Latest CVE Feed
-
9.3
HIGHCVE-2008-2779
Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST com... Read more
Affected Products : cuteftp- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-20610
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-1391... Read more
Affected Products : android exynos_8895 exynos_9810 exynos_7885 exynos_8890 exynos_7570 exynos_7870 exynos_7880- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2690
Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) con... Read more
Affected Products : browsercrm- Published: Jun. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2021-41088
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not c... Read more
Affected Products : elvish- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2683
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, a... Read more
Affected Products : barcode_sdk- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2684
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: s... Read more
Affected Products : black_ice_barcode_sdk- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2570
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.... Read more
Affected Products : limesurvey- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2545
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a... Read more
- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2503
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.... Read more
Affected Products : emule_x-ray- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2548
Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers me... Read more
Affected Products : razr- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2547
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross... Read more
Affected Products : windows_installer- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-54946
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.... Read more
Affected Products :- Published: Aug. 30, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2008-2435
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.... Read more
- Published: Dec. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4197
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or con... Read more
- Published: Sep. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2408
Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.... Read more
Affected Products : trillian_pro- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2409
Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.... Read more
Affected Products : trillian- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2399
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2427
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.... Read more
- Published: Jun. 24, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4234
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application associati... Read more
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2325
QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025