Latest CVE Feed
-
10.0
HIGHCVE-2017-8248
A buffer overflow may occur in the processing of a downlink NAS message in Qualcomm Telephony as used in Apple iPhone 5 and later, iPad 4th generation and later, iPod touch 6th generation.... Read more
Affected Products : iphone_os- EPSS Score: %2.38
- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5790
A remote deserialization of untrusted data vulnerability in HPE Intelligent Management Center (IMC) PLAT version 7.2 E0403P06 was found.... Read more
Affected Products : intelligent_management_center- EPSS Score: %42.75
- Published: Feb. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-1000082
systemd v233 and earlier fails to safely parse usernames starting with a numeric digit (e.g. "0day"), running the service in question with root privileges rather than the user intended.... Read more
Affected Products : systemd- EPSS Score: %0.56
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-5411
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.... Read more
- EPSS Score: %0.41
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-8480
The VideoFramePool::PoolImpl::CreateFrame function in media/base/video_frame_pool.cc in Google Chrome before 47.0.2526.73 does not initialize memory for a video-frame data structure, which might allow remote attackers to cause a denial of service (out-of-... Read more
Affected Products : chrome- EPSS Score: %0.79
- Published: Dec. 06, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2022-29464
Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../... Read more
- Actively Exploited
- EPSS Score: %94.43
- Published: Apr. 18, 2022
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2014-2955
Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.... Read more
- EPSS Score: %1.26
- Published: Jul. 14, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-2623
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : storage_data_protector- EPSS Score: %89.84
- Published: Jul. 18, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-4784
The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.... Read more
Affected Products : integrated_lights-out_bmc- EPSS Score: %60.68
- Published: Jul. 08, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-4161
The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 colo... Read more
Affected Products : laserjet_4250 laserjet_4350 laserjet_9040 laserjet_9050 color_laserjet_4700 color_laserjet_4730_mfp color_laserjet_5550 color_laserjet_9500 color_mfp_cm8060 laserjet_4240 +31 more products- EPSS Score: %9.57
- Published: Dec. 01, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0923
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."... Read more
Affected Products : data_protector- EPSS Score: %89.89
- Published: Feb. 09, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0888
Unspecified vulnerability in the Sun Ray Server Software component in Oracle Sun Product Suite 4.0, 4.1, and 4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Device Services.... Read more
Affected Products : sun_products_suite- EPSS Score: %3.08
- Published: Apr. 13, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-4462
Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.... Read more
- EPSS Score: %50.67
- Published: Dec. 30, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4294
Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.... Read more
Affected Products : ray_server_software- EPSS Score: %3.90
- Published: Dec. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6507
SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, which allows remote attackers to obtain "full file system access" and execut... Read more
- EPSS Score: %71.36
- Published: Dec. 20, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2004-0348
SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.... Read more
Affected Products : spidersales- EPSS Score: %0.56
- Published: Nov. 23, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-1121
Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary con... Read more
Affected Products : scriptlogic- EPSS Score: %4.96
- Published: Dec. 31, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0436
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.... Read more
- EPSS Score: %3.93
- Published: Jul. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0018
In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administra... Read more
- EPSS Score: %36.04
- Published: Mar. 08, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0800
String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.... Read more
Affected Products : suse_linux- EPSS Score: %2.88
- Published: Oct. 20, 2000
- Modified: Apr. 03, 2025