Latest CVE Feed
-
10.0
HIGHCVE-2008-3692
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMw... Read more
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-3113
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.... Read more
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6818
SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS comma... Read more
Affected Products : business_intelligence_platform- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2008-1100
Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.... Read more
Affected Products : clamav- Published: Apr. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0657
Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstr... Read more
- Published: Feb. 07, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6726
Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.... Read more
Affected Products : android- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2007-6047
Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.... Read more
- Published: Nov. 20, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6045
Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.... Read more
- Published: Nov. 20, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2021-1609
Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) co... Read more
- Published: Aug. 04, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-2831
Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel memo... Read more
Affected Products : madwifi- Published: May. 24, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-2418
Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that trigg... Read more
Affected Products : trillian_pro- Published: May. 02, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6646
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2)... Read more
- Published: Oct. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2006-5362
Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 10.1.3.0.0 has unknown impact and remote attack vectors, aka Vuln# OC4J04.... Read more
Affected Products : application_server- Published: Oct. 18, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5349
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07.... Read more
Affected Products : http_server- Published: Oct. 18, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5156
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.... Read more
- Published: Oct. 05, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2021-1459
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to improper v... Read more
- Published: Apr. 08, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-6563
Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following prod... Read more
Affected Products : dir-823_firmware dir-822_firmware dir-818l\(w\)_firmware dir-895l_firmware dir-890l_firmware dir-885l_firmware dir-880l_firmware dir-868l_firmware dir-850l_firmware dir-890l +8 more products- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-6554
Synology NAS servers DS107, firmware version 3.1-1639 and prior, and DS116, DS213, firmware versions prior to 5.2-5644-1, use non-random default credentials of: guest:(blank) and admin:(blank) . A remote network attacker can gain privileged access to a vu... Read more
- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-0992
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentall... Read more
Affected Products : groupwise_messenger- Published: Apr. 14, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-3983
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute... Read more
Affected Products : firefox thunderbird ubuntu_linux linux_enterprise_server seamonkey linux_enterprise_desktop- Published: Oct. 10, 2012
- Modified: Apr. 11, 2025