Latest CVE Feed
-
9.3
HIGHCVE-2009-2582
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2... Read more
Affected Products : download_manager- Published: Jul. 23, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2530
Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption... Read more
Affected Products : windows_7 windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2643
Multiple unspecified vulnerabilities in the PDF distiller in the Attachment Service component in Research In Motion (RIM) BlackBerry Enterprise Server (BES) software 4.1.3 through 5.0 and BlackBerry Professional Software 4.1.4 allow user-assisted remote a... Read more
- Published: Jul. 28, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2519
The DHTML Editing Component ActiveX control in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly format HTML markup, which allows remote attackers to execute arbitrary code via a crafted web site that triggers "system state... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2496
Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Interne... Read more
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2550
Stack-based buffer overflow in Hamster Audio Player 0.3a allows remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .hpl playlist file.... Read more
Affected Products : hamster_audio_player- Published: Jul. 20, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2498
Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf,... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2503
GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP... Read more
Affected Products : windows_server_2008 office .net_framework excel_viewer word_viewer internet_explorer windows_2000 windows_2003_server windows_vista windows_xp +17 more products- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2501
Heap-based buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold a... Read more
Affected Products : windows_server_2008 office .net_framework excel_viewer word_viewer internet_explorer windows_2000 windows_2003_server windows_vista windows_xp +17 more products- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2403
Heap-based buffer overflow in SCMPX 1.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long string in a .m3u playlist file.... Read more
Affected Products : scmpx- Published: Jul. 09, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2497
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser applicati... Read more
Affected Products : windows_7 windows_server_2008 .net_framework windows_2000 windows_server_2003 windows_vista windows_xp- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2375
Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : photo_dvd_maker- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2363
Stack-based buffer overflow in KUDRSOFT AudioPLUS 2.00.215 allows remote attackers to execute arbitrary code via a .pls playlist file with a playlist entry containing a long File1 argument.... Read more
Affected Products : audioplus- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.... Read more
- Published: Jul. 09, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2020-13533
A privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which reference binaries with weak permissions, can be abused by attackers to effectively ‘backdoor’ the installation files an... Read more
- Published: Apr. 09, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-2386
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.... Read more
Affected Products : awakening_winds3d_viewer_plugin- Published: Jul. 10, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2347
Multiple integer overflows in inter-color spaces conversion tools in libtiff 3.8 through 3.8.2, 3.9, and 4.0 allow context-dependent attackers to execute arbitrary code via a TIFF image with large (1) width and (2) height values, which triggers a heap-bas... Read more
Affected Products : libtiff- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2384
Buffer overflow in amp.exe in Brothersoft PEamp 1.02b allows user-assisted remote attackers to execute arbitrary code via a long string in a .m3u playlist file. NOTE: some of these details are obtained from third party information.... Read more
Affected Products : peamp- Published: Jul. 08, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2223
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible.... Read more
Affected Products : lightopencms- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2186
Unspecified vulnerability in Adobe Shockwave Player before 11.0.0.465 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2009-1860, related to an older issue that "was previously resolved in Shockwave... Read more
Affected Products : shockwave_player- Published: Jun. 25, 2009
- Modified: Apr. 09, 2025