Latest CVE Feed
-
9.3
HIGHCVE-2015-2482
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted repla... Read more
- Published: Oct. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-2819
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.... Read more
Affected Products : raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_sprint_wifi airlink_mp_telus +9 more products- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2717
Multiple unspecified vulnerabilities in the System Management (aka SysAdmin) Console in EMC Smarts Network Configuration Manager (NCM) through 9.2 have unknown impact and attack vectors, a different issue than CVE-2013-0935. NOTE: this might overlap CVEs... Read more
Affected Products : smarts_network_configuration_manager- Published: Mar. 28, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2803
ProSoft RadioLinx ControlScape before 6.00.040 uses a deficient PRNG algorithm and seeding strategy for passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.... Read more
Affected Products : radiolinx_controlscape- Published: Sep. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-1313
The nsTextFrame::ClearTextRun function in layout/generic/nsTextFrameThebes.cpp in Mozilla Firefox 3.0.9 allows remote attackers to cause a denial of service (memory corruption) and probably execute arbitrary code via unspecified vectors. NOTE: this vulne... Read more
Affected Products : firefox- Published: Apr. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-4708
Format string vulnerability in Address Book in Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via the URL handler.... Read more
- Published: Dec. 19, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2021-21052
Adobe Animate version 21.0.2 (and earlier) is affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issu... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-21053
Adobe Illustrator version 25.1 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current u... Read more
- Published: Feb. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-1202
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and ap... Read more
- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1208
Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related ... Read more
- Published: Jul. 30, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2642
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote authenticate... Read more
- Published: Mar. 18, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-1286
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1287, CVE-2010-1289, CVE-2010-129... Read more
Affected Products : windows_7 windows_server_2008 macos windows_server_2003 windows_vista windows shockwave_player- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-3452
Use-after-free vulnerability in oowriter in OpenOffice.org (OOo) 2.x and 3.x before 3.3 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted tags in an RTF document.... Read more
- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2577
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.... Read more
Affected Products : xnview- Published: Aug. 09, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1419
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) ... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2516
Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell.... Read more
Affected Products : fileutils- Published: Feb. 15, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-9567
Adobe Bridge versions 10.0.1 and earlier version have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Jun. 26, 2020
- Modified: May. 05, 2025
-
9.3
HIGHCVE-2013-2460
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceabilit... Read more
- Published: Jun. 18, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2436
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a ... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-2426
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Librari... Read more
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025