Latest CVE Feed
-
10.0
HIGHCVE-2015-6459
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.... Read more
Affected Products : mds_pulsenet- EPSS Score: %1.85
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-3544
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availa... Read more
Affected Products : ubuntu_linux jdk jre linux_enterprise_server jre jdk satellite_with_embedded_oracle linux_enterprise_java- Actively Exploited
- EPSS Score: %93.04
- Published: Oct. 19, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-8598
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges.... Read more
- EPSS Score: %8.46
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-3089
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.... Read more
Affected Products : chrome- EPSS Score: %4.57
- Published: May. 16, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0742
Buffer overflow in ZfHIPCND.exe in Novell ZENworks Handheld Management 7.0 allows remote attackers to execute arbitrary code via a crafted IP Conduit packet to TCP port 2400.... Read more
Affected Products : zenworks_handheld_management- EPSS Score: %39.73
- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-6412
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.... Read more
- EPSS Score: %1.94
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-0485
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."... Read more
- EPSS Score: %6.78
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0266
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %78.81
- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-8432
In Das U-Boot through 2020.01, a double free has been found in the cmd/gpt.c do_rename_gpt_parts() function. Double freeing may result in a write-what-where condition, allowing an attacker to execute arbitrary code. NOTE: this vulnerablity was introduced ... Read more
- EPSS Score: %1.20
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-4508
The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.... Read more
Affected Products : firefox- EPSS Score: %0.48
- Published: Dec. 09, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4586
The default configuration of Opera before 11.00 enables WebSockets functionality, which has unspecified impact and remote attack vectors, possibly a related issue to CVE-2010-4508.... Read more
Affected Products : opera_browser- EPSS Score: %0.46
- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-8298
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.... Read more
Affected Products : fs-path- EPSS Score: %3.18
- Published: Mar. 04, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-2298
browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0.375.70 on Linux does not properly handle ViewHostMsg_DatabaseOpenFile messages in chroot-based sandboxing, which allows remote attackers to bypass intended sandbox restrictions ... Read more
- EPSS Score: %0.41
- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1554
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid iCount parameter.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %83.37
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-8271
Unauthenticated remote code execution with root privileges in Citrix SD-WAN Center versions before 11.2.2, 11.1.2b and 10.2.8... Read more
Affected Products : sd-wan- EPSS Score: %39.30
- Published: Nov. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-0270
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate fields in SMB transaction responses, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory... Read more
- EPSS Score: %81.39
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-2722
Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6429594. NOTE: this issue exists because of an incorrect fix for BugId 6406003.... Read more
Affected Products : java_se- EPSS Score: %4.20
- Published: Aug. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2688
Multiple integer overflows in glyphs-eimage.c in XEmacs 21.4.22, when running on Windows, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) the tiff_instantiate function processing a crafted TIFF file, (2) the p... Read more
Affected Products : xemacs- EPSS Score: %3.66
- Published: Aug. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2463
Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of... Read more
- EPSS Score: %4.17
- Published: Jul. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1930
The Telnet service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote Telnet servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a cli... Read more
- EPSS Score: %47.00
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025