Latest CVE Feed
-
9.3
CRITICALCVE-2012-10021
A stack-based buffer overflow vulnerability exists in D-Link DIR-605L Wireless N300 Cloud Router firmware versions 1.12 and 1.13 via the getAuthCode() function. The flaw arises from unsafe usage of sprintf() when processing user-supplied CAPTCHA data via ... Read more
Affected Products : dir-605l_firmware- Published: Jul. 31, 2025
- Modified: Jul. 31, 2025
- Vuln Type: Memory Corruption
-
9.3
CRITICALCVE-2012-10045
XODA version 0.4.5 contains an unauthenticated file upload vulnerability that allows remote attackers to execute arbitrary PHP code on the server. The flaw resides in the upload functionality, which fails to properly validate or restrict uploaded file typ... Read more
Affected Products :- Published: Aug. 08, 2025
- Modified: Aug. 08, 2025
- Vuln Type: Authentication
-
9.3
HIGHCVE-2012-0985
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, and 3.0; SmartWi Connection Utility 4.7, 4.7.4, 4.8, 4.9, 4.10, and 4.11; and... Read more
Affected Products : smartwi_connection_utillity vaio_easy_connect vaio_pc_wireless_lan_wizard vaio_wireless_wizard- Published: Jun. 07, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0926
The RV10 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, does not properly handle height and width values, which allows remote attackers to execute arbitrary code via a crafted RV10 RealVideo vid... Read more
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0916
Heap-based buffer overflow in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via a crafted image in a chat message, as demonstrated using a PNG file.... Read more
Affected Products : renren_talk- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0924
RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via vectors involving a VIDOBJ_START_CODE code in a header within a video stream.... Read more
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0915
Integer signedness error in RenRen Talk 2.9 allows remote attackers to execute arbitrary code via crafted dimensions of a skin file, leading to a heap-based buffer overflow, as demonstrated using a BMP image.... Read more
Affected Products : renren_talk- Published: Jan. 24, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0925
Unspecified vulnerability in the RV40 codec in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted RV40 RealVideo video stream.... Read more
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0922
rvrender.dll in RealNetworks RealPlayer 11.x, 14.x, and 15.x before 15.02.71, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via crafted flags in an RMFF file.... Read more
- Published: Feb. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0592
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CV... Read more
- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0627
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CV... Read more
- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0623
WebKit, as used in Apple iOS before 5.1 and iTunes before 10.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CV... Read more
- Published: Mar. 08, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2012-0724
Adobe Flash Player before 11.2.202.229 in Google Chrome before 18.0.1025.151 allow attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2012-0725.... Read more
- Published: Apr. 06, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-6085
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-20... Read more
Affected Products : internet_explorer- Published: Nov. 11, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2012-0754
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to execute arbitrary code or cause a denial of serv... Read more
- Actively Exploited
- Published: Feb. 16, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1562
A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code on a target system. To exploit the vulnerability, a ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_10_1607 windows_10_1809 +9 more products- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-0755
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows attackers to bypass intended access restrictions via unspecif... Read more
- Published: Feb. 16, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1555
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context o... Read more
- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2014-4080
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-20... Read more
Affected Products : internet_explorer- Published: Sep. 10, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2012-0677
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.... Read more
Affected Products : itunes- Published: Jun. 12, 2012
- Modified: Apr. 11, 2025