Latest CVE Feed
-
10.0
HIGHCVE-2019-7791
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful ex... Read more
- Published: May. 22, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7684
inxedu through 2018-12-24 has a vulnerability that can lead to the upload of a malicious JSP file. The vulnerable code location is com.inxedu.os.common.controller.VideoUploadController#gok4 (com/inxedu/os/common/controller/VideoUploadController.java). The... Read more
Affected Products : inxedu- Published: Feb. 09, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0886
Format string vulnerability in hfaxd for Hylafax 4.1.7 and earlier allows remote attackers to execute arbitrary code.... Read more
Affected Products : hylafax- Published: Dec. 01, 2003
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2019-7609
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to... Read more
- Actively Exploited
- Published: Mar. 25, 2019
- Modified: Mar. 13, 2025
-
10.0
HIGHCVE-2015-6988
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.... Read more
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2003-0784
Format string vulnerability in tsm for the bos.rte.security fileset on AIX 5.2 allows remote attackers to gain root privileges via login, and local users to gain privileges via login, su, or passwd, with a username that contains format string specifiers.... Read more
Affected Products : aix- Published: Oct. 06, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0640
BEA WebLogic Server and Express, when using NodeManager to start servers, provides Operator users with privileges to overwrite usernames and passwords, which may allow Operators to gain Admin privileges.... Read more
Affected Products : weblogic_server- Published: Aug. 27, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0588
admin.php in Digi-news 1.1 allows remote attackers to bypass authentication via a cookie with the username set to the name of the administrator, which satisfies an improper condition in admin.php that does not require a correct password.... Read more
Affected Products : digi-news- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-3908
Multiple buffer overflows in Princeton WordNet (wn) 3.0 allow context-dependent attackers to execute arbitrary code via (1) a long argument on the command line; a long (2) WNSEARCHDIR, (3) WNHOME, or (4) WNDBVERSION environment variable; or (5) a user-sup... Read more
Affected Products : wordnet- Published: Sep. 04, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2003-0560
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.... Read more
Affected Products : vp-asp- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0494
password.asp in Snitz Forums 3.4.03 and earlier allows remote attackers to reset passwords and gain privileges as other users by via a direct request to password.asp with a modified member id.... Read more
Affected Products : snitz_forums_2000- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0409
Buffer overflow in BRS WebWeaver 1.04 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP (1) POST or (2) HEAD request.... Read more
Affected Products : webweaver- Published: Jun. 30, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0473
Unknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.... Read more
Affected Products : irix- Published: Aug. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0347
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.... Read more
- Published: Oct. 20, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-7276
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.... Read more
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0209
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to execute arbitrary code via large sequence numbers in packets, which enable a heap-based buffer overflow.... Read more
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2019-7256
Linear eMerge E3-Series devices allow Command Injections.... Read more
- Actively Exploited
- Published: Jul. 02, 2019
- Modified: Feb. 06, 2025
-
10.0
HIGHCVE-2003-0252
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newline... Read more
Affected Products : nfs-utils- Published: Aug. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2008-4322
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote attackers to execute arbitrary code via a crafted FC_INFOTAG/SET_CONTROL packet.... Read more
Affected Products : realwin_server- Published: Sep. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-4304
general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CERT environment variable. NOTE: in some environments, SSL_CLIENT_CERT always ... Read more
Affected Products : phpcollab- Published: Dec. 23, 2008
- Modified: Apr. 09, 2025