Latest CVE Feed
-
10.0
HIGHCVE-2006-3717
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.9 have unknown impact and attack vectors, aka Oracle Vuln# (1) APPS03 and (2) APPS04 for Oracle Application Object Library; and (3) APPS20 for Oracle XML Gateway.... Read more
Affected Products : e-business_suite- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-12775
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary syst... Read more
Affected Products : hicos- Published: Mar. 01, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3573
Format string vulnerability in the WriteText function in agl_text.cpp in Milan Mimica Sparklet 0.9.4 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a player nickname.... Read more
Affected Products : sparklet- Published: Jul. 13, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-11560
A buffer overflow vulnerability in the streaming server provided by hisilicon in HI3516 models allows an unauthenticated attacker to remotely run arbitrary code by sending a special RTSP over HTTP packet. The vulnerability was found in many cameras using ... Read more
- Published: May. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3439
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.... Read more
- Published: Aug. 09, 2006
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2020-12493
An open port used for debugging in SWARCOs CPU LS4000 Series with versions starting with G4... grants root access to the device without access control via network. A malicious user could use this vulnerability to get access to the device and disturb opera... Read more
Affected Products : cpu_ls4000_firmware- Published: May. 29, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-4439
PHP remote file inclusion vulnerability in admin/bin/patch.php in MartinWood Datafeed Studio before 1.6.3 allows remote attackers to execute arbitrary PHP code via a URL in the INSTALL_FOLDER parameter. NOTE: the provenance of this information is unknown;... Read more
Affected Products : datafeed_studio- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2020-12388
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.... Read more
- Published: May. 26, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3232
Unspecified vulnerability in IBM WebSphere Application Server before 6.0.2.11 has unknown impact and attack vectors because the "UserNameToken cache was improperly used."... Read more
Affected Products : websphere_application_server- Published: Jun. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-12441
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ agent. The DoS can be triggered by sending a specially crafted network packet.... Read more
- Published: Aug. 06, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-12284
cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.... Read more
- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2020-12271
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration (HTTPS) service or the User Portal ... Read more
- Actively Exploited
- Published: Apr. 27, 2020
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-4397
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve Backup) r11.1 through r12.0 allows remote attackers to execute arbitrary commands via a .. (dot dot) in an RPC call with opnum 0x10A.... Read more
- Published: Oct. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2020-12389
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8 and Firefox < 76.... Read more
- Published: May. 26, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-4390
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-management command, which allows remote attackers to obtain sensitive information such as passwords by sniffing th... Read more
- Published: Dec. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-12125
A remote buffer overflow vulnerability in the /cgi-bin/makeRequest.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary machine instructions as root without authentication.... Read more
- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-4383
Stack-based buffer overflow in the Agranet-Emweb embedded management web server in Alcatel OmniSwitch OS7000, OS6600, OS6800, OS6850, and OS9000 Series devices with AoS 5.1 before 5.1.6.463.R02, 5.4 before 5.4.1.429.R01, 6.1.3 before 6.1.3.965.R01, 6.1.5 ... Read more
- Published: Oct. 03, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-11975
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.... Read more
Affected Products : unomi- Published: Jun. 05, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-2547
Unspecified vulnerability in the sapdba command in SAP with Informix before 700, and 700 up to patch 100, allows local users to execute arbitrary commands via unknown vectors related to "insecure environment variable" handling.... Read more
Affected Products : sapdba- Published: May. 23, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-4358
Unspecified vulnerability in class/theme.class.php in SPAW Editor PHP Edition before 2.0.8.1 has unknown impact and attack vectors, probably related to directory traversal sequences in the theme name.... Read more
Affected Products : spaw_php- Published: Sep. 30, 2008
- Modified: Apr. 09, 2025