Latest CVE Feed
-
10.0
HIGHCVE-2008-5982
Format string vulnerability in BMC PATROL Agent before 3.7.30 allows remote attackers to execute arbitrary code via format string specifiers in an invalid version number to TCP port 3181, which are not properly handled when writing a log message.... Read more
Affected Products : patrol_agent- Published: Jan. 27, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5963
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remote attackers to execute arbitrary PHP code via the objectname parameter.... Read more
Affected Products : gravity-gtd- Published: Jan. 23, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5848
The Advantech ADAM-6000 module has 00000000 as its default password, which makes it easier for remote attackers to obtain access through an HTTP session, and (1) monitor or (2) control the module's Modbus/TCP I/O activity.... Read more
Affected Products : adam-6015 adam-6017 adam-6018 adam-6022 adam-6024 adam-6050 adam-6050w adam-6051 adam-6051w adam-6052 +4 more products- Published: Jan. 06, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5722
Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long SAWSTUDIO PREFERENCES STRUCT value in a .prf (preferences) file.... Read more
Affected Products : sawstudio- Published: Dec. 26, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5685
Sun ScApp firmware 5.18.x, 5.19.x, and 5.20.0 through 5.20.10 on Sun Fire and Netra platforms allows remote attackers to access the System Controller (SC), the system console, and possibly the host OS, and cause a denial of service (shutdown or reboot), v... Read more
- Published: Dec. 19, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5649
SQL injection vulnerability in admin/admin.php in AlstraSoft Article Manager Pro 1.6 allows remote attackers to execute arbitrary SQL commands via the username parameter.... Read more
Affected Products : article_manager_pro- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5619
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail) 0.2-1.alpha and 0.2-3.beta, Mahara, and AtMail Open 1.03, allows remote attackers to execute arbitrary code via crafted input that is ... Read more
- Published: Dec. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5448
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5444 and CVE-2008-... Read more
Affected Products : secure_backup- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-1597
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. Ther... Read more
- Published: Feb. 19, 2024
- Modified: Jun. 12, 2025
-
10.0
HIGHCVE-2008-5444
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5448 and CVE-2008-... Read more
Affected Products : secure_backup- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5412
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs. NOTE: this is probably a duplicate of CVE-2009-0438.... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5419
Stack-based buffer overflow in SAN Manager Master Agent service (aka msragent.exe) in EMC Control Center 5.2 SP5 and 6.0 allows remote attackers to execute arbitrary code via multiple SST_CTGTRANS requests.... Read more
Affected Products : control_center- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5403
Heap-based buffer overflow in the XML parser in the AIM plugin in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a malformed XML tag.... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5402
Double free vulnerability in the XML parser in Trillian before 3.1.12.0 allows remote attackers to execute arbitrary code via a crafted XML expression, related to the "IMG SRC ID."... Read more
- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5404
Insecure method vulnerability in the FlexCell.Grid ActiveX control in FlexCell.ocx 5.7.0.1 in FlexCell Grid ActiveX Component allows remote attackers to create and overwrite arbitrary files via the HttpDownloadFile method. NOTE: this could be leveraged f... Read more
Affected Products : flexcell_grid_control- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5449
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2008-5444 and CVE-2008-... Read more
Affected Products : secure_backup- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5353
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote a... Read more
- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5332
Multiple PHP remote file inclusion vulnerabilities in Pie 0.5.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib parameter to files in lib/action/ including (a) alias.php, (b) cancel.php, (c) context.php, (d) deadlinks.php, (e... Read more
Affected Products : pie- Published: Dec. 05, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5305
Eval injection vulnerability in TWiki before 4.2.4 allows remote attackers to execute arbitrary Perl code via the %SEARCH{}% variable.... Read more
Affected Products : twiki- Published: Dec. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5227
Unspecified vulnerability in PHPCow allows remote attackers to execute arbitrary code via unknown vectors, related to a "file inclusion vulnerability," as exploited in the wild in November 2008.... Read more
Affected Products : phpcow- Published: Nov. 25, 2008
- Modified: Apr. 09, 2025