Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2009-4225

    Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method.... Read more

    • Published: Dec. 08, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4244

    Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows rem... Read more

    • Published: Jan. 25, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-4219

    Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote attackers to execute arbitrary code via a long URL property value. NOTE: some of these details are obtained... Read more

    Affected Products : haihaisoft_universal_player
    • Published: Dec. 07, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-1943

    Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.... Read more

    Affected Products : acdsee_photo_manager
    • Published: Apr. 11, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2012-0142

    Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary c... Read more

    • Published: May. 09, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-4195

    Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third... Read more

    Affected Products : illustrator
    • Published: Dec. 04, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4107

    Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.... Read more

    Affected Products : invisible_browsing
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4100

    Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.... Read more

    Affected Products : firefox yoono
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4101

    infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.... Read more

    Affected Products : firefox inforss
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4127

    Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaScript with Chrome privileges via vectors involving unspecified Toolbar buttons and the eval function. NOTE... Read more

    Affected Products : firefox wikipedia_toolbar
    • Published: Dec. 02, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4103

    Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service and possibly execute arbitrary code via unspecified FTP server responses. NOTE: the provenance of this information is unknown; the det... Read more

    Affected Products : robo-ftp
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-11815

    An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.... Read more

    • Published: May. 08, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-0999

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler b... Read more

    • Published: Mar. 12, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2014-4405

    IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.... Read more

    Affected Products : mac_os_x iphone_os tvos
    • Published: Sep. 18, 2014
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2009-0556

    Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that tri... Read more

    Affected Products : powerpoint office_powerpoint
    • Published: Apr. 03, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4844

    Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML ... Read more

    Affected Products : internet_explorer
    • Published: Dec. 11, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4035

    The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to ex... Read more

    Affected Products : xpdf gpdf kdegraphics kpdf
    • Published: Dec. 21, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-3976

    Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).... Read more

    Affected Products : proftp
    • Published: Nov. 18, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2009-4001

    Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.... Read more

    Affected Products : xnview
    • Published: Mar. 15, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2020-1408

    A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.... Read more

    • Published: Jul. 14, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 294503 Results