Latest CVE Feed
-
10.0
HIGHCVE-2008-0235
The Microsoft VFP_OLE_Server ActiveX control allows remote attackers to execute arbitrary code by invoking the foxcommand method.... Read more
Affected Products : vfp_ole_server_activex_control- Published: Jan. 11, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0215
Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspecified access to a managed device via unknown attack vectors.... Read more
- Published: Feb. 12, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0176
Heap-based buffer overflow in w32rtr.exe in GE Fanuc CIMPLICITY HMI SCADA system 7.0 before 7.0 SIM 9, and earlier versions before 6.1 SP6 Hot fix - 010708_162517_6106, allow remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : cimplicity- Published: Jan. 29, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0148
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.... Read more
Affected Products : tutos- Published: Jan. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0082
An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or vide... Read more
Affected Products : windows_messenger- Published: Aug. 13, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0014
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-200... Read more
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0013
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-200... Read more
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0027
Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote at... Read more
- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-0012
Heap-based buffer overflow in an unspecified procedure in Trend Micro ServerProtect 5.7 and 5.58 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to the product's configuration, a different vulnerability than CVE-200... Read more
- Published: Nov. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6711
Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges via unknown vectors.... Read more
Affected Products : freewebshop- Published: Mar. 24, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6686
The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.... Read more
Affected Products : gallery- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6685
Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.... Read more
Affected Products : gallery_publish_xp_module- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6690
The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.... Read more
Affected Products : gallery- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6721
The Legion of the Bouncy Castle Java Cryptography API before release 1.38, as used in Crypto Provider Package before 1.36, has unknown impact and remote attack vectors related to "a Bleichenbacher vulnerability in simple RSA CMS signatures without signed ... Read more
Affected Products : legion-of-the-bouncy-castle-java-crytography-api bc-java bouncy-castle-crypto-package- Published: Mar. 30, 2009
- Modified: May. 12, 2025
-
10.0
HIGHCVE-2007-6688
Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the storage folder."... Read more
Affected Products : gallery- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-6691
Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the WebDAV module, (3) a comment view in the Comment module, (4) unspecified "ite... Read more
Affected Products : gallery- Published: Jan. 17, 2008
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2025-20265
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to inject arbitrary shell commands that are executed by the device. This vulnerabilit... Read more
- Published: Aug. 14, 2025
- Modified: Aug. 16, 2025
- Vuln Type: Injection
-
10.0
HIGHCVE-2007-6757
GE Healthcare Centricity DMS 4.2, 4.1, and 4.0 has a password of Muse!Admin for the Museadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or prod... Read more
Affected Products : centricity_dms_firmware- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2007-6732
Multiple buffer overflows in the dtt_load function in loaders/dtt_load.c Extended Module Player (XMP) 2.5.1 and earlier allow remote attackers to execute arbitrary code via unspecified vectors related to an untrusted length value and the (1) pofs and (2) ... Read more
- Published: Sep. 13, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-3268
Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.... Read more
Affected Products : php- Published: Aug. 25, 2011
- Modified: Apr. 11, 2025