Latest CVE Feed
-
9.3
HIGHCVE-2008-2399
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2427
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.... Read more
- Published: Jun. 24, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4234
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application associati... Read more
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2325
QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2383
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issu... Read more
Affected Products : xterm- Published: Jan. 02, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2320
Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (applicat... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2321
Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments.... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2322
Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF file with a long Type 1 font, which triggers a heap-based buffer ov... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2363
The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that t... Read more
Affected Products : pan- Published: Jun. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2306
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute a... Read more
- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2305
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."... Read more
- Published: Sep. 16, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2281
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containi... Read more
- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2259
Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."... Read more
Affected Products : internet_explorer- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2256
Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitia... Read more
Affected Products : internet_explorer- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2253
Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling ... Read more
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2254
Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2245
Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allo... Read more
- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2228
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.... Read more
Affected Products : cyberfolio- Published: May. 14, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2283
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the ... Read more
- Published: May. 18, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2258
Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific ... Read more
Affected Products : internet_explorer- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025