Latest CVE Feed
-
10.0
HIGHCVE-2006-4902
The NetBackup bpcd daemon (bpcd.exe) in Symantec Veritas NetBackup 5.0 before 5.0_MP7, 5.1 before 5.1_MP6, and 6.0 before 6.0_MP4 does not properly check for chained commands, which allows remote attackers to execute arbitrary commands by appending malici... Read more
Affected Products : veritas_netbackup_client veritas_netbackup_enterprise_server veritas_netbackup_server- Published: Dec. 14, 2006
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2020-13300
GitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorization flow.... Read more
Affected Products : gitlab- Published: Sep. 14, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-4691
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.... Read more
- Published: Nov. 14, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4509
Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request.... Read more
Affected Products : edirectory- Published: Oct. 24, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4461
Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly implement a "list of acceptable host IP addresses in the probe settings," which has unknown impact and attack vectors.... Read more
Affected Products : ipcheck_server_monitor- Published: Aug. 31, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-13159
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.... Read more
Affected Products : artica_proxy- Published: Jun. 22, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-4309
VNC server on the AK-Systems Windows Terminal 1.2.5 ExVLP is not password protected, which allows remote attackers to login and view RDP or Citrix sessions.... Read more
Affected Products : windows_terminal- Published: Aug. 23, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4304
Buffer overflow in the sppp driver in FreeBSD 4.11 through 6.1, NetBSD 2.0 through 4.0 beta before 20060823, and OpenBSD 3.8 and 3.9 before 20060902 allows remote attackers to cause a denial of service (panic), obtain sensitive information, and possibly e... Read more
- Published: Aug. 24, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4098
Stack-based buffer overflow in the CSRadius service in Cisco Secure Access Control Server (ACS) for Windows before 4.1 and ACS Solution Engine before 4.1 allows remote attackers to execute arbitrary code via a crafted RADIUS Accounting-Request packet.... Read more
Affected Products : secure_access_control_server- Published: Dec. 31, 2006
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-4037
Unspecified vulnerability in Fenestrae Faxination Server allows remote attackers to execute arbitrary code via a crafted packet.... Read more
Affected Products : faxination_server- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-4084
Unspecified vulnerability in phpAutoMembersArea (phpAMA) before 3.2.4 has unknown impact and attack vectors, related to "a potential security exploit which is critical."... Read more
Affected Products : phpautomembersarea- Published: Aug. 11, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3892
The Management Console server in EMC NetWorker (formerly Legato NetWorker) 7.3.2 before Jumbo Update 1 uses weak authentication, which allows remote attackers to execute arbitrary commands.... Read more
Affected Products : networker- Published: Mar. 02, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2006-3838
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network ... Read more
Affected Products : enterprise_security_analyzer- Published: Jul. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3724
Unspecified vulnerability in JD Edwards HTML Server for Oracle OneWorld Tools EnterpriseOne Tools 8.95 and 8.96 has unknown impact and attack vectors, aka Oracle Vuln# JDE01.... Read more
Affected Products : enterpriseone- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3717
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS03 and (2) APPS04 for Oracle Application Object Library; and (3) APPS20 for Oracle XML Gateway.... Read more
Affected Products : e-business_suite- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-12775
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary syst... Read more
Affected Products : hicos- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3573
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.... Read more
Affected Products : sparklet- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-11560
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using ... Read more
- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3439
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2020-12493
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb opera... Read more
Affected Products : cpu_ls4000_firmware- Published: May. 29, 2020
- Modified: Nov. 21, 2024