Latest CVE Feed
-
10.0
HIGHCVE-2008-4318
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter to (1) whois.php or (2) netcmd.php.... Read more
Affected Products : observer- Published: Sep. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4301
A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In ad... Read more
Affected Products : internet_information_services- Published: Sep. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target serv... Read more
Affected Products : spamtitan- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-2077
Buffer overflow in Paul Rombouts pdnsd before 1.2.4 has unknown impact and attack vectors. NOTE: this issue might be related to the OUSPG PROTOS DNS test suite.... Read more
Affected Products : pdnsd- Published: Apr. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-2074
Unspecified vulnerability in Juniper Networks JUNOSe E-series routers before 7-1-1 has unknown impact and remote attack vectors related to the DNS "client code," as demonstrated by the OUSPG PROTOS DNS test suite.... Read more
Affected Products : junose- Published: Apr. 27, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-4283
CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified v... Read more
Affected Products : websphere_application_server- Published: Feb. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-11600
An issue was discovered on Samsung mobile devices with Q(10.0) software. There is arbitrary code execution in the Fingerprint Trustlet via a memory overwrite. The Samsung IDs are SVE-2019-16587, SVE-2019-16588, SVE-2019-16589 (April 2020).... Read more
Affected Products : android- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-11552
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to es... Read more
Affected Products : manageengine_adselfservice_plus- Published: Aug. 11, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-1887
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Security Server 8.95.J1 has unknown impact and attack vectors, aka Vuln# JDE01.... Read more
Affected Products : enterpriseone- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-11543
OpsRamp Gateway before 7.0.0 has a backdoor account vadmin with the password 9vt@f3Vt that allows root SSH access to the server. This issue has been resolved in OpsRamp Gateway firmware version 7.0.0 where an administrator and a system user accounts are t... Read more
Affected Products : gateway- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-1881
Unspecified vulnerability in the Financials for Asia/Pacific component in Oracle E-Business Suite and Applications 11.5.9 has unknown impact and attack vectors. component, aka Vuln# APPS02.... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1885
Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02.... Read more
Affected Products : enterprise_manager- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1880
Multiple unspecified vulnerabilities in Oracle E-Business Suite and Applications 11.5.10CU2 have unknown impact and attack vectors, as identified by Vuln# (1) APPS01 in the (a) Application Install component; (2) APPS09 in the (b) Oracle Diagnostics Interf... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1883
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite and Applications 11.5.10CU1 has unknown impact and attack vectors, aka Vuln# APPS05.... Read more
Affected Products : e-business_suite- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-1792
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits". NOTE: this is a diff... Read more
- Published: Apr. 15, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-0796
Format string vulnerability in the logging component of snmpdx for Solaris 5.6 through 8 allows remote attackers to gain root privileges.... Read more
- Published: Aug. 12, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-11196
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Sna... Read more
Affected Products : sa6150p_firmware sa6155p_firmware sa8150p_firmware sa8155p_firmware sa8195p_firmware sdx55m_firmware qcm4290_firmware qcs4290_firmware sa6155_firmware sa8155_firmware +174 more products- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-11193
u'Buffer over read can happen while parsing mkv clip due to improper typecasting of data returned from atomsize' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapd... Read more
Affected Products : sa6145p_firmware sa6155p_firmware sa8155p_firmware sdx55m_firmware qcm4290_firmware qcs4290_firmware qsm8350_firmware sa6155_firmware sa8155_firmware sdx55_firmware +174 more products- Published: Nov. 12, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-11167
Memory corruption while calculating L2CAP packet length in reassembly logic when remote sends more data than expected in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, S... Read more
- Published: Jan. 21, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-11153
u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to remote code execution' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Sna... Read more
Affected Products : qca6390_firmware sdx55_firmware qca9379_firmware qcn7605_firmware sc8180x_firmware apq8053_firmware apq8053 qca6390 qca9379 sdx55 +2 more products- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024