Latest CVE Feed
-
9.3
HIGHCVE-2009-1869
Integer overflow in the ActionScript Virtual Machine 2 (AVM2) abcFile parser in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execu... Read more
- Published: Jul. 31, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-1920
The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a craft... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2024-34711
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to perform XML External Entities (XEE) attack, then send GET request to any HTTP ... Read more
- Published: Jun. 10, 2025
- Modified: Aug. 26, 2025
- Vuln Type: XML External Entity
-
9.3
HIGHCVE-2019-1352
A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.... Read more
- Published: Jan. 24, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-0840
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot... Read more
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2244
Microsoft Office Word 2002 SP3 allows remote attackers to execute arbitrary code via a .doc file that contains malformed data, as exploited in the wild in July 2008, and as demonstrated by attachement.doc.... Read more
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-2555
Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary cod... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-9950
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks... Read more
- Published: Dec. 17, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-3241
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-B... Read more
- Published: Oct. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-2520
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2510
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 SP3, Office 2010 SP2, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, Lync Basic 2013 SP1, and Live Meeting 2007 Console allows remote att... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2509
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2514
Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a cra... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2487
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2486, CVE-20... Read more
Affected Products : internet_explorer- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-3822
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, accesses an uninitialized pointer during processing of Cascading Style Sheets (CSS) counter styles, which allows remote attackers to execute ... Read more
- Published: Nov. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3384
Multiple unspecified vulnerabilities in WebKit in Apple Safari before 4.0.4 on Windows allow remote FTP servers to execute arbitrary code, cause a denial of service (application crash), or obtain sensitive information via a crafted directory listing in a ... Read more
- Published: Nov. 13, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-2502
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.... Read more
- Actively Exploited
- Published: Aug. 19, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-2486
Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE... Read more
- Published: Sep. 09, 2015
- Modified: Apr. 12, 2025
-
9.3
CRITICALCVE-2020-5260
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. Git uses external "credential helper" programs to store and retrieve passwords or other credentials from secure ... Read more
- Published: Apr. 14, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-3973
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, ... Read more
Affected Products : wmi_administrative_tools- Published: Dec. 23, 2010
- Modified: Apr. 11, 2025