Latest CVE Feed
-
10.0
HIGHCVE-2015-6552
The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance through 2.5.4, 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, and... Read more
- Published: May. 07, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2012-2803
Double free vulnerability in the mpeg_decode_frame function in libavcodec/mpeg12.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, has unknown impact and attack vectors, related to resetting the data size value.... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2800
Unspecified vulnerability in the ff_ivi_process_empty_tile function in libavcodec/ivi_common.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors in which the "tile size ... mismatches paramet... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1126
FreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (invalid heap read operation and memory corruption) or possibly execute arbitrary code via crafted property dat... Read more
- Published: Apr. 25, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-3143
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Update 35 and earlier, and 5.0 Update 36 and earlier allows remote attackers to affect confidentiality, integrity, and availability, rela... Read more
- Published: Oct. 16, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-0751
The ActiveX control in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
- Published: Feb. 16, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-6490
Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
- Published: Oct. 28, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6476
Advantech EKI-122x-BE devices with firmware before 1.65, EKI-132x devices with firmware before 1.98, and EKI-136x devices with firmware before 1.27 have hardcoded SSH keys, which makes it easier for remote attackers to obtain access via an SSH session.... Read more
Affected Products : eki-1321_series_firmware eki-1322_series_firmware eki-1361_series_firmware eki-1362_series_firmware eki-122x_series_firmware eki-1221 eki-1221d eki-1222 eki-1222d eki-1224 +4 more products- Published: Nov. 07, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute a... Read more
- Published: Dec. 25, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-4791
DBServer.exe in HP Data Protector Media Operations 6.11 and earlier allows remote attackers to execute arbitrary code via a crafted request containing a large value in a length field.... Read more
Affected Products : data_protector_media_operations- Published: Feb. 03, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-6473
WAGO IO 750-849 01.01.27 and WAGO IO 750-881 01.02.05 do not contain privilege separation.... Read more
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2020-8599
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit t... Read more
- Actively Exploited
- Published: Mar. 18, 2020
- Modified: Feb. 12, 2025
-
10.0
HIGHCVE-2015-6459
Absolute path traversal vulnerability in the download feature in FileDownloadServlet in GE Digital Energy MDS PulseNET and MDS PulseNET Enterprise before 3.1.5 allows remote attackers to read or delete arbitrary files via a full pathname.... Read more
Affected Products : mds_pulsenet- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-3544
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availa... Read more
Affected Products : ubuntu_linux jdk jre linux_enterprise_server jre jdk satellite_with_embedded_oracle linux_enterprise_java- Actively Exploited
- Published: Oct. 19, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-8598
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges.... Read more
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-3089
Use-after-free vulnerability in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving tables.... Read more
Affected Products : chrome- Published: May. 16, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0742
Buffer overflow in ZfHIPCND.exe in Novell ZENworks Handheld Management 7.0 allows remote attackers to execute arbitrary code via a crafted IP Conduit packet to TCP port 2400.... Read more
Affected Products : zenworks_handheld_management- Published: Feb. 02, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-6412
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.... Read more
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-0485
Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle speech data, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "stale pointer."... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0266
Buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long nameParams parameter, a different vulnerability than CVE-2011-0267.2.... Read more
Affected Products : openview_network_node_manager- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025