Latest CVE Feed
-
9.3
HIGHCVE-2008-2570
Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.... Read more
Affected Products : limesurvey- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2545
Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a... Read more
- Published: Jun. 06, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2503
Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.... Read more
Affected Products : emule_x-ray- Published: May. 29, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2548
Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers me... Read more
Affected Products : razr- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2547
Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross... Read more
Affected Products : windows_installer- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-54946
A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.... Read more
Affected Products :- Published: Aug. 30, 2025
- Modified: Sep. 02, 2025
- Vuln Type: Injection
-
9.3
HIGHCVE-2008-2435
Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.... Read more
- Published: Dec. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4197
Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or con... Read more
- Published: Sep. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2408
Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.... Read more
Affected Products : trillian_pro- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2409
Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.... Read more
Affected Products : trillian- Published: May. 23, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2399
Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue... Read more
- Published: May. 22, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2427
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.... Read more
- Published: Jun. 24, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-4234
Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application associati... Read more
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2325
QuickLook in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office file, related to insufficient "bounds checking."... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2383
CRLF injection vulnerability in xterm allows user-assisted attackers to execute arbitrary commands via LF (aka \n) characters surrounding a command name within a Device Control Request Status String (DECRQSS) escape sequence in a text file, a related issu... Read more
Affected Products : xterm- Published: Jan. 02, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2320
Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (applicat... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2321
Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments.... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2322
Integer overflow in CoreGraphics in Apple Mac OS X 10.4.11, 10.5.2, and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF file with a long Type 1 font, which triggers a heap-based buffer ov... Read more
- Published: Aug. 04, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2363
The PartsBatch class in Pan 0.132 and earlier does not properly manage the data structures for Parts batches, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted .nzb file that t... Read more
Affected Products : pan- Published: Jun. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2306
Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows remote attackers to bypass intended access restrictions, and force a client system to download and execute a... Read more
- Published: Jun. 23, 2008
- Modified: Apr. 09, 2025