Latest CVE Feed
-
9.3
HIGHCVE-2005-3693
The AxWebRemoveCtrl ActiveX control for uninstalling the SunnComm MediaMax DRM allows remote attackers to download and execute arbitrary code, a similar vulnerability to CVE-2005-3650.... Read more
Affected Products : axwebremovectrl- Published: Nov. 19, 2005
- Modified: Apr. 03, 2025
-
9.3
HIGHCVE-2014-3524
Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.... Read more
- Published: Aug. 26, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-4380
The IOHIDFamily kernel extension in Apple iOS before 8 and Apple TV before 7 lacks proper bounds checking on write operations, which allows attackers to execute arbitrary code in the kernel's context via a crafted application.... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-6930
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7629
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "kext tools" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via ... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0089
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different ... Read more
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0104
The iSNS Server service in Microsoft Windows Server 2008 SP2 and R2, Windows Server 2012 Gold and R2, and Windows Server 2016 allows remote attackers to issue malicious requests via an integer overflow, aka "iSNS Server Memory Corruption Vulnerability."... Read more
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-3074
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the firs... Read more
- Published: Feb. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2020-5922
In BIG-IP versions 15.0.0-15.1.0.4, 14.1.0-14.1.2.6, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.2, iControl REST does not implement Cross Site Request Forgery protections for users which make use of Basic Authentication in a web browser.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_fraud_protection_service big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager +4 more products- Published: Aug. 26, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-1089
Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."... Read more
- Published: Apr. 08, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1701
Use-after-free vulnerability in the JavaScript DOM implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of serv... Read more
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-6152
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162... Read more
Affected Products : windows_7 windows_server_2008 windows_server_2012 internet_explorer windows_8 windows_rt- Published: Dec. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3842
Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.... Read more
Affected Products : android- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3849
The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return values of certain read operations, which allows attackers to execute arbitrary code via an application that sen... Read more
Affected Products : android- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3865
The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23050463.... Read more
Affected Products : android- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3799
The Apple ID OD plug-in in Apple OS X before 10.10.5 allows attackers to change arbitrary user passwords via a crafted app.... Read more
- Published: Aug. 17, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3843
The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM commands via an application that sends a crafted Intent, related to com/android/internal/telephony/cat/AppInterfa... Read more
Affected Products : android- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-3768
Integer overflow in the kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to execute arbitrary code in a privileged context via a crafted app that makes unspecified IOKit API calls.... Read more
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2012-1889
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.... Read more
Affected Products : windows_7 windows_server_2008 windows_server_2012 office sharepoint_server windows_server_2003 windows_vista windows_xp office_word_viewer office_compatibility_pack +5 more products- Actively Exploited
- Published: Jun. 13, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-1875
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_server_2003 windows_vista windows_xp- Published: Jun. 12, 2012
- Modified: Apr. 11, 2025