Latest CVE Feed
-
9.3
HIGHCVE-2009-4225
Stack-based buffer overflow in the PestPatrol ActiveX control (ppctl.dll) 5.6.7.9 in CA eTrust PestPatrol allows remote attackers to execute arbitrary code via a long argument to the Initialize method.... Read more
- Published: Dec. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4244
Heap-based buffer overflow in RealNetworks RealPlayer 10; RealPlayer 10.5 6.0.12.1040 through 6.0.12.1741; RealPlayer 11 11.0.0 through 11.0.4; RealPlayer Enterprise; Mac RealPlayer 10, 10.1, and 11.0; Linux RealPlayer 10; and Helix Player 10.x allows rem... Read more
- Published: Jan. 25, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4219
Stack-based buffer overflow in the MYACTIVEX.MyActiveXCtrl.1 ActiveX control in MyActiveX.ocx 1.4.8.0 in Haihaisoft Universal Player allows remote attackers to execute arbitrary code via a long URL property value. NOTE: some of these details are obtained... Read more
Affected Products : haihaisoft_universal_player- Published: Dec. 07, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1943
Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.... Read more
Affected Products : acdsee_photo_manager- Published: Apr. 11, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2012-0142
Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary c... Read more
- Published: May. 09, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-4195
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execute arbitrary code via a long DSC comment in an Encapsulated PostScript (.eps) file. NOTE: some of these details are obtained from third... Read more
Affected Products : illustrator- Published: Dec. 04, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4107
Buffer overflow in Invisible Browsing 5.0.52 allows user-assisted remote attackers to execute arbitrary code via a crafted .ibkey file containing a long string.... Read more
Affected Products : invisible_browsing- Published: Nov. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4100
Yoono extension before 6.1.1 for Firefox performs certain operations with chrome privileges, which allows user-assisted remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via DOM event handlers such as onload.... Read more
- Published: Nov. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4101
infoRSS 1.1.4.2 and earlier extension for Firefox performs certain operations with chrome privileges, which allows remote attackers to execute arbitrary commands and perform cross-domain scripting attacks via the description tag of an RSS feed.... Read more
- Published: Nov. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4127
Unspecified vulnerability in Wikipedia Toolbar extension before 0.5.9.2 for Firefox allows user-assisted remote attackers to execute arbitrary JavaScript with Chrome privileges via vectors involving unspecified Toolbar buttons and the eval function. NOTE... Read more
- Published: Dec. 02, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4103
Buffer overflow in Robo-FTP 3.6.17, and possibly other versions, allows remote FTP servers to cause a denial of service and possibly execute arbitrary code via unspecified FTP server responses. NOTE: the provenance of this information is unknown; the det... Read more
Affected Products : robo-ftp- Published: Nov. 29, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-11815
An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup.... Read more
Affected Products : linux_kernel ubuntu_linux debian_linux leap active_iq_unified_manager hci_management_node solidfire cn1610_firmware vasa_provider_for_clustered_data_ontap virtual_storage_console +5 more products- Published: May. 08, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-0999
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler b... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +5 more products- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2014-4405
IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via an application that provides crafted key-mapping properties.... Read more
- Published: Sep. 18, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2009-0556
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid index value that tri... Read more
- Published: Apr. 03, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4844
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML ... Read more
Affected Products : internet_explorer- Published: Dec. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4035
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to ex... Read more
- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3976
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).... Read more
Affected Products : proftp- Published: Nov. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4001
Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.... Read more
Affected Products : xnview- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1408
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024