Latest CVE Feed
-
9.3
HIGHCVE-2020-6517
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-6518
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.... Read more
- Published: Jul. 22, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-4674
The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer files that are retrieved without use of SSL, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : timedoctor- Published: Aug. 07, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-4496
Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-4493
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk ... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2007-5400
Heap-based buffer overflow in the Shockwave Flash (SWF) frame handling in RealNetworks RealPlayer 10.5 Build 6.0.12.1483 might allow remote attackers to execute arbitrary code via a crafted SWF file.... Read more
- Published: Jul. 28, 2008
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2015-4523
Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory d... Read more
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2011-0611
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; Adobe AIR before 2.6.19140; and Authplay.dll (aka AuthPlayLib.bundle) in Adobe Reader 9.x before 9.4.4 and 10.x through 10.0.1 on Window... Read more
Affected Products : android linux_kernel chrome flash_player mac_os_x opensuse solaris linux_enterprise_desktop chrome_os acrobat +5 more products- Actively Exploited
- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2099
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-... Read more
- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2007-5760
Array index error in the XFree86-Misc extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via a PassMessage request containing a large array index.... Read more
- Published: Jan. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-6015
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logons" option is enabled, allows remote attackers to execute arbitrary code via a GETDC mailslot request composed of a long GETDC string fo... Read more
Affected Products : samba- Published: Dec. 13, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-6402
Stack-based buffer overflow in mplayerc.exe in Media Player Classic (MPC) 6.4.9, when used with the 3ivx 4.5.1 or 5.0.1 codec, allows remote attackers to execute arbitrary code via a certain .mp4 file, possibly a related issue to CVE-2007-6401.... Read more
- Published: Dec. 17, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2011-2867
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CV... Read more
- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-2883
The NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 attempts to validate signed DLLs by checking the certificate subject, not the signature, which... Read more
Affected Products : access_gateway- Published: Jul. 21, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-4451
Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass JavaScript ... Read more
- Published: Jul. 15, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-3508
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect confidentiality, integrity, and availability, related to LDAP library.... Read more
- Published: Oct. 18, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-3504
The Matroska format decoder in FFmpeg before 0.8.3 does not properly allocate memory, which allows remote attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : ffmpeg- Published: Sep. 29, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2008-0726
Integer overflow in Adobe Reader and Acrobat 8.1.1 and earlier allows remote attackers to execute arbitrary code via crafted arguments to the printSepsWithParams, which triggers memory corruption.... Read more
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-0956
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInstActivator.dll in BackWeb before 8.1.1.87, as used in Logitech Desktop Manager (LDM) before 2.56, allow remote att... Read more
- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1195
Unspecified vulnerability in Sun JDK and Java Runtime Environment (JRE) 6 Update 4 and earlier and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier; allows remote attackers to access arbitrary network services on the local host via unspecif... Read more
- Published: Mar. 06, 2008
- Modified: Apr. 09, 2025