Latest CVE Feed
-
10.0
HIGHCVE-2010-1553
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via an invalid MaxAge parameter.... Read more
Affected Products : openview_network_node_manager- Published: May. 13, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1386
page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.... Read more
Affected Products : webkit- Published: Aug. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0477
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes ... Read more
- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2019-17440
Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS... Read more
- Published: Dec. 20, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-0239
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrar... Read more
- Published: Feb. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0160
The Web Worker functionality in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly handle array data types for posted messages, which allows remote attackers to cause a denial of service (heap memory ... Read more
- Published: Feb. 22, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0079
Multiple vulnerabilities in the JRockit component in BEA Product Suite R27.6.5 using JRE/JDK 1.4.2, 5, and 6 allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: this CVE identifier overlaps CVE-2009-386... Read more
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4538
drivers/net/e1000e/netdev.c in the e1000e driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to have an unspecified impact via crafted packets, a relate... Read more
- Published: Jan. 12, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4181
Stack-based buffer overflow in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via vectors involving the sel and arg parameters to jovgraph.exe.... Read more
Affected Products : openview_network_node_manager- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4177
Buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long HTTP Host header.... Read more
Affected Products : openview_network_node_manager- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-4072
Unspecified vulnerability in Opera before 10.10 has unknown impact and attack vectors, related to a "moderately severe issue."... Read more
Affected Products : opera_browser- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3955
Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted JPC_MS_RGN marker in the Jp2c stream of a JpxDecode encoded data stream, which triggers an integer sign ex... Read more
- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3845
The port-3443 HTTP server in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostname parameter to unspecified Perl scripts.... Read more
Affected Products : openview_network_node_manager- Published: Dec. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3245
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack ... Read more
Affected Products : openssl- Published: Mar. 05, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-3075
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and appl... Read more
Affected Products : firefox- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3073
Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more
Affected Products : firefox- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3050
Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.... Read more
Affected Products : htmldoc- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3027
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; ... Read more
Affected Products : hp-ux veritas_storage_foundation veritas_storage_foundation_cluster_file_system_for_oracle_rac veritas_backup_exec backup_exec_continuous_protection_server veritas_application_director veritas_cluster_server veritas_cluster_server_management_console veritas_cluster_server_one veritas_command_central_enterprise_reporter +14 more products- Published: Dec. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2532
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a craft... Read more
- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2494
The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations aft... Read more
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025