Latest CVE Feed
-
10.0
HIGHCVE-2011-0885
A certain Comcast Business Gateway configuration of the SMC SMCD3G-CCR with firmware before 1.4.0.49.2 has a default password of D0nt4g3tme for the mso account, which makes it easier for remote attackers to obtain administrative access via the (1) web int... Read more
- Published: Feb. 08, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0919
Multiple stack-based buffer overflows in the (1) POP3 and (2) IMAP services in IBM Lotus Domino allow remote attackers to execute arbitrary code via non-printable characters in an envelope sender address, aka SPR KLYH87LLVJ.... Read more
Affected Products : lotus_domino- Published: Feb. 08, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0814
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unk... Read more
- Published: Jun. 14, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0871
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affe... Read more
- Published: Jun. 14, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0802
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unk... Read more
- Published: Jun. 14, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-2051
The escapeshellcmd API function in PHP before 5.2.6 has unknown impact and context-dependent attack vectors related to "incomplete multibyte chars."... Read more
Affected Products : php- Published: May. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-15692
In Nim 1.2.4, the standard library browsers mishandles the URL argument to browsers.openDefaultBrowser. This argument can be a local file path that will be opened in the default explorer. An attacker can pass one argument to the underlying open command to... Read more
Affected Products : nim- Published: Aug. 14, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0732
Multiple unspecified vulnerabilities in IBM Tivoli Integrated Portal (TIP) 1.1.1.1, as used in IBM Tivoli Common Reporting (TCR) 1.2.0 before Interim Fix 9, have unknown impact and attack vectors, related to "security vulnerabilities of Websphere Applicat... Read more
- Published: Feb. 01, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-15607
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When p... Read more
Affected Products : webpanel- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15609
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When pa... Read more
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15615
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_ftp_manager.php. The i... Read more
Affected Products : webpanel- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15611
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When pa... Read more
Affected Products : webpanel- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12754
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the curren... Read more
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-15608
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_dashboard.php. When pa... Read more
Affected Products : webpanel- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0647
The irccd.exe service in EMC Replication Manager Client before 5.3 and NetWorker Module for Microsoft Applications 2.1.x and 2.2.x allows remote attackers to execute arbitrary commands via the RunProgram function to TCP port 6542.... Read more
- Published: Feb. 10, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0661
The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remot... Read more
Affected Products : windows_7 windows_server_2008 windows_2003_server windows_server_2003 windows_vista windows_xp- Published: Apr. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-15568
TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for exam... Read more
- Published: Jan. 30, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-0432
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote attackers to have an unspecified impact via unknown vectors.... Read more
- Published: Dec. 25, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-16039
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a... Read more
- Published: Jan. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0471
The node-iteration implementation in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 does not properly handle pointers, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vect... Read more
- Published: Jan. 14, 2011
- Modified: Apr. 11, 2025