Latest CVE Feed
-
10.0
HIGHCVE-2018-17067
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.... Read more
- EPSS Score: %0.70
- Published: Sep. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0968
Stack-based buffer overflow in SMB_Logon_Server of the rlm_smb experimental module for FreeRADIUS 0.9.3 and earlier allows remote attackers to execute arbitrary code via a long User-Password attribute.... Read more
Affected Products : freeradius- EPSS Score: %2.54
- Published: Dec. 15, 2003
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2022-31125
Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted... Read more
Affected Products : roxy-wi- EPSS Score: %12.86
- Published: Jul. 06, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-2639
Directory traversal vulnerability in TFTPdWin 0.4.2 allows remote attackers to read or modify arbitrary files outside the TFTP root via unspecified vectors.... Read more
Affected Products : tftp_server_tftpdwin- EPSS Score: %3.22
- Published: May. 13, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2001-1481
Xitami 2.4 through 2.5 b4 stores the Administrator password in plaintext in the default.aut file, whose default permissions are world-readable, which allows remote attackers to gain privileges.... Read more
Affected Products : xitami- EPSS Score: %1.70
- Published: Dec. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-2365
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.... Read more
Affected Products : simple_wais- EPSS Score: %1.59
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of its input parameters was not validated. A remote attacker could use this flaw to bypass authentication and execute arbitrary commands ... Read more
Affected Products : unitrends_backup- EPSS Score: %71.00
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2010-4597
Stack-based buffer overflow in the save method in the IntegraXor.Project ActiveX control in igcomm.dll in Ecava IntegraXor Human-Machine Interface (HMI) before 3.5.3900.10 allows remote attackers to execute arbitrary code via a long string in the second a... Read more
Affected Products : integraxor- EPSS Score: %43.40
- Published: Dec. 23, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2833
Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to improper management of ownership relationships in... Read more
- EPSS Score: %1.36
- Published: Apr. 16, 2013
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2018-1722
IBM Security Access Manager Appliance 9.0.4.0 and 9.0.5.0 could allow remote code execution when Advanced Access Control or Federation services are running. IBM X-Force ID: 147370.... Read more
Affected Products : security_access_manager- EPSS Score: %31.96
- Published: Aug. 24, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-2711
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.... Read more
Affected Products : tinyidentd- EPSS Score: %79.23
- Published: May. 16, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2015-9008
An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384689.... Read more
Affected Products : android- EPSS Score: %0.58
- Published: Apr. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-9035
In all Qualcomm products with Android releases from CAF using the Linux kernel, a memory buffer fails to be freed after it is no longer needed potentially resulting in memory exhaustion.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9036
In all Qualcomm products with Android releases from CAF using the Linux kernel, an incorrect length is used to clear a memory buffer resulting in adjacent memory getting corrupted.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9037
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read may occur in the processing of a downlink 3G NAS message.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2002-1699
SQL injection vulnerability in ASP Client Check (ASPCC) 1.3 and 1.5 allows remote attackers to bypass authentication and gain unauthorized access via the password field.... Read more
Affected Products : asp_client_check- EPSS Score: %1.87
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-2153
Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.... Read more
Affected Products : real_estate_management_software- EPSS Score: %0.48
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1760
The default installation of Cisco voice products, when running the IBM Director Agent on IBM servers before OS 2000.2.6, does not require authentication, which allows remote attackers to gain administrator privileges by connecting to TCP port 14247.... Read more
- EPSS Score: %6.12
- Published: Jan. 21, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2015-9147
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9625, MDM9635M, SD 400, and SD 800, userspace-provided pointer arguments are not validated.... Read more
Affected Products : android mdm9635m_firmware mdm9625_firmware sd_800_firmware sd_400_firmware mdm9625 mdm9635m sd_400 sd_800- EPSS Score: %0.22
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-9149
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD ... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware mdm9650_firmware mdm9206_firmware sd_410_firmware sd_412_firmware sd_210_firmware +42 more products- EPSS Score: %0.19
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024