Latest CVE Feed
-
9.3
HIGHCVE-2014-1817
usp10.dll in Uniscribe (aka the Unicode Script Processor) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office ... Read more
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-2098
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-... Read more
- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2095
Buffer overflow in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2011-2094 and CVE-2011-2097.... Read more
- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-1989
Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word,... Read more
- Published: Sep. 15, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0694
RealNetworks RealPlayer 11.0 through 11.1, SP 1.0 through 1.1.5, and 14.0.0 through 14.0.1, and Enterprise 2.0 through 2.1.4, uses predictable names for temporary files, which allows remote attackers to conduct cross-domain scripting attacks and execute a... Read more
- Published: Feb. 21, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0663
Multiple integer overflows in the Microsoft (1) JScript 5.6 through 5.8 and (2) VBScript 5.6 through 5.8 scripting engines allow remote attackers to execute arbitrary code via a crafted web page, aka "Scripting Memory Reallocation Vulnerability."... Read more
Affected Products : windows_7 windows_server_2008 windows_2003_server windows_server_2003 windows_vista windows_xp vbscript jscript- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0608
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-... Read more
Affected Products : flash_player- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0606
Stack-based buffer overflow in rt3d.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via un... Read more
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0591
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, relate... Read more
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0323
Topaz Systems SigPlus Pro ActiveX Control 3.95, and possibly other versions before 4.29, allows remote attackers to execute arbitrary code by calling the exposed unsafe (1) SetLogFilePath and (2) SigMessage methods to create arbitrary files with arbitrary... Read more
Affected Products : sigplus_pro_activex_control- Published: Feb. 07, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0238
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0235
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE... Read more
- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-4587
Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assisted remote attackers to have an unspecified impact via a crafted module.... Read more
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-4397
Integer overflow in the pnen3260.dll module in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.1, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 allows remote attackers to execute arbitrary code via a crafted T... Read more
- Published: Dec. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3962
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code via vectors related to Cascading Style Sheets (CSS) token sequences and the clip attribute, aka an "invalid flag reference" issue or ... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Nov. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3821
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, does not properly handle the :first-letter pseudo-element in a Cascading Style Sheets (CSS) token sequence, which allows remote attackers to ... Read more
- Published: Nov. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3805
Integer underflow in WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving... Read more
- Published: Nov. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3653
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a Director movie with a crafted rcsL chunk containing a field whose value i... Read more
Affected Products : shockwave_player- Published: Oct. 26, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3145
Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Microsoft Windows Vista SP1 and SP2, allows local users to gain privileges via a Trojan horse fveapi.dll file in the current working direc... Read more
Affected Products : windows_vista- Published: Aug. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-2997
Use-after-free vulnerability in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.0.1, Mac RealPlayer 11.0 through 11.1, Linux RealPlayer 11.0.2.1744, and possibly HelixPlayer 1.0.6 and other versions, allows remote attackers to execu... Read more
- Published: Dec. 14, 2010
- Modified: Apr. 11, 2025