Latest CVE Feed
-
10.0
HIGHCVE-2008-2811
The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display... Read more
- EPSS Score: %26.86
- Published: Jul. 07, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-2403
Multiple directory traversal vulnerabilities in unspecified ASP applications in Sun Java Active Server Pages (ASP) Server before 4.0.3 allow remote attackers to read or delete arbitrary files via a .. (dot dot) in the Path parameter to the MapPath method.... Read more
Affected Products : java_asp_server- EPSS Score: %1.00
- Published: Jun. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-1842
Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins w... Read more
Affected Products : openview_network_node_manager- EPSS Score: %34.11
- Published: Apr. 16, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0102
Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."... Read more
Affected Products : publisher- EPSS Score: %59.61
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-5580
Buffer overflow in a certain driver in Cisco Security Agent 4.5.1 before 4.5.1.672, 5.0 before 5.0.0.225, 5.1 before 5.1.0.106, and 5.2 before 5.2.0.238 on Windows allows remote attackers to execute arbitrary code via a crafted SMB packet in a TCP session... Read more
Affected Products : security_agent- EPSS Score: %16.47
- Published: Dec. 15, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-4880
Buffer overflow in the Client Acceptor Daemon (CAD), dsmcad.exe, in certain IBM Tivoli Storage Manager (TSM) clients 5.1 before 5.1.8.1, 5.2 before 5.2.5.2, 5.3 before 5.3.5.3, and 5.4 before 5.4.1.2 allows remote attackers to execute arbitrary code via c... Read more
Affected Products : tivoli_storage_manager_client- EPSS Score: %88.94
- Published: Sep. 28, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-1071
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %5.72
- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2007-1674
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.... Read more
Affected Products : landesk_management_suite- EPSS Score: %72.56
- Published: Apr. 18, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-1063
The SSH server in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier, uses a hard-coded username and password, which allows remote attackers to access the device.... Read more
Affected Products : unified_ip_phone_7911g unified_ip_phone_7941g unified_ip_phone_7961g unified_ip_phone_7970g unified_ip_phone_firmware_7906g unified_ip_phone_firmware_7911g unified_ip_phone_firmware_7941g unified_ip_phone_firmware_7961g unified_ip_phone_firmware_7970g unified_ip_phone_firmware_7971g +2 more products- EPSS Score: %2.76
- Published: Feb. 22, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-0749
Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTS... Read more
- EPSS Score: %19.69
- Published: May. 13, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-6841
Certain forms in phpBB before 2.0.22 lack session checks, which has unknown impact and remote attack vectors.... Read more
- EPSS Score: %0.43
- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-6299
Integer overflow in Msg.dll in Novell ZENworks 7 Asset Management (ZAM) before SP1 IR11 and the Collection client allows remote attackers to execute arbitrary code via crafted packets, which trigger a heap-based buffer overflow.... Read more
Affected Products : zenworks_asset_management- EPSS Score: %13.89
- Published: Dec. 05, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-5359
Multiple unspecified vulnerabilities in Oracle Reports Developer component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Oracle E-Business Suite and Applications 11.5.10CU2, have unknown impact and remote attack vectors, aka Vuln# (1) REP01 and... Read more
- EPSS Score: %2.46
- Published: Oct. 18, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4950
Cisco IOS 12.2 through 12.4 before 20060920, as used by Cisco IAD2430, IAD2431, and IAD2432 Integrated Access Devices, the VG224 Analog Phone Gateway, and the MWR 1900 and 1941 Mobile Wireless Edge Routers, is incorrectly identified as supporting DOCSIS, ... Read more
Affected Products : ios- EPSS Score: %3.39
- Published: Sep. 23, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1875
Unspecified vulnerability in Oracle Database Server 9.0.1.5, 9.2.0.7, and 10.1.0.5 has unknown impact and attack vectors in the Oracle Spatial component, aka Vuln# DB11. NOTE: Oracle has not disputed reliable researcher claims that this issue is SQL inje... Read more
Affected Products : database_server- EPSS Score: %1.29
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-0289
Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Develope... Read more
- EPSS Score: %2.56
- Published: Jan. 18, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2668
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %82.85
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2659
Buffer overflow in the LZX decompression in CHM Lib (chmlib) 0.35, as used in products such as KchmViewer, has unknown impact and attack vectors.... Read more
Affected Products : chm_lib- EPSS Score: %1.00
- Published: Nov. 16, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-2122
Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Sub... Read more
- EPSS Score: %65.56
- Published: Oct. 21, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2005-0519
ArGoSoft FTP Server before 1.4.2.7 allows remote attackers to read arbitrary files by uploading a ZIP file containing a shortcut (.LNK) file, using SITE UNZIP to extract the .LNK file onto the server, then accessing the file, a different vulnerability tha... Read more
Affected Products : ftp_server- EPSS Score: %1.19
- Published: Feb. 18, 2005
- Modified: Apr. 03, 2025