Latest CVE Feed
-
9.3
HIGHCVE-2010-1385
Use-after-free vulnerability in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1 on Mac OS X 10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF docume... Read more
- Published: Jun. 11, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1377
Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vect... Read more
- Published: Jun. 17, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1423
Argument injection vulnerability in the URI handler in (a) Java NPAPI plugin and (b) Java Deployment Toolkit in Java 6 Update 10, 19, and other versions, when running on Windows and possibly on Linux, allows remote attackers to execute arbitrary code via ... Read more
- Published: Apr. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1326
perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before build 3736, and 2009 before 3729 allows remote attackers to bypass the permissions check, modify arbitrary mod... Read more
- Published: Sep. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1290
Adobe Shockwave Player before 11.5.7.609 allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-1284, CVE-2010-1286, CVE-2010-1287, CVE-2010-128... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1280
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1279
Multiple unspecified vulnerabilities in Adobe Photoshop CS4 11.x before 11.0.1 allow user-assisted remote attackers to execute arbitrary code via a crafted TIFF file.... Read more
- Published: May. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1273
Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.... Read more
Affected Products : wt- Published: Apr. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1292
The implementation of pami RIFF chunk parsing in Adobe Shockwave Player before 11.5.7.609 does not validate a certain value from a file before using it in file-pointer calculations, which allows remote attackers to execute arbitrary code or cause a denial... Read more
Affected Products : windows_7 windows_server_2008 macos windows_server_2003 windows_vista windows shockwave_player- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1250
Heap-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with malformed (1) EDG (0x88) and (2) P... Read more
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1225
The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server 2005 Gold and R2 SP1, and Windows Virtual PC does not properly restrict access from the guest OS to memor... Read more
- Published: Apr. 01, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1239
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Action /S /Launch" sequence, and (2) execute arbitrary programs embedded in a PDF document via an unspecified "/Launch /Action" sequence, ... Read more
- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1297
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial o... Read more
Affected Products : flash_player mac_os_x opensuse linux_enterprise acrobat acrobat_reader windows air- Actively Exploited
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1252
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."... Read more
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1203
The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.... Read more
Affected Products : firefox- Published: Jun. 24, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1249
Buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed ExternName (0x23) record, aka "Ex... Read more
- Published: Jun. 08, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1177
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving document.write calls with long crafted strings.... Read more
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-0604
A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the ... Read more
Affected Products : visual_studio_code- Published: Aug. 17, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-1180
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.... Read more
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-1175
Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified impact via a certain XML document that references a crafted web site in the SRC attribute of an image element, related to a "0day Vulnerab... Read more
- Published: Mar. 29, 2010
- Modified: Apr. 11, 2025