Latest CVE Feed
-
9.3
HIGHCVE-2008-3480
Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Print Wizard, allows remote attackers to execute arbitrary code via a long mainurl parameter.... Read more
- Published: Aug. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3595
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers to execute arbitrary PHP code via a URL in the CFG[txtsql][class] parameter.... Read more
Affected Products : txtsql- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4255
Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) in Microsoft Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2, and Office Project 2... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3430
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as SiOL Komunikator 1.3, allows remote attackers to execute arbitrary code via a large argument supplied to the BGColor method. NOTE: thi... Read more
Affected Products : eyeball_messenger_sdk- Published: Jul. 31, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3364
Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.... Read more
- Published: Jul. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3360
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.... Read more
Affected Products : intellitamper- Published: Jul. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3329
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."... Read more
Affected Products : links- Published: Jul. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3285
The Filesys::SmbClientParser module 2.7 and earlier for Perl allows remote SMB servers to execute arbitrary code via a folder name containing shell metacharacters.... Read more
Affected Products : filesys_smbclientparser- Published: Jul. 24, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3246
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1) before bundle 36 and BlackBerry Enterprise Server 4.1 SP3 (4.1.3) through 4.1 SP5 (4.1.5) allows user-assisted remote attack... Read more
- Published: Jul. 21, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3207
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the (1) sourceFolder or (2) moduleFolder parameter.... Read more
Affected Products : praygan_cms- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3182
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL.... Read more
Affected Products : download_accelerator_plus- Published: Jul. 15, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3232
Unrestricted file upload vulnerability in ecrire/images.php in Dotclear 1.2.7.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in... Read more
Affected Products : dotclear- Published: Jul. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3156
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method.... Read more
Affected Products : panda_activescan- Published: Jul. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3155
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Update method.... Read more
Affected Products : panda_activescan- Published: Jul. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3166
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the sIncPath parameter.... Read more
Affected Products : ray- Published: Jul. 14, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3018
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerabil... Read more
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3012
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe... Read more
Affected Products : office internet_explorer windows_vista windows_xp works sql_server office_powerpoint_viewer windows-nt visio digital_image_suite +6 more products- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3021
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka ... Read more
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3033
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php... Read more
Affected Products : rss_aggregator- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3007
Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Unifo... Read more
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025