Latest CVE Feed
-
10.0
HIGHCVE-2017-12762
In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy without a length check which can cause a buffer overflow. This affects the Linux kernel 4.9-stable tree, 4.12-stable tree, 3.18-stable tr... Read more
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-10920
The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed by only a GNTMAP_host_map unmapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption... Read more
Affected Products : xen- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2007-5538
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), and Unified CallManager 5.0, allows remote attackers to execute arbitrary code or cause a denial of servic... Read more
- Published: Oct. 18, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2017-3086
Adobe Shockwave versions 12.2.8.198 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : shockwave_player- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6629
An issue was discovered in phpMyAdmin involving the $cfg['ArbitraryServerRegexp'] configuration directive. An attacker could reuse certain cookie values in a way of bypassing the servers defined by ArbitraryServerRegexp. All 4.6.x versions (prior to 4.6.4... Read more
Affected Products : phpmyadmin- Published: Dec. 11, 2016
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Servi... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_server_2012 windows_server_2016 linux_kernel aix windows_server_2019 hp-ux solaris +5 more products- Published: Nov. 14, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-3714
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageT... Read more
- Actively Exploited
- Published: May. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2007-5531
Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02.... Read more
- Published: Oct. 17, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2015-3053
Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3054, CVE-2015-3055, CVE-2... Read more
- Published: May. 13, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2019-14514
An issue was discovered in Microvirt MEmu all versions prior to 7.0.2. A guest Android operating system inside the MEmu emulator contains a /system/bin/systemd binary that is run with root privileges on startup (this is unrelated to Red Hat's systemd init... Read more
Affected Products : memu- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-14482
AdRem NetCrunch 10.6.0.4587 has a hardcoded SSL private key vulnerability in the NetCrunch web client. The same hardcoded SSL private key is used across different customers' installations when no other SSL certificate is installed, which allows remote att... Read more
Affected Products : netcrunch- Published: Dec. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-4844
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.... Read more
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4835
Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60, and Java SE Embedded 8u51, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2015-4881.... Read more
- Published: Oct. 21, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4760
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.... Read more
- Published: Jul. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4600
The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confu... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2017-17106
Credentials for Zivif PR115-204-P-RS V2.3.4.2103 Webcams can be obtained by an unauthenticated remote attacker using a standard web /cgi-bin/hi3510/param.cgi?cmd=getuser HTTP request. This vulnerability exists because of a lack of authentication checks in... Read more
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2007-5528
Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.2 have unknown impact and attack vectors related to (1) Public Sector Human Resources (APP03) and (2) Quoting component (APP06).... Read more
Affected Products : e-business_suite- Published: Oct. 17, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-5526
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2, 10.1.2.2, and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS11.... Read more
- Published: Oct. 17, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2019-14112
Potential buffer overflow while processing CBF frames due to lack of check of buffer length before copy in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mo... Read more
Affected Products : ipq6018_firmware ipq8074_firmware qca8081_firmware sdm660_firmware sm8150_firmware sxr2130_firmware qcs605_firmware qcn7605_firmware apq8098_firmware msm8998_firmware +42 more products- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-14132
Buffer over-write when this 0-byte buffer is typecasted to some other structure and hence memory corruption in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in QCS605, SA6155P, SM8150... Read more
- Published: Apr. 16, 2020
- Modified: Nov. 21, 2024