Latest CVE Feed
-
9.3
HIGH- Published: Dec. 10, 2020
- Modified: Aug. 28, 2025
-
9.3
HIGHCVE-2008-2152
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.... Read more
Affected Products : openoffice.org- Published: Jun. 10, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2160
Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.... Read more
- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2111
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.... Read more
Affected Products : yahoo_assistant- Published: May. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2069
Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.... Read more
Affected Products : groupwise- Published: May. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-54720
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons allows SQL Injection. This issue affects Nest Addons: from n/a through 1.6.3.... Read more
Affected Products :- Published: Aug. 28, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2008-2015
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in on... Read more
Affected Products : appscan- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2008
Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.... Read more
Affected Products : trillian- Published: Apr. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2054
Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.... Read more
Affected Products : ciscoworks_common_services- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2010
Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute arbitrary code via a crafted QuickTime media file. NOTE: as of 20080429, the only disclosure is a vague pre-advisory with no actionable... Read more
- Published: Apr. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1973
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.... Read more
Affected Products : subedit_player- Published: Apr. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1965
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -lau... Read more
- Published: Apr. 25, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1912
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.... Read more
Affected Products : divx_player- Published: Apr. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1898
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterfac... Read more
- Published: Apr. 21, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1860
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.... Read more
Affected Products : lokicms- Published: Apr. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-1925
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-1929
Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more
- Published: Aug. 07, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-1802
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitrary code via a Remote Desktop Protocol (RDP) redirect request with modified length fields.... Read more
Affected Products : rdesktop- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1803
Integer signedness error in the xrealloc function (rdesktop.c) in RDesktop 1.5.0 allows remote attackers to execute arbitrary code via unknown parameters that trigger a heap-based overflow. NOTE: the role of the channel_process function was not specified... Read more
Affected Products : rdesktop- Published: May. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-1805
Incomplete blacklist vulnerability in Skype 3.6.0.248, and other versions before 3.8.0.139, allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI that ends in an executable extension that is no... Read more
- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025