Latest CVE Feed
-
10.0
HIGHCVE-2011-1851
Stack-based buffer overflow in tftpserver.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a long mode field.... Read more
Affected Products : intelligent_management_center- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-1848
Stack-based buffer overflow in img.exe in HP Intelligent Management Center (IMC) 5.0 before E0101L02 allows remote attackers to execute arbitrary code via a crafted length field in a packet.... Read more
Affected Products : intelligent_management_center- Published: May. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-8408
Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allow attackers to ... Read more
Affected Products : android linux_kernel flash_player mac_os_x iphone_os windows air air_sdk air_sdk_\&_compiler- Published: Dec. 10, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2011-1206
Stack-based buffer overflow in the server process in ibmslapd.exe in IBM Tivoli Directory Server (TDS) 5.2 before 5.2.0.5-TIV-ITDS-IF0010, 6.0 before 6.0.0.67 (aka 6.0.0.8-TIV-ITDS-IF0009), 6.1 before 6.1.0.40 (aka 6.1.0.5-TIV-ITDS-IF0003), 6.2 before 6.2... Read more
Affected Products : tivoli_directory_server- Published: Apr. 21, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0285
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka krb5) 1.7 through 1.9 frees an invalid pointer, which allows remote attackers to execute arbitrary code or cause a denial of service (dae... Read more
Affected Products : kerberos_5- Published: Apr. 15, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0075
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.19 and 3.6.x before 3.6.17, Thunderbird before 3.1.10, and SeaMonkey before 2.0.14 allows remote attackers to cause a denial of service (memory corruption and application ... Read more
- Published: May. 07, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4581
Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."... Read more
Affected Products : opera_browser- Published: Dec. 22, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4469
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4465
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4463
Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 21 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, an... Read more
- Published: Feb. 17, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4233
The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it eas... Read more
- Published: Nov. 17, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2019-18189
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulne... Read more
- Published: Oct. 28, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-3912
The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.... Read more
Affected Products : suse_linux- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2019-18184
Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.... Read more
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-3731
Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attac... Read more
Affected Products : db2- Published: Oct. 05, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-3572
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-3562
Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previou... Read more
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-3193
Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.... Read more
Affected Products : db2- Published: Aug. 31, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-3114
The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLine... Read more
- Published: Aug. 24, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2019-17621
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connect... Read more
Affected Products : dir-823_firmware dir-822_firmware dir-895l_firmware dir-890l_firmware dir-885l_firmware dir-880l_firmware dir-868l_firmware dir-859_firmware dir-865l_firmware dir-869_firmware +18 more products- Actively Exploited
- Published: Dec. 30, 2019
- Modified: Apr. 03, 2025