Latest CVE Feed
-
10.0
HIGHCVE-2006-5370
Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10CU2 have unknown impact and remote authenticated attack vectors, aka Vuln# (1) APPS06 for Oracle CRM Gateway for Mobile Devices and (2) APPS08 for Oracle iStore.... Read more
Affected Products : e-business_suite- EPSS Score: %2.75
- Published: Oct. 18, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-3893
Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML ... Read more
- EPSS Score: %19.92
- Published: Dec. 04, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-2137
Heap-based buffer overflow in kde.dll in IBM Tivoli Monitoring Express 6.1.0 before Fix Pack 2, as used in Tivoli Universal Agent, Windows OS Monitoring agent, and Enterprise Portal Server, allows remote attackers to execute arbitrary code by sending a lo... Read more
Affected Products : tivoli_monitoring_express- EPSS Score: %27.54
- Published: Apr. 22, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-3500
Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.... Read more
Affected Products : xeforum- EPSS Score: %0.84
- Published: Jun. 29, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-3624
Heap-based buffer overflow in the Message HTTP Server in SAP Message Server allows remote attackers to execute arbitrary code via a long string in the group parameter to /msgserver/html/group.... Read more
Affected Products : sap_message_server- EPSS Score: %65.41
- Published: Jul. 09, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-4121
Multiple SQL injection vulnerabilities in admin.aspx in E-Commerce Scripts Shopping Cart Script, Multi-Vendor E-Shop Script, and Auction Script allow remote attackers to execute arbitrary SQL commands via the (1) EmailAdd (Username) and (2) Pass (password... Read more
- EPSS Score: %1.16
- Published: Aug. 01, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6638
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, passwords, device names, and IP addresses via a direct request for scripts/logfiles.tar.gz.... Read more
Affected Products : 3204_dvr- EPSS Score: %8.25
- Published: Jan. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4429
Unspecified vulnerability in SOURCENEXT Virus Security ZERO 9.5.0173 and earlier and Virus Security 9.5.0173 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via malformed compressed files. NOTE: ... Read more
- EPSS Score: %2.51
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4801
Heap-based buffer overflow in the Data Protection for SQL CAD service (aka dsmcat.exe) in the Client Acceptor Daemon (CAD) and the scheduler in the Backup-Archive client 5.1.0.0 through 5.1.8.1, 5.2.0.0 through 5.2.5.2, 5.3.0.0 through 5.3.6.1, 5.4.0.0 th... Read more
Affected Products : tivoli_storage_manager tivoli_storage_manager_client tivoli_storage_manager_express- EPSS Score: %33.61
- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5284
The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other versions before 5.0.52, Air Marshal 2.0.4 and other versions before 2.0.8, and Radius test client (aka Radlogin) 4.0.20 and earlier, allo... Read more
- EPSS Score: %11.41
- Published: Nov. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1012
Unspecified vulnerability in the plug-ins for Apache and IIS web servers in Oracle BEA WebLogic Server 7.0 Gold through SP7, 8.1 Gold through SP6, 9.0, 9.1, 9.2 Gold through MP3, 10.0 Gold through MP1, and 10.3 allows remote attackers to affect confidenti... Read more
Affected Products : bea_product_suite- EPSS Score: %7.14
- Published: Apr. 15, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-7164
Multiple unspecified vulnerabilities in Shareaza before 2.3.1.0 have unknown impact and attack vectors related to "very important security fixes," possibly involving update notifications and a domain that is no longer controlled by the vendor.... Read more
Affected Products : shareaza- EPSS Score: %0.43
- Published: Sep. 04, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-7173
The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remote attackers to cause a denial of service (physical damage), modify coffee settings, and possibly execute c... Read more
- EPSS Score: %12.59
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-7200
Double free vulnerability in Deliantra server engine before 2.4 has unknown impact and attack vectors.... Read more
Affected Products : deliantra- EPSS Score: %0.34
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3843
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.... Read more
Affected Products : operations_manager- EPSS Score: %86.83
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-4514
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authenticatio... Read more
Affected Products : wincc wincc_flexible simatic_hmi_panels wincc_runtime_advanced wincc_flexible_runtime- EPSS Score: %0.55
- Published: Feb. 03, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1805
Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters.... Read more
- EPSS Score: %7.58
- Published: Apr. 13, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-6392
Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc7... Read more
- EPSS Score: %4.18
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4610
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.... Read more
- EPSS Score: %0.32
- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4937
Multiple unspecified vulnerabilities in the AiCloud feature on the ASUS RT-AC66U, RT-N66U, RT-N65U, RT-N14U, RT-N16, RT-N56U, and DSL-N55U with firmware before 3.0.4.372 have unknown impact and attack vectors.... Read more
Affected Products : rt-ac66u_firmware rt-n56u_firmware rt-n14u_firmware rt-n16_firmware rt-n65u_firmware rt-n66u_firmware rt-n66u rt-n56u rt-ac66u rt-n65u +4 more products- EPSS Score: %0.53
- Published: Jul. 26, 2013
- Modified: Apr. 11, 2025