Latest CVE Feed
-
10.0
HIGHCVE-2016-2554
Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive.... Read more
Affected Products : php- EPSS Score: %16.57
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2804
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %1.20
- Published: Apr. 30, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0543
Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Co... Read more
- EPSS Score: %0.78
- Published: Aug. 12, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4350
Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule p... Read more
Affected Products : storage_resource_monitor- EPSS Score: %47.63
- Published: May. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-0401
Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary c... Read more
Affected Products : tivoli_provisioning_manager_os_deployment- EPSS Score: %28.52
- Published: Jan. 23, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0386
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.... Read more
- EPSS Score: %34.06
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2015-0301
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe... Read more
Affected Products : linux_kernel flash_player mac_os_x windows adobe_air adobe_air_sdk adobe_air_sdk_and_compiler- EPSS Score: %7.40
- Published: Jan. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6944
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more
- EPSS Score: %1.97
- Published: Oct. 13, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6998
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %2.24
- Published: Oct. 13, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7019
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %5.86
- Published: Oct. 13, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7406
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.... Read more
Affected Products : dropbear_ssh- EPSS Score: %10.35
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2004-0623
Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.... Read more
Affected Products : gnats- EPSS Score: %3.45
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-3107
Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an u... Read more
- EPSS Score: %14.53
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-3108
Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to fo... Read more
- EPSS Score: %10.64
- Published: Jul. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2015-3039
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more
- EPSS Score: %8.70
- Published: Apr. 14, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4477
Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.... Read more
- EPSS Score: %4.96
- Published: Aug. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2017-0561
A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the conte... Read more
- EPSS Score: %44.37
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-5589
The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmenta... Read more
Affected Products : php- EPSS Score: %8.49
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2004-0897
The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- EPSS Score: %55.01
- Published: Jan. 11, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-1695
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
- EPSS Score: %1.44
- Published: May. 03, 2012
- Modified: Apr. 11, 2025