Latest CVE Feed
-
10.0
HIGHCVE-2009-2317
The Axesstel MV 410R has a certain default administrator password, and does not force a password change, which makes it easier for remote attackers to obtain access.... Read more
Affected Products : mv_410r- EPSS Score: %0.88
- Published: Jul. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2300
The management interface in the phion airlock Web Application Firewall (WAF) 4.1-10.41 does not properly handle CGI requests that specify large width and height parameters for an image, which allows remote attackers to execute arbitrary commands or cause ... Read more
Affected Products : airlock_web_application_firewall- EPSS Score: %1.71
- Published: Jul. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2227
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrary code via a crafted request to TCP port 19810.... Read more
Affected Products : bopup_communication_server- EPSS Score: %72.38
- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2271
The Huawei D100 has (1) a certain default administrator password for the web interface, and does not force a password change; and has (2) a default password of admin for the admin account in the telnet interface; which makes it easier for remote attackers... Read more
Affected Products : d100- EPSS Score: %0.34
- Published: Jul. 01, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2296
The NFSv4 server kernel module in Sun Solaris 10, and OpenSolaris before snv_119, does not properly implement the nfs_portmon setting, which allows remote attackers to access shares, and read, create, and modify arbitrary files, via unspecified vectors.... Read more
- EPSS Score: %4.56
- Published: Jul. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2193
Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet.... Read more
- EPSS Score: %24.77
- Published: Aug. 06, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2204
Unspecified vulnerability in the CoreTelephony component in Apple iPhone OS before 3.0.1 allows remote attackers to execute arbitrary code, obtain GPS coordinates, or enable the microphone via an SMS message that triggers memory corruption, as demonstrate... Read more
Affected Products : iphone_os- EPSS Score: %18.69
- Published: Aug. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2030
Unspecified vulnerability in the XML Digital Signature verification functionality in JVA-RUN in JDK 6.0 in IBM OS/400 i5/OS V5R4M0 and V6R1M0 has unknown impact and attack vectors related to "XML SECURITY PATCH."... Read more
- EPSS Score: %0.78
- Published: Jun. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2038
Unspecified vulnerability in the Finnish Bank Payment module 2.2 for osCommerce has unknown impact and attack vectors related to bank charges.... Read more
- EPSS Score: %0.47
- Published: Jun. 12, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2039
Unspecified vulnerability in the Luottokunta module before 1.3 for osCommerce has unknown impact and attack vectors related to orders.... Read more
- EPSS Score: %0.42
- Published: Jun. 12, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1916
dig.php in GScripts.net DNS Tools allows remote attackers to execute arbitrary commands via shell metacharacters in the ns parameter.... Read more
Affected Products : dns_tools- EPSS Score: %4.68
- Published: Jun. 04, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1943
Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers to execute arbitrary code via a long request to UDP port 62514.... Read more
- EPSS Score: %64.25
- Published: Jun. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1918
Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not pr... Read more
Affected Products : windows_server_2008 internet_explorer windows_2000 windows_server_2003 windows_vista windows_xp- EPSS Score: %62.48
- Published: Jul. 29, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1783
Multiple FRISK Software F-Prot anti-virus products, including Antivirus for Exchange, Linux on IBM zSeries, Linux x86 File Servers, Linux x86 Mail Servers, Linux x86 Workstations, Solaris Mail Servers, Antivirus for Windows, and others, allow remote attac... Read more
- EPSS Score: %0.41
- Published: May. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1784
The AVG parsing engine 8.5 323, as used in multiple AVG anti-virus products including Anti-Virus Network Edition, Internet Security Netzwerk Edition, Server Edition für Linux/FreeBSD, Anti-Virus SBS Edition, and others allows remote attackers to bypass ma... Read more
Affected Products : avg_anti-virus- EPSS Score: %0.44
- Published: May. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1669
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the equation attribute of the math function. NOTE: some of these details are... Read more
Affected Products : smarty- EPSS Score: %19.48
- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1611
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long 257 reply to a CWD command.... Read more
Affected Products : 32bit_ftp- EPSS Score: %10.78
- Published: May. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1656
Xerox WorkCentre and WorkCentre Pro 232, 238, 245, 255, 265, 275; and WorkCentre 5632, 5638, 5645, 5655, 5665, 5675, 5687, 7655, 7656, and 7675 allows remote attackers to execute arbitrary commands via unknown attack vectors, aka "command injection vulner... Read more
Affected Products : workcentre- EPSS Score: %6.94
- Published: May. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1477
The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt htt... Read more
- EPSS Score: %0.82
- Published: May. 27, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1520
Buffer overflow in the Web GUI in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, 5.4.0.0 through 5.4.2.6, and 5.5.0.0 through 5.5.1.17 allows attackers to cause a denial of service (a... Read more
- EPSS Score: %1.15
- Published: May. 05, 2009
- Modified: Apr. 09, 2025