Latest CVE Feed
-
10.0
HIGHCVE-2009-3075
Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.2, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and appl... Read more
Affected Products : firefox- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3073
Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more
Affected Products : firefox- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3050
Buffer overflow in the set_page_size function in util.cxx in HTMLDOC 1.8.27 and earlier allows context-dependent attackers to execute arbitrary code via a long MEDIA SIZE comment. NOTE: it was later reported that there were additional vectors in htmllib.... Read more
Affected Products : htmldoc- Published: Sep. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3027
VRTSweb.exe in VRTSweb in Symantec Backup Exec Continuous Protection Server (CPS) 11d, 12.0, and 12.5; Veritas NetBackup Operations Manager (NOM) 6.0 GA through 6.5.5; Veritas Backup Reporter (VBR) 6.0 GA through 6.6; Veritas Storage Foundation (SF) 3.5; ... Read more
Affected Products : hp-ux veritas_storage_foundation veritas_storage_foundation_cluster_file_system_for_oracle_rac veritas_backup_exec backup_exec_continuous_protection_server veritas_application_director veritas_cluster_server veritas_cluster_server_management_console veritas_cluster_server_one veritas_command_central_enterprise_reporter +14 more products- Published: Dec. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2532
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a craft... Read more
- Published: Oct. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2494
The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations aft... Read more
- Published: Aug. 12, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2415
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.... Read more
- Published: Aug. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-2028
Multiple unspecified vulnerabilities in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 have unknown impact and attack vectors, related to "Adobe internally discovered iss... Read more
- Published: Jun. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1925
The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly manage state information, which allows remote attackers to execute arbitrary code by sending packets to a listening service, and thereby... Read more
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1899
Unspecified vulnerability in the Administrative Configservice API in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5 on z/OS allows remote authenticate... Read more
Affected Products : websphere_application_server- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1300
apt 0.7.20 does not check when the date command returns an "invalid date" error, which can prevent apt from loading security updates in time zones for which DST occurs at midnight.... Read more
- Published: Apr. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1172
The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknow... Read more
Affected Products : websphere_application_server- Published: Mar. 31, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0916
Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."... Read more
Affected Products : opera_browser- Published: Mar. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0771
The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and as... Read more
- Published: Mar. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0650
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd fiel... Read more
Affected Products : tptest- Published: Feb. 20, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0544
Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.... Read more
Affected Products : arc2- Published: Feb. 12, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0258
The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is n... Read more
Affected Products : typo3- Published: Jan. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0208
Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : virtual_rooms- Published: Feb. 26, 2009
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2019-16932
A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.... Read more
Affected Products : visualizer- Published: Sep. 30, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-6821
Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-200... Read more
Affected Products : db2- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025