Read more
- Published: Dec. 11, 2015
- Modified: Apr. 12, 2025