Latest CVE Feed
-
10.0
HIGHCVE-2018-17157
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to ex... Read more
Affected Products : freebsd- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-4437
Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."... Read more
Affected Products : salt- Published: Nov. 05, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4265
The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.... Read more
Affected Products : ffmpeg- Published: Nov. 23, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-17063
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters... Read more
- Published: Sep. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-17065
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.... Read more
- Published: Sep. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-3359
Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.... Read more
Affected Products : shockwave_player- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-3350
Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.... Read more
Affected Products : coldfusion- Published: Jul. 10, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-3195
The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT do... Read more
Affected Products : windows_7 windows_server_2008 windows_server_2012 windows_server_2003 windows_vista windows_xp windows_8 windows_rt- Published: Oct. 09, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2335
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1733.... Read more
Affected Products : storage_data_protector- Published: Jun. 06, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2328
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1636.... Read more
Affected Products : storage_data_protector- Published: Jun. 06, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2324
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1629.... Read more
Affected Products : storage_data_protector- Published: Jun. 06, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-16803
In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.... Read more
Affected Products : cimscan- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-1751
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.... Read more
Affected Products : twiki- Published: Nov. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-1534
Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : database_server- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-1483
Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the Februa... Read more
Affected Products : javafx- Published: Feb. 02, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-1319
Microsoft Publisher 2003 SP3 does not properly check the return value of an unspecified method, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Return Value Handling Vulnerability."... Read more
Affected Products : publisher- Published: May. 15, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-1318
Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."... Read more
Affected Products : publisher- Published: May. 15, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-16590
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.... Read more
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-1091
Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : iprint- Published: May. 02, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2003-0178
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the Preset... Read more
Affected Products : lotus_domino_web_server- Published: Apr. 02, 2003
- Modified: Apr. 03, 2025