Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2008-2435

    Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.... Read more

    Affected Products : housecall housecall
    • Published: Dec. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4197

    Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or con... Read more

    • Published: Sep. 27, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2408

    Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.... Read more

    Affected Products : trillian_pro
    • Published: May. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2409

    Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.... Read more

    Affected Products : trillian
    • Published: May. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2399

    Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue... Read more

    Affected Products : firefox fireftp
    • Published: May. 22, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2427

    Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.... Read more

    • Published: Jun. 24, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4234

    Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application associati... Read more

    Affected Products : mac_os_x mac_os_x_server
    • Published: Dec. 17, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2325

    QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."... Read more

    Affected Products : mac_os_x mac_os_x_server quicklook
    • Published: Aug. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2383

    CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issu... Read more

    Affected Products : xterm
    • Published: Jan. 02, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2320

    Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (applicat... Read more

    Affected Products : mac_os_x carboncore mac_os_x_server
    • Published: Aug. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2321

    Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments.... Read more

    Affected Products : mac_os_x coregraphics mac_os_x_server
    • Published: Aug. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2322

    Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF file with a long Type 1 font, which triggers a heap-based buffer ov... Read more

    Affected Products : mac_os_x coregraphics mac_os_x_server
    • Published: Aug. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2363

    The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that t... Read more

    Affected Products : pan
    • Published: Jun. 02, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2306

    Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute a... Read more

    Affected Products : windows_vista windows_xp safari
    • Published: Jun. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2305

    Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."... Read more

    Affected Products : mac_os_x mac_os_x_server
    • Published: Sep. 16, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2281

    Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containi... Read more

    Affected Products : internet_explorer ie
    • Published: May. 18, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2259

    Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."... Read more

    Affected Products : internet_explorer
    • Published: Aug. 13, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2256

    Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitia... Read more

    Affected Products : internet_explorer
    • Published: Aug. 13, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2253

    Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling ... Read more

    • Published: Sep. 11, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2254

    Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."... Read more

    Affected Products : internet_explorer
    • Published: Aug. 13, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 294701 Results