Latest CVE Feed
-
10.0
HIGHCVE-2012-4876
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera allows remote attackers to execute arbitrary code via a long string to the OpenFileDlg method.... Read more
Affected Products : securview_wireless_internet_camera_activex_control securview_wireless_internet_camera- Published: Sep. 06, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-4577
The Linux firmware image on (1) Korenix Jetport 5600 series serial-device servers and (2) ORing Industrial DIN-Rail serial-device servers has a hardcoded password of "password" for the root account, which allows remote attackers to obtain administrative a... Read more
Affected Products : jetport- Published: Aug. 21, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-4145
Unspecified vulnerability in Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, has unknown impact and attack vectors, related to a "low severity issue."... Read more
- Published: Aug. 06, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-16037
Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a... Read more
- Published: Jan. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-15981
Flash Player versions 31.0.0.148 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player_desktop_runtime flash_player mac_os_x chrome_os +1 more products- Published: Nov. 29, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-3828
The MPEG4Extractor::parse3GPPMetaData function in MPEG4Extractor.cpp in libstagefright in Android before 5.1.1 LMY48I does not enforce a minimum size for UTF-16 strings containing a Byte Order Mark (BOM), which allows remote attackers to execute arbitrary... Read more
Affected Products : android- Published: Oct. 01, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2003-0033
Buffer overflow in the RPC preprocessor for Snort 1.8 and 1.9.x before 1.9.1 allows remote attackers to execute arbitrary code via fragmented RPC packets.... Read more
Affected Products : snort- Published: Mar. 07, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-3283
Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511.... Read more
- Published: Feb. 06, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-3274
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (IMC) before 5.1 E0101P01 allows remote attackers to execute arbitrary code via vectors related to log data.... Read more
Affected Products : intelligent_management_center- Published: Dec. 06, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-15958
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2012-3202
Multiple unspecified vulnerabilities in the Oracle JRockit component in Oracle Fusion Middleware 28.2.4 and earlier, and 27.7.3 and earlier, when using JDK/JRE 5 or 6, allow remote attackers to affect confidentiality, integrity, and availability via unkno... Read more
- Published: Oct. 17, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-15959
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : coldfusion- Published: Sep. 25, 2018
- Modified: May. 06, 2025
-
10.0
HIGHCVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation flash_player mac_os_x chrome_os windows +1 more products- Actively Exploited
- Published: Jan. 18, 2019
- Modified: Feb. 13, 2025
-
10.0
HIGHCVE-2003-0030
Buffer overflows in protegrity.dll of Protegrity Secure.Data Extension Feature (SEF) before 2.2.3.9 allow attackers with SQL access to execute arbitrary code via the extended stored procedures (1) xp_pty_checkusers, (2) xp_pty_insert, or (3) xp_pty_select... Read more
Affected Products : secure.data- Published: Mar. 18, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-2785
Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors, related to (1) "some subframes only encode some channels" or (2) a large order value.... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2782
Unspecified vulnerability in the decode_slice_header function in libavcodec/h264.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to a "rejected resolution change."... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-15808
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for attackers to remotely execute code o... Read more
Affected Products : evo- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-15890
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.... Read more
Affected Products : ethereumj- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-2046
Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2044, CVE-2012-2045, and CVE-2012-2047.... Read more
Affected Products : shockwave_player- Published: Aug. 15, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2033
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.... Read more
Affected Products : shockwave_player- Published: May. 09, 2012
- Modified: Apr. 11, 2025