Latest CVE Feed
-
10.0
HIGHCVE-2012-2785
Multiple unspecified vulnerabilities in libavcodec/wmalosslessdec.c in FFmpeg before 0.11 have unknown impact and attack vectors, related to (1) "some subframes only encode some channels" or (2) a large order value.... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2782
Unspecified vulnerability in the decode_slice_header function in libavcodec/h264.c in FFmpeg before 0.11 has unknown impact and attack vectors, related to a "rejected resolution change."... Read more
Affected Products : ffmpeg- Published: Sep. 10, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-15808
POSIM EVO 15.13 for Windows includes hardcoded database credentials for the "root" database user. "root" access to POSIM EVO's database may result in a breach of confidentiality, integrity, or availability or allow for attackers to remotely execute code o... Read more
Affected Products : evo- Published: Aug. 23, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-15890
An issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject in crypto/ECKey.java. When a node syncs and mines a new block, arbitrary OS commands can be run on the server.... Read more
Affected Products : ethereumj- Published: Jun. 20, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-2046
Adobe Shockwave Player before 11.6.6.636 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2043, CVE-2012-2044, CVE-2012-2045, and CVE-2012-2047.... Read more
Affected Products : shockwave_player- Published: Aug. 15, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2033
Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2030, CVE-2012-2031, and CVE-2012-2032.... Read more
Affected Products : shockwave_player- Published: May. 09, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-2012
HP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.... Read more
- Published: Jun. 29, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1853
Stack-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Administrat... Read more
Affected Products : windows_xp- Published: Aug. 15, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1852
Heap-based buffer overflow in the Remote Administration Protocol (RAP) implementation in the LanmanWorkstation service in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via crafted RAP response packets, aka "Remote Admi... Read more
Affected Products : windows_xp- Published: Aug. 15, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2004-2407
Unknown vulnerability in phpGroupWare before 0.9.14.002 has unknown attack vectors and impact, related to a "security hole" in the Setup/Config functionality.... Read more
Affected Products : phpgroupware- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-1166
The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.... Read more
- Published: May. 21, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2002-2402
SURECOM broadband router EP-4501 uses a default SNMP read community string of "public" and a default SNMP read/write community string of "secret," which allows remote attackers to read and modify router configuration information.... Read more
Affected Products : ep-4501- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-15555
On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.... Read more
- Published: Jun. 28, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-0780
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.... Read more
- Published: May. 09, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2002-2365
Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.... Read more
Affected Products : simple_wais- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2012-0697
HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.... Read more
Affected Products : storageworks_p2000_g3_msa- Published: Jan. 13, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-15556
The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.... Read more
- Published: Jun. 27, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2012-0290
Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pc... Read more
- Published: Feb. 06, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-0264
op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via unspecified vectors.... Read more
Affected Products : monitor- Published: Dec. 31, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-0261
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.... Read more
- Published: Dec. 31, 2013
- Modified: Apr. 11, 2025