Latest CVE Feed
-
9.3
HIGHCVE-2010-0679
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument t... Read more
Affected Products : chemview- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0658
Multiple integer overflows in Skia, as used in Google Chrome before 4.0.249.78, allow remote attackers to execute arbitrary code in the Chrome sandbox or cause a denial of service (memory corruption and application crash) via vectors involving CANVAS elem... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0657
Google Chrome before 4.0.249.78 on Windows does not perform the expected encoding, escaping, and quoting for the URL in the --app argument in a desktop shortcut, which allows user-assisted remote attackers to execute arbitrary programs or obtain sensitive... Read more
- Published: Feb. 18, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0555
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving the product'... Read more
Affected Products : windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Feb. 04, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0599
Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt XML RPC sessions from operat... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0598
Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediator NBM-2400 and NBM-4800 and the Richards-Zeta Mediator 2500 does not encrypt HTTP sessions from operator ... Read more
- Published: May. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1225
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1226.... Read more
- Published: Jun. 09, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0529
Heap-based buffer overflow in QuickTime.qts in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PICT image with a BkPixPat opcode (0x12) containing crafted val... Read more
- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0527
Integer overflow in Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image.... Read more
- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0620
Directory traversal vulnerability in the SSL Service in EMC HomeBase Server 6.2.x before 6.2.3 and 6.3.x before 6.3.2 allows remote attackers to overwrite arbitrary files with any content, and consequently execute arbitrary code, via a .. (dot dot) in an ... Read more
Affected Products : homebase_server- Published: Feb. 25, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-8575
A remote code execution vulnerability exists in Microsoft Project software when it fails to properly handle objects in memory, aka "Microsoft Project Remote Code Execution Vulnerability." This affects Microsoft Project, Office 365 ProPlus, Microsoft Proje... Read more
- Published: Nov. 14, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0486
The WinVerifyTrust function in Authenticode Signature Verification 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 doe... Read more
Affected Products : windows_7 windows_server_2008 windows_2000 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-1658
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-1706... Read more
Affected Products : internet_explorer- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-0487
The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server ... Read more
Affected Products : windows_7 windows_server_2008 windows_2000 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0480
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AV... Read more
Affected Products : windows_server_2008 windows_2000 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0491
Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory... Read more
Affected Products : internet_explorer windows_2000 windows_2003_server windows_server_2003 windows_xp- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-1710
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE... Read more
Affected Products : internet_explorer- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-0492
Use-after-free vulnerability in mstime.dll in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via vectors related to the TIME2 behavior, the CTimeAction object, and destruction of markup, leading to memory corruption, aka "... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2003_server windows_server_2003 windows_vista windows_xp ie- Published: Mar. 31, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0512
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access re... Read more
- Published: Mar. 30, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2021-35989
Adobe Bridge version 11.0.2 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the cu... Read more
- Published: Aug. 20, 2021
- Modified: Nov. 21, 2024