Latest CVE Feed
-
10.0
HIGHCVE-2009-2685
Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.... Read more
Affected Products : power_manager- Published: Nov. 06, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1582
compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in netw... Read more
Affected Products : mailreader.com- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2009-2452
Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."... Read more
Affected Products : licensing- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1985
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : database_server- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1628
Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet.... Read more
- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-13101
KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to... Read more
Affected Products : kiosksimple- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1350
Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of ... Read more
Affected Products : netidentity_client1.2.3- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1231
Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.... Read more
Affected Products : db2_content_manager- Published: Apr. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0896
Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.... Read more
Affected Products : websphere_mq- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0837
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "... Read more
Affected Products : reader3.0- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0720
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : openview_network_node_manager- Published: May. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0517
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.... Read more
Affected Products : phpslash- Published: Feb. 11, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1383
Multiple integer overflows in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allow remote attackers to execute arbitrary code via (1) the CUPSd HTTP interface, as demonstrated by vanilla-coke, and (2) the image handling code in CUPS filters, as ... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1369
jobs.c in Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 does not properly use the strncat function call when processing the options string, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more
- Published: Dec. 26, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1358
Multiple SSH2 servers and clients do not properly handle lists with empty elements or strings, which may allow remote attackers to cause a denial of service or possibly execute arbitrary code, as demonstrated by the SSHredder SSH protocol test suite.... Read more
- Published: Dec. 23, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2009-0137
Multiple unspecified vulnerabilities in Safari RSS in Apple Mac OS X 10.4.11 and 10.5.6, and Windows XP and Vista, allow remote attackers to execute arbitrary JavaScript in the local security zone via a crafted feed: URL, related to "input validation issu... Read more
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0042
Multiple unspecified vulnerabilities in the Arclib library (arclib.dll) before 7.3.0.15 in the CA Anti-Virus engine for CA Anti-Virus for the Enterprise 7.1, r8, and r8.1; Anti-Virus 2007 v8 and 2008; Internet Security Suite 2007 v3 and 2008; and other CA... Read more
- Published: Jan. 28, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0012
Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.... Read more
- Published: Feb. 13, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-12823
Adobe Digital Editions versions 4.5.8 and below have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : digital_editions- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-7219
Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 before 2.2-RC2; Groupware 1.0 before 1.0.3 and 1.1 before 1.1-RC2; and Groupware Webmail Edition 1.0 before 1.... Read more
- Published: Sep. 13, 2009
- Modified: Apr. 09, 2025