Latest CVE Feed
-
9.3
HIGHCVE-2009-4035
The FoFiType1::parse function in fofi/FoFiType1.cc in Xpdf 3.0.0, gpdf 2.8.2, kpdf in kdegraphics 3.3.1, and possibly other libraries and versions, does not check the return value of the getNextLine function, which allows context-dependent attackers to ex... Read more
- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3976
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).... Read more
Affected Products : proftp- Published: Nov. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-4001
Integer overflow in XnView before 1.97.2 might allow remote attackers to execute arbitrary code via a DICOM image with crafted dimensions, leading to a heap-based buffer overflow.... Read more
Affected Products : xnview- Published: Mar. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2020-1408
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Microsoft Graphics Remote Code Execution Vulnerability'.... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_server_2019 windows_server windows +1 more products- Published: Jul. 14, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-3969
Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file.... Read more
Affected Products : faslo_player- Published: Nov. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3932
The Gears plugin in Google Chrome before 3.0.195.32 allows user-assisted remote attackers to cause a denial of service (memory corruption and plugin crash) or possibly execute arbitrary code via unspecified use of the Gears SQL API, related to putting "SQ... Read more
Affected Products : chrome- Published: Nov. 12, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-2645
Integer overflow in the exif_data_load_data_entry function in exif-data.c in libexif before 0.6.14 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data, involving the (1) doff ... Read more
Affected Products : libexif- Published: May. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3924
Buffer overflow in pbsv.dll, as used in Soldier of Fortune II and possibly other applications when Even Balance PunkBuster 1.728 or earlier is enabled, allows remote attackers to cause a denial of service (application server crash) and possibly execute ar... Read more
- Published: Nov. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3930
Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file that triggers a buffer overflow.... Read more
- Published: Nov. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2010-0262
Microsoft Office Excel 2007 SP1 and SP2 and Office 2004 for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers access of an uninitialized stack variable, aka "Mi... Read more
- Published: Mar. 10, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3859
Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 e... Read more
- Published: Nov. 04, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3799
Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory ... Read more
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3810
Heap-based buffer overflow in Acoustica MP3 Audio Mixer 2.471 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long string in a .M3U playlist file.... Read more
Affected Products : mp3_audio_mixer- Published: Oct. 27, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3793
Unspecified vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory consumption) or possibly execute arbitrary code via unknown vectors.... Read more
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2014-4979
Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom.... Read more
Affected Products : quicktime- Published: Jul. 26, 2014
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2009-3838
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.... Read more
Affected Products : pegasus_mail- Published: Nov. 02, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3800
Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.... Read more
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-3027
Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka "Language Pack Installation Vulner... Read more
- Published: Jun. 12, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3737
The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.... Read more
- Published: Aug. 17, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3673
Microsoft Internet Explorer 7 and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Unin... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Dec. 09, 2009
- Modified: Apr. 09, 2025