Latest CVE Feed
-
9.3
HIGHCVE-2010-0364
Stack-based buffer overflow in VideoLAN VLC Media Player 0.8.6 allows user-assisted remote attackers to execute arbitrary code via an ogg file with a crafted Advanced SubStation Alpha Subtitle (.ass) file, probably involving the Dialogue field.... Read more
Affected Products : vlc_media_player- Published: Jan. 21, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0379
Multiple unspecified vulnerabilities in the Macromedia Flash ActiveX control in Adobe Flash Player 6, as distributed in Microsoft Windows XP SP2 and SP3, might allow remote attackers to execute arbitrary code via unspecified vectors that are not related t... Read more
- Published: Jan. 21, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0257
Microsoft Office Excel 2002 SP3 does not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Microsoft Office Excel Record Memory Corruption Vulnerability."... Read more
- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0249
Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attac... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Jan. 15, 2010
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-2411
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-20... Read more
Affected Products : internet_explorer- Published: Jul. 14, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2010-0244
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Jan. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2022-28845
Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim ... Read more
- Published: Jun. 15, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0250
Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows ... Read more
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0203
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0198, CVE-2010-0199, and CVE-2010-0202.... Read more
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0196
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors, a different vulnerability than CVE-... Read more
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0194
Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to cause a denial of service (memory corruption) or execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2010-0197, CVE-... Read more
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0176
Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 do not properly manage reference counts for option elements in a XUL tree optgroup, which might allow remote attackers to execu... Read more
- Published: Apr. 05, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2017-15126
A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly can lead to a situation where a fork event will be remo... Read more
Affected Products : linux_kernel- Published: Jan. 14, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-0165
The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary c... Read more
Affected Products : firefox- Published: Mar. 25, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0130
Integer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via a crafted .dir (aka Director) file.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0127
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted FFFFFF45h Shockwave 3D blocks in a Shockwave file.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0129
Multiple integer overflows in Adobe Shockwave Player before 11.5.7.609 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted .dir (aka Director) file that triggers an array index error.... Read more
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0131
Stack-based buffer overflow in the SpreadSheet Lotus 123 reader (wkssr.dll), as used in Autonomy KeyView 10.4 and 10.9, Symantec Mail Security, and possibly other products, allows remote attackers to execute arbitrary code via unspecified vectors related ... Read more
- Published: Aug. 17, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-4573
The Update Installer in VMware ESXi 4.1, when a modified sfcb.cfg is present, does not properly configure the SFCB authentication mode, which allows remote attackers to obtain access via an arbitrary username and password.... Read more
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2010-0116
Integer overflow in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows might allow remote attackers to execute arbitrary code via a crafted QCP file that triggers a heap-based buffer overflow.... Read more
- Published: Aug. 30, 2010
- Modified: Apr. 11, 2025