Latest CVE Feed
-
10.0
HIGHCVE-2010-2299
The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitr... Read more
Affected Products : chrome- Published: Jun. 15, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1573
Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 ... Read more
- Published: Jun. 10, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1549
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: May. 07, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1319
Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted p... Read more
- Published: Apr. 20, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1229
The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.... Read more
Affected Products : chrome- Published: Apr. 01, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-1122
Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a differ... Read more
Affected Products : firefox- Published: Mar. 25, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0580
Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."... Read more
Affected Products : ios- Published: Mar. 25, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by upload... Read more
- Published: Oct. 18, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2002-1918
Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJ... Read more
Affected Products : data_access_components- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2010-0073
Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : weblogic_server- Published: Apr. 14, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-0071
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : database_server- Published: Jan. 13, 2010
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1794
Unknown vulnerability in pam_authz in the LDAP-UX Integration product on HP-UX 11.00 and 11.11 allows remote attackers to execute r-commands with privileges of other users.... Read more
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-11138
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.... Read more
- Actively Exploited
- Published: May. 31, 2018
- Modified: Mar. 14, 2025
-
10.0
HIGHCVE-2009-4335
Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."... Read more
Affected Products : db2- Published: Dec. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3792
Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.... Read more
Affected Products : flash_media_server- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1641
Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- Published: May. 27, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1659
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.... Read more
Affected Products : portalapp- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-13338
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.... Read more
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-13306
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.... Read more
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-13311
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.... Read more
- Published: Nov. 26, 2018
- Modified: Nov. 21, 2024