Latest CVE Feed
-
10.0
HIGHCVE-2010-0284
Directory traversal vulnerability in the getEntry method in the PortalModuleInstallManager component in a servlet in nps.jar in the Administration Console (aka Access Management Console) in Novell Access Manager 3.1 before 3.1.2-281 on Windows allows remo... Read more
- EPSS Score: %10.81
- Published: Jun. 18, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0240
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows... Read more
- EPSS Score: %55.48
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0239
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrar... Read more
- EPSS Score: %66.84
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0160
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory ... Read more
- EPSS Score: %5.18
- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0079
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-386... Read more
- EPSS Score: %1.28
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4637
FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors that trigger a stack-based buffer overflow.... Read more
Affected Products : ffmpeg- EPSS Score: %33.81
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-4634
Multiple integer underflows in FFmpeg 0.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted file that (1) bypasses a validation check in vorbis_dec.c and triggers a wraparound of the stack pointer, or (2... Read more
Affected Products : ffmpeg- EPSS Score: %5.99
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-4538
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a relate... Read more
- EPSS Score: %3.18
- Published: Jan. 12, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4181
Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors involving the sel and arg parameters to jovgraph.exe.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %18.69
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4177
Buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %21.29
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4072
Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."... Read more
Affected Products : opera_browser- EPSS Score: %1.39
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3955
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign ex... Read more
- EPSS Score: %36.20
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3848
Stack-based buffer overflow in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long Template parameter, related to the vsprintf function.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %21.38
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3847
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %6.15
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3845
The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter to unspecified Perl scripts.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %18.59
- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3844
Stack-based buffer overflow in the OmniInet process in HP OpenView Data Protector Application Recovery Manager 5.50 and 6.0 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted MSG_PROTOCOL packet.... Read more
Affected Products : openview_data_protector_application_recovery_manager- EPSS Score: %66.26
- Published: Dec. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3637
Stack-based buffer overflow in the M_AddToServerList function in client/menu.c in Red Planet Arena Alien Arena 7.30 allows remote attackers to execute arbitrary code via a packet with a crafted server description to UDP port 27901 followed by a packet wit... Read more
Affected Products : alien_arena- EPSS Score: %12.45
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3371
Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.... Read more
Affected Products : firefox- EPSS Score: %3.18
- Published: Oct. 29, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3245
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack ... Read more
Affected Products : openssl- EPSS Score: %6.72
- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-3075
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and appl... Read more
Affected Products : firefox- EPSS Score: %6.78
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025