Latest CVE Feed
-
10.0
HIGHCVE-2008-5038
Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence ... Read more
Affected Products : edirectory- Published: Nov. 12, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5060
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the DIR parameter to (1) export_batch.inc.php, (2) run_auto_suspend.cron.php, and (3) send_email_cache.php i... Read more
Affected Products : modernbill- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5045
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to cause a denial of service (crash) via a 200 server response that is exactly 1024 characters long.... Read more
Affected Products : ftp_now- Published: Nov. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5031
Multiple integer overflows in Python 2.2.3 through 2.5.1, and 2.6, allow context-dependent attackers to have an unknown impact via a large integer value in the tabsize argument to the expandtabs method, as implemented by (1) the string_expandtabs function... Read more
Affected Products : python- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4868
Unspecified vulnerability in the avcodec_close function in libavcodec/utils.c in FFmpeg 0.4.9 before r14787, as used by MPlayer, has unknown impact and attack vectors, related to a free "on random pointers."... Read more
- Published: Nov. 01, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4910
The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a file:// URL argument to the showDocument method.... Read more
Affected Products : java_web_start- Published: Nov. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-5005
Multiple stack-based buffer overflows in (1) University of Washington IMAP Toolkit 2002 through 2007c, (2) University of Washington Alpine 2.00 and earlier, and (3) Panda IMAP allow (a) local users to gain privileges by specifying a long folder extension ... Read more
- Published: Nov. 10, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4809
Multiple unspecified vulnerabilities in the Profiles search pages in IBM Lotus Connections 2.x before 2.0.1 have unknown impact and attack vectors related to "Active" content. NOTE: the provenance of this information is unknown; the details are obtained ... Read more
Affected Products : lotus_connections- Published: Oct. 31, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4828
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM) client 5.1.0.0 through 5.1.8.2, 5.2.0.0 through 5.2.5.3, 5.3.0.0 through 5.3.6.4, and 5.4.0.0 through 5.4.1.96, and the TSM Express c... Read more
- Published: May. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4779
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary code via a long filename in a .zip file.... Read more
Affected Products : tguzip- Published: Oct. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4704
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.... Read more
Affected Products : sezhoo- Published: Oct. 23, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4615
Unspecified vulnerability in i_utils.asp in PortalApp before 4.01a has unknown impact and attack vectors.... Read more
Affected Products : portalapp- Published: Oct. 20, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4630
Multiple unspecified vulnerabilities in Midgard Components (MidCOM) Framework before 8.09.1 have unknown impact and attack vectors.... Read more
Affected Products : midgard_components_framework- Published: Oct. 21, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4556
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allows remote attackers to execute arbitrary code via a crafted request.... Read more
Affected Products : solaris- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4526
Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the skin parameter to (1) index.php, (2) forums.php, (3) admin.php, (4) header.php, (5) pages/story.php and ... Read more
Affected Products : ccms- Published: Oct. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4557
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted into an executable regular expression.... Read more
Affected Products : cutenews- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4559
HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via shell metacharacters in argument fields to the (1) webappmon.exe or (2) OpenView5.exe CGI program. NOTE: this issue may be partially cove... Read more
Affected Products : openview_network_node_manager- Published: Feb. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4541
Heap-based buffer overflow in the FTP subsystem in Sun Java System Web Proxy Server 4.0 through 4.0.7 allows remote attackers to execute arbitrary code via a crafted HTTP GET request.... Read more
Affected Products : java_system_web_proxy_server- Published: Oct. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4588
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command.... Read more
Affected Products : eserv- Published: Oct. 15, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4563
Heap-based buffer overflow in adsmdll.dll 5.3.7.7296, as used by the daemon (dsmsvc.exe) in the backup server in IBM Tivoli Storage Manager (TSM) Express 5.3.7.3 and earlier and TSM 5.2, 5.3 before 5.3.6.0, and 5.4.0.0 through 5.4.4.0, allows remote attac... Read more
- Published: Mar. 11, 2009
- Modified: Apr. 09, 2025