Latest CVE Feed
-
10.0
HIGHCVE-2011-0807
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administra... Read more
- Published: Apr. 20, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-14528
Invoxia NVX220 devices allow TELNET access as admin with a default password.... Read more
- Published: Jul. 05, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-14495
Vivotek FD8136 devices allow Remote Command Injection, aka "another command injection vulnerability in our target device," a different issue than CVE-2018-14494. NOTE: The vendor has disputed this as a vulnerability and states that the issue does not caus... Read more
- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0654
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in Mrxsmb.sys or bowser.sys in Active Directory in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, W... Read more
- Published: Feb. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-14494
Vivotek FD8136 devices allow Remote Command Injection, related to BusyBox and wget. NOTE: the vendor sent a clarification on 2019-09-17 explaining that, although this CVE was first populated in July 2019, it is a historical vulnerability that does not app... Read more
- Published: Jul. 10, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-0272
Unspecified vulnerability in HP LoadRunner 9.52 allows remote attackers to execute arbitrary code via network traffic to TCP port 5001 or 5002, related to the HttpTunnel feature.... Read more
Affected Products : loadrunner- Published: Jan. 18, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-14417
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to ... Read more
Affected Products : cloud- Published: Aug. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-14324
The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, perform database operations, or manipu... Read more
Affected Products : glassfish_server- Published: Jul. 16, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-4802
Commands.pm in Mojolicious before 0.999928 does not properly perform CGI environment detection, which has unspecified impact and remote attack vectors.... Read more
Affected Products : mojolicious- Published: May. 03, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4326
Multiple buffer overflows in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via variables in a VCALENDAR message, as demonstrated by a long (1) REQUEST-STATUS, (2) TZNAME, (... Read more
Affected Products : groupwise- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4142
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEV... Read more
Affected Products : realwin- Published: Nov. 02, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-14009
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.... Read more
Affected Products : codiad- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-3635
Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vulnerability."... Read more
Affected Products : flash_media_server- Published: Nov. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2002-1974
The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.... Read more
Affected Products : zaurus- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1993
webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.... Read more
Affected Products : affordable_web_space_design_webbbs- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1971
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.... Read more
Affected Products : networking_utils- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2010-3036
Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.... Read more
- Published: Oct. 29, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-13861
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allows unauthorized remote attackers to reboot or execute other functions via the "/xml/system/control.xml" URL, using the GET request "?action=reboot" for example.... Read more
- Published: Jul. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-2902
The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.... Read more
Affected Products : chrome- Published: Jul. 28, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2002-2017
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025