Latest CVE Feed
-
10.0
HIGHCVE-2020-3765
Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- EPSS Score: %2.56
- Published: Feb. 20, 2020
- Modified: May. 05, 2025
-
10.0
HIGHCVE-2000-0800
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.... Read more
Affected Products : suse_linux- EPSS Score: %2.88
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-3746
Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- EPSS Score: %4.38
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2000-0012
Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.... Read more
Affected Products : msql- EPSS Score: %4.58
- Published: Dec. 27, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-3743
Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- EPSS Score: %4.38
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-7279
The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.... Read more
- EPSS Score: %57.90
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-7235
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserial... Read more
- EPSS Score: %57.42
- Published: Oct. 07, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7192
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.... Read more
Affected Products : node.js- EPSS Score: %43.94
- Published: Dec. 11, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7249
Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, Cent... Read more
Affected Products : centrecom_ar415s_firmware centrecom_ar415s at-8624t\/2m_firmware at-8624t\/2m ar442s_firmware ar442s at-9924t_firmware at-9924t at-8848_firmware at-8848 +38 more products- EPSS Score: %8.45
- Published: Dec. 19, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7232
GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these password... Read more
- EPSS Score: %0.62
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-7169
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment... Read more
- Actively Exploited
- EPSS Score: %90.11
- Published: Sep. 25, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-3548
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applet... Read more
- EPSS Score: %2.42
- Published: Oct. 19, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-3554
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentialit... Read more
- EPSS Score: %2.86
- Published: Oct. 19, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-0063
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 5501... Read more
- EPSS Score: %7.59
- Published: Sep. 21, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-3692
u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, ... Read more
Affected Products : sdx55_firmware sm8150_firmware sm8250_firmware sxr2130_firmware qcs610_firmware sa415m_firmware sdx24_firmware qcm6125_firmware sc7180_firmware sc8180x_firmware +24 more products- EPSS Score: %0.36
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3686
Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon In... Read more
- EPSS Score: %0.14
- Published: Jan. 21, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-3525
Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.... Read more
Affected Products : traffic_server- EPSS Score: %1.27
- Published: Aug. 22, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-3175
Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in truetype/ttgload.c in FreeType and oth... Read more
Affected Products : chrome- EPSS Score: %2.03
- Published: Aug. 27, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2020-3633
Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon ... Read more
Affected Products : sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware apq8009_firmware msm8909w_firmware sdm429w_firmware +64 more products- EPSS Score: %0.33
- Published: Jun. 02, 2020
- Modified: Nov. 21, 2024