Latest CVE Feed
-
10.0
HIGHCVE-2012-2974
The web interface on the SMC SMC8024L2 switch allows remote attackers to bypass authentication and obtain administrative access via a direct request to a .html file under (1) status/, (2) system/, (3) ports/, (4) trunks/, (5) vlans/, (6) qos/, (7) rstp/, ... Read more
Affected Products : smc8024l2_switch- Published: Jul. 19, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2953
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.... Read more
Affected Products : web_gateway- Published: Jul. 23, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2949
The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows remote attackers to gain privileges via a crafted application.... Read more
- Published: May. 29, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2802
Unspecified vulnerability in the ac3_decode_frame function in libavcodec/ac3dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "number of output channels" and "out of array writes."... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2792
Unspecified vulnerability in the decode_init function in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to the samples per frame.... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2791
Multiple unspecified vulnerabilities in the (1) decode_band_hdr function in indeo4.c and (2) ff_ivi_decode_blocks function in ivi_common.c in libavcodec/ in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.5, have unknown impact and a... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2796
Unspecified vulnerability in the vc1_decode_frame function in libavcodec/vc1dec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to inconsistencies in "coded slice positions and interlacing" that trigger ... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2795
Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors related to (1) size of "mclms arrays," (2) "a get_bits(0) in decode_ac_filter," and (3) "too many bits in decode_channel_resid... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2799
Unspecified vulnerability in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to the "put bit buffer when num_saved_bits is reset."... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2786
Unspecified vulnerability in the decode_wdlt function in libavcodec/dfa.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array write."... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2787
Unspecified vulnerability in the decode_frame function in libavcodec/indeo4.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.4 has unknown impact and attack vectors, related to the "setup width/height."... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2750
Unspecified vulnerability in MySQL 5.5.x before 5.5.23 has unknown impact and attack vectors related to a "Security Fix", aka Bug #59533. NOTE: this might be a duplicate of CVE-2012-1689, but as of 20120816, Oracle has not commented on this possibility.... Read more
- Published: Aug. 17, 2012
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2024-43102
Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object representing the mapping too many times, causing it to be freed too early. A... Read more
Affected Products : freebsd- Published: Sep. 05, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-2797
Unspecified vulnerability in the decode_frame_mp3on4 function in libavcodec/mpegaudiodec.c in FFmpeg before 0.11 and Libav 0.8.x before 0.8.5 has unknown impact and attack vectors related to a calculation that prevents a frame from being "large enough."... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-1852
Multiple stack-based buffer overflows in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allow remote attackers to execute arbitrary code via crafted packet content accompanying a (1) DATA or (2) ERROR opcode.... Read more
Affected Products : intelligent_management_center- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2788
Unspecified vulnerability in the avi_read_packet function in libavformat/avidec.c in FFmpeg before 0.11, and Libav 0.7.x before 0.7.7 and 0.8.x before 0.8.4, has unknown impact and attack vectors, related to an "out of array read" when a "packet is shrunk... Read more
- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2561
HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component via a crafted request to TCP port 1098, 1099, or 44... Read more
Affected Products : business_service_management- Published: May. 21, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2576
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginN... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2011-2457
Stack-based buffer overflow in Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code via un... Read more
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2399
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager 1.1 and earlier, and other products allows remote attackers to inject arbitrary web script or HTML via the... Read more
Affected Products : wordpress- Published: Apr. 21, 2012
- Modified: Apr. 11, 2025