Latest CVE Feed
-
10.0
HIGHCVE-2010-1552
Stack-based buffer overflow in the doLoad function in snmpviewer.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via the act and app parameters.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %82.08
- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0445
Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.... Read more
Affected Products : network_node_manager- EPSS Score: %1.88
- Published: Feb. 11, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0138
Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA Gener... Read more
- EPSS Score: %10.86
- Published: Jan. 21, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-4178
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Topic parameter.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %86.10
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4124
Heap-based buffer overflow in the rb_str_justify function in string.c in Ruby 1.9.1 before 1.9.1-p376 allows context-dependent attackers to execute arbitrary code via unspecified vectors involving (1) String#ljust, (2) String#center, or (3) String#rjust. ... Read more
Affected Products : ruby- EPSS Score: %2.05
- Published: Dec. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4012
Multiple integer overflows in LibThai before 0.1.13 might allow context-dependent attackers to execute arbitrary code via long strings that trigger heap-based buffer overflows, related to (1) thbrk/thbrk.c and (2) thwbrk/thwbrk.c. NOTE: some of these det... Read more
Affected Products : libthai- EPSS Score: %2.26
- Published: Jan. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-3854
Buffer overflow in the traditional client scheduler in the client in IBM Tivoli Storage Manager (TSM) 5.3 before 5.3.6.7 and 5.4 before 5.4.2 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %10.70
- Published: Nov. 04, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3710
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel, which allows remote attackers to gain privileges via port 8022.... Read more
Affected Products : rios- EPSS Score: %2.78
- Published: Oct. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2853
Wordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-form-advanced.php, (4) edit-form-comment.php, (5) edit-link-category-form.php, (6) edit-link-form.php, (7)... Read more
Affected Products : wordpress- EPSS Score: %1.35
- Published: Aug. 18, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2459
Multiple unspecified vulnerabilities in mimeTeX, when downloaded before 20090713, have unknown impact and attack vectors related to the (1) \environ, (2) \input, and (3) \counter TeX directives.... Read more
Affected Products : mimetex- EPSS Score: %0.47
- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1979
Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained fro... Read more
Affected Products : database_server- EPSS Score: %85.75
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1571
Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt... Read more
- EPSS Score: %7.86
- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-7251
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.... Read more
Affected Products : phpmyadmin- EPSS Score: %2.40
- Published: Jan. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-5340
Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access loc... Read more
- EPSS Score: %4.01
- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5052
The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigg... Read more
- EPSS Score: %23.01
- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4237
Managed Client in Apple Mac OS X before 10.5.6 sometimes misidentifies a system when installing per-host configuration settings, which allows context-dependent attackers to have an unspecified impact by leveraging unintended settings, as demonstrated by t... Read more
- EPSS Score: %0.52
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4226
Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.... Read more
Affected Products : libxml- EPSS Score: %3.82
- Published: Nov. 25, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-3693
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMw... Read more
- EPSS Score: %1.24
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-3692
Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMw... Read more
- EPSS Score: %1.24
- Published: Sep. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-3113
Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.... Read more
- EPSS Score: %22.99
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025