Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2008-2362

    Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateCon... Read more

    Affected Products : x11
    • EPSS Score: %2.08
    • Published: Jun. 16, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-1100

    Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.... Read more

    Affected Products : clamav
    • EPSS Score: %16.52
    • Published: Apr. 14, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-0657

    Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstr... Read more

    Affected Products : jre jdk
    • EPSS Score: %1.77
    • Published: Feb. 07, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6047

    Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.... Read more

    • EPSS Score: %0.65
    • Published: Nov. 20, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6045

    Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.... Read more

    • EPSS Score: %1.00
    • Published: Nov. 20, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-2831

    Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel memo... Read more

    Affected Products : madwifi
    • EPSS Score: %2.09
    • Published: May. 24, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-2418

    Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that trigg... Read more

    Affected Products : trillian_pro
    • EPSS Score: %27.10
    • Published: May. 02, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5362

    Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 10.1.3.0.0 has unknown impact and remote attack vectors, aka Vuln# OC4J04.... Read more

    Affected Products : application_server
    • EPSS Score: %0.96
    • Published: Oct. 18, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5349

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07.... Read more

    Affected Products : http_server
    • EPSS Score: %0.96
    • Published: Oct. 18, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5156

    Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.... Read more

    • EPSS Score: %82.74
    • Published: Oct. 05, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-0992

    Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentall... Read more

    Affected Products : groupwise_messenger
    • EPSS Score: %88.81
    • Published: Apr. 14, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2012-3983

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute... Read more

    • EPSS Score: %0.77
    • Published: Oct. 10, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2006-0283

    Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize O... Read more

    • EPSS Score: %2.94
    • Published: Jan. 18, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-4837

    snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of service (crash) by causing a particular TCP disconnect, which triggers a fr... Read more

    Affected Products : net-snmp net-snmp
    • EPSS Score: %8.18
    • Published: Dec. 31, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-3666

    Multiple unspecified format string vulnerabilities in multiple unspecified implementations of Internet Key Exchange version 1 (IKEv1) have multiple unspecified attack vectors and impacts, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: d... Read more

    Affected Products : internet_key_exchange
    • EPSS Score: %0.75
    • Published: Nov. 18, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-3449

    Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) ... Read more

    Affected Products : application_server
    • EPSS Score: %1.63
    • Published: Nov. 02, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-1851

    A certain contributed script for ekg Gadu Gadu client 1.5 and earlier allows attackers to execute shell commands via unknown attack vectors.... Read more

    Affected Products : ekg
    • EPSS Score: %0.45
    • Published: Jul. 19, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-0441

    Multiple stack-based buffer overflows in Sybase Adaptive Server Enterprise (ASE) 12.x before 12.5.3 ESD#1 allow remote authenticated users to execute arbitrary code via the (1) attrib_valid function, (2) covert function, (3) declare statement, or (4) a cr... Read more

    Affected Products : adaptive_server_enterprise
    • EPSS Score: %21.28
    • Published: Dec. 22, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-2441

    Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."... Read more

    Affected Products : kerio_mailserver
    • EPSS Score: %0.43
    • Published: Dec. 31, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-2427

    Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to obtain sensitive information via direct requests to (1) admin/getparam.cgi, (2) admin/systemlog.cgi, (3) admin/serverreport.cgi, and (4) admin/paramlist.cg... Read more

    • EPSS Score: %4.75
    • Published: Dec. 31, 2004
    • Modified: Apr. 03, 2025
Showing 20 of 291005 Results