Latest CVE Feed
-
10.0
HIGHCVE-2004-0903
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments tha... Read more
- EPSS Score: %18.83
- Published: Jan. 27, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0628
Stack-based buffer overflow in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long scramble string.... Read more
Affected Products : mysql- EPSS Score: %6.38
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0521
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.... Read more
- EPSS Score: %6.14
- Published: Aug. 18, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-1015
Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.... Read more
- EPSS Score: %5.70
- Published: Jan. 10, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2004-0212
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Exp... Read more
- EPSS Score: %79.93
- Published: Aug. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0722
The default installation of sadmind on Solaris uses weak authentication (AUTH_SYS), which allows local and remote attackers to spoof Solstice AdminSuite clients and gain root privileges via a certain sequence of RPC packets.... Read more
Affected Products : solaris- EPSS Score: %89.40
- Published: Sep. 22, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0690
KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5... Read more
Affected Products : kde- EPSS Score: %2.08
- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0648
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.... Read more
- EPSS Score: %1.76
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %80.77
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3700
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.... Read more
Affected Products : database_server- EPSS Score: %3.61
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0609
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.... Read more
Affected Products : cfingerd- EPSS Score: %9.91
- Published: Aug. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0133
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET... Read more
Affected Products : interscan_viruswall- EPSS Score: %0.84
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0100
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more
Affected Products : bslist.cgi- EPSS Score: %18.80
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1077
Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.... Read more
Affected Products : iplanet_web_server- EPSS Score: %3.46
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0584
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.... Read more
- EPSS Score: %5.33
- Published: Jul. 02, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-1420
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.... Read more
- EPSS Score: %1.64
- Published: Jul. 20, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0937
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.... Read more
Affected Products :- EPSS Score: %2.01
- Published: Dec. 03, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0853
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.... Read more
- EPSS Score: %0.93
- Published: Dec. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0452
A service or application has a backdoor password that was placed there by the developer.... Read more
Affected Products :- EPSS Score: %0.48
- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.... Read more
Affected Products : sendmail- EPSS Score: %6.71
- Published: Jan. 01, 1997
- Modified: Apr. 03, 2025