Latest CVE Feed
-
9.3
HIGHCVE-2008-3018
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file, aka the "Malformed PICT Filter Vulnerabil... Read more
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3012
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe... Read more
Affected Products : office internet_explorer windows_vista windows_xp works sql_server office_powerpoint_viewer windows-nt visio digital_image_suite +6 more products- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3021
Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka ... Read more
- Published: Aug. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3033
RSS-aggregator 1.0 does not require administrative authentication for the admin/fonctions/ directory, which allows remote attackers to access admin functions and have unspecified other impact, as demonstrated by (1) an IdFlux request to supprimer_flux.php... Read more
Affected Products : rss_aggregator- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3007
Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Unifo... Read more
- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3001
The Aggregation module 5.x before 5.x-4.4 for Drupal allows remote attackers to upload files with arbitrary extensions, and possibly execute arbitrary code, via a crafted feed that allows upload of files with arbitrary extensions.... Read more
Affected Products : aggregation_module- Published: Jul. 03, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-3014
Buffer overflow in gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP... Read more
Affected Products : office internet_explorer windows_vista windows_xp works sql_server office_powerpoint_viewer windows-nt visio digital_image_suite +5 more products- Published: Sep. 11, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2959
Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might allow remote attackers to execute arbitrary code via a long lpstrLinkPath argument to the fCreateShellLink function.... Read more
Affected Products : visual_basic_enterprise_edition- Published: Jul. 02, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2910
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll 6.0.18.1 and mvtextout.dll, in muvee autoProducer 6.0 and 6.1 allows remote attackers to execute arbitrary code via a long FontSetting ... Read more
Affected Products : autoproducer- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2898
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the c_temp_path parameter. NOTE: in some environments, this can be leveraged for remot... Read more
Affected Products : hedgehog-cms- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2908
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame p... Read more
Affected Products : iprint_client- Published: Jun. 30, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2886
PHP remote file inclusion vulnerability in include/plugins/jrBrowser/purchase.php in Jamroom 3.3.0 through 3.3.5, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the jamroom[jm_dir] parameter.... Read more
Affected Products : jamroom- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2885
PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a U... Read more
Affected Products : odars- Published: Jun. 27, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2785
Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows r... Read more
- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2779
Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST com... Read more
Affected Products : cuteftp- Published: Jun. 19, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-20610
An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-1391... Read more
Affected Products : android exynos_8895 exynos_9810 exynos_7885 exynos_8890 exynos_7570 exynos_7870 exynos_7880- Published: Mar. 24, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2690
Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) con... Read more
Affected Products : browsercrm- Published: Jun. 13, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2021-41088
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not c... Read more
Affected Products : elvish- Published: Sep. 23, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2008-2683
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, a... Read more
Affected Products : barcode_sdk- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2008-2684
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: s... Read more
Affected Products : black_ice_barcode_sdk- Published: Jun. 12, 2008
- Modified: Apr. 09, 2025