Latest CVE Feed
-
10.0
HIGHCVE-2009-1120
EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where the vulnerability is caused by an error when the rep_sr... Read more
Affected Products : emc_replistor- Published: Jan. 15, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1174
The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 and 7.0 before 7.0.0.3 has an unspecified "security problem" in the XML digital-signature specification, which has unknown impact and attack vectors.... Read more
Affected Products : websphere_application_server- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1057
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that triggers memory corruption, related to a "format string buffer overflow." NOTE: CVE has not investigated whether the specified file.zip fi... Read more
Affected Products : zipitfast\!- Published: Mar. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1176
mapserv.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 does not ensure that the string holding the id parameter ends in a '\0' character, which allows remote attackers to conduct buffer-overflow attacks or have unspecified other impact v... Read more
- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1048
The web interface on the snom VoIP phones snom 300, snom 320, snom 360, snom 370, and snom 820 with firmware 6.5 before 6.5.20, 7.1 before 7.1.39, and 7.3 before 7.3.14 allows remote attackers to bypass authentication, and reconfigure the phone or make ar... Read more
- Published: Aug. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1058
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file that triggers an SEH overwrite. NOTE: it is possible that this overlaps CVE-2005-3317. NOTE: CVE has not investigated whether the spec... Read more
Affected Products : zipgenius- Published: Mar. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0939
Tor before 0.2.0.34 treats incomplete IPv4 addresses as valid, which has unknown impact and attack vectors related to "Spec conformance," as demonstrated using 192.168.0.... Read more
- Published: Mar. 18, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0921
Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.d... Read more
- Published: Mar. 25, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1043
Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.... Read more
- Published: Mar. 23, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0869
Buffer overflow in the client in IBM Tivoli Storage Manager (TSM) HSM 5.3.2.0 through 5.3.5.0, 5.4.0.0 through 5.4.2.5, and 5.5.0.0 through 5.5.1.4 on Windows allows remote attackers to cause a denial of service (application crash) or possibly execute arb... Read more
- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0898
Stack-based buffer overflow in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted HTTP request.... Read more
Affected Products : openview_network_node_manager- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0894
Heap-based buffer overflow in the decoder_create function in the initialization functionality in xvidcore/src/decoder.c in Xvid before 1.2.2, as used by Windows Media Player and other applications, allows remote attackers to execute arbitrary code via vec... Read more
Affected Products : xvid- Published: Jun. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0836
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmation before performing dangerous actions defined in a PDF file, which allows remote attackers to execute arbitrary programs and have unspe... Read more
Affected Products : reader- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0895
Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.... Read more
Affected Products : edirectory- Published: Dec. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0773
The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-... Read more
- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0721
Unspecified vulnerability in Easy Login in the Sender module in HP Remote Graphics Software (RGS) 4.0.0 through 5.2.4 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : remote_graphics_software- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0893
Multiple heap-based buffer overflows in xvidcore/src/decoder.c in the xvidcore library in Xvid before 1.2.2, as used by Windows Media Player and other applications, allow remote attackers to execute arbitrary code by providing a crafted macroblock (aka MB... Read more
Affected Products : xvid- Published: Jun. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0616
Cisco Application Networking Manager (ANM) before 2.0 uses default usernames and passwords, which makes it easier for remote attackers to access the application, or cause a denial of service via configuration changes, related to "default user credentials ... Read more
Affected Products : application_networking_manager- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0568
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory l... Read more
Affected Products : windows_server_2008 windows_2000 windows_2003_server windows_vista windows_xp windows_server- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0621
Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device management, which makes it easier for remote attackers to perform configuration ch... Read more
Affected Products : ace_4710- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025