Latest CVE Feed
-
9.3
HIGHCVE-2022-27799
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the co... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-27797
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context o... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-27792
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploit... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-27787
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploit... Read more
- Published: May. 11, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2022-27784
Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exp... Read more
- Published: May. 06, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-1787
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) inc_dir or (2) lib_dir pa... Read more
Affected Products : time-assistant- Published: Mar. 31, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2022-26761
A memory corruption issue was addressed with improved memory handling. This issue is fixed in Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. An application may be able to execute arbitrary code with kernel privileges.... Read more
- Published: May. 26, 2022
- Modified: May. 30, 2025
-
9.3
HIGHCVE-2022-26720
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Security Update 2022-004 Catalina, macOS Monterey 12.4, macOS Big Sur 11.6.6. A malicious application may be able to execute arbitrary code with kernel privil... Read more
- Published: May. 26, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2007-1754
PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which b... Read more
Affected Products : publisher- Published: Jul. 10, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1747
Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.... Read more
Affected Products : office- Published: May. 08, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1749
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, wh... Read more
Affected Products : internet_explorer- Published: Aug. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1765
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, ... Read more
- Published: Mar. 30, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1735
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.... Read more
Affected Products : wordperfect- Published: Mar. 28, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1725
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.... Read more
Affected Products : icebb- Published: Mar. 28, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1688
Buffer overflow in the PhPInfo ActiveX control in PhPCtrl.dll in Callisto PhotoParade Player allows remote attackers to execute arbitrary code via the FileVersionof property.... Read more
Affected Products : photoparade_player- Published: Sep. 14, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1680
Stack-based buffer overflow in the createAndJoinConference function in the AudioConf ActiveX control (yacscom.dll) in Yahoo! Messenger before 20070313 allows remote attackers to execute arbitrary code via long (1) socksHostname and (2) hostname properties... Read more
Affected Products : messenger- Published: Apr. 06, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1658
Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the s... Read more
Affected Products : windows_vista- Published: Mar. 24, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1628
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the SPL_CFG[dirroot] parameter to (1) service.alert.in... Read more
Affected Products : studiewijzer- Published: Mar. 23, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2007-1614
Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename.... Read more
- Published: Mar. 23, 2007
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2019-0581
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka "Jet Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows ... Read more
- Published: Jan. 08, 2019
- Modified: Nov. 21, 2024