Latest CVE Feed
-
9.3
HIGHCVE-2010-1402
Double free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors relat... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1396
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors re... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1285
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified manipulations involving the newclass (0x58) operator and an "invalid pointer vulnerability" that triggers me... Read more
- Published: Jun. 30, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1263
Windows Shell and WordPad in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; Microsoft Office XP SP3; Office 2003 SP3; and Office System 2007 SP1 and SP2 do not pr... Read more
Affected Products : office- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1260
The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka ... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2003_server windows_vista windows_xp ie- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1253
Microsoft Office Excel 2002 SP3, 2007 SP1, and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2; allows remote attackers to e... Read more
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0267
Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, a... Read more
- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0261
Heap-based buffer overflow in Microsoft Office Excel 2007 SP1 and SP2 and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted spreadsheet in which "a MDXSE... Read more
- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0103
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Arucer.dll file in the %WINDIR%\system32 directory, which allows remote attackers to download arbitrary programs onto a Windows PC, and ex... Read more
Affected Products : duo_usb- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0031
Array index error in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "PowerPoint OEPlaceholderAtom 'placementId' Invalid Arr... Read more
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4324
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib co... Read more
Affected Products : mac_os_x opensuse linux_enterprise acrobat acrobat_reader windows linux_enterprise_debuginfo- Actively Exploited
- Published: Dec. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4257
Heap-based buffer overflow in datatype/smil/common/smlpkt.cpp in smlrender.dll in RealNetworks RealPlayer 10, RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741, RealPlayer 11 11.0.0 through 11.0.4, RealPlayer Enterprise, Mac RealPlayer 10 and 10.1, Linux Re... Read more
- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3994
Stack-based buffer overflow in the GetUID function in src-IL/src/il_dicom.c in DevIL 1.7.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted DICOM file.... Read more
Affected Products : devil- Published: Dec. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3829
Integer overflow in wiretap/erf.c in Wireshark before 1.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted erf file, related to an "unsigned integer wrap vulnerability."... Read more
Affected Products : wireshark- Published: Oct. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3604
The Splash::drawImage function in Splash.cc in Xpdf 2.x and 3.x before 3.02pl4, and Poppler 0.x, as used in GPdf and kdegraphics KPDF, does not properly allocate memory, which allows remote attackers to cause a denial of service (application crash) or pos... Read more
- Published: Oct. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2986
Multiple heap-based buffer overflows in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 might allow attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Oct. 19, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2850
Multiple buffer overflows in NASA Common Data Format (CDF) allow context-dependent attackers to execute arbitrary code, as demonstrated using (1) an array index error in the ReadAEDRList64 function, and other errors in the (2) SearchForRecord_r_64, (3) La... Read more
Affected Products : common_data_format- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2555
Heap-based buffer overflow in src/jsregexp.cc in Google V8 before 1.1.10.14, as used in Google Chrome before 2.0.172.37, allows remote attackers to execute arbitrary code in the Chrome sandbox via a crafted JavaScript regular expression.... Read more
- Published: Jul. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2500
Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Of... Read more
Affected Products : windows_server_2008 office .net_framework excel_viewer word_viewer internet_explorer windows_2000 windows_2003_server windows_vista windows_xp +17 more products- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1865
Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerabil... Read more
- Published: Jul. 31, 2009
- Modified: Apr. 09, 2025