Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2012-09-19 CVE-2012-3258 Remote Code Execution vulnerability in HP Operations Orchestration 9.0
Unspecified vulnerability in HP Operations Orchestration 9.0 before 9.03 allows remote attackers to execute arbitrary code via unknown vectors.
network
low complexity
hp
critical
10.0
2012-09-18 CVE-2012-4969 Unspecified vulnerability in Microsoft Internet Explorer
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code via a crafted web site, as exploited in the wild in September 2012.
network
microsoft
critical
9.3
2012-09-16 CVE-2012-3088 Remote Security vulnerability in Cisco Anyconnect Secure Mobility Client 3.1.0/3.2.0
Cisco AnyConnect Secure Mobility Client 3.1.x before 3.1.00495, and 3.2.x, does not check whether an HTTP request originally contains ScanSafe headers, which allows remote attackers to have an unspecified impact via a crafted request, aka Bug ID CSCua13166.
network
cisco
critical
9.3
2012-09-15 CVE-2012-4924 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Asus Ipswcom Activex Component and Net4Switch
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 allows remote attackers to execute arbitrary code via a long parameter to the Alert method.
network
asus CWE-119
critical
9.3
2012-09-15 CVE-2011-5172 Buffer Errors vulnerability in Powerproduction Storyboard Quick 6.0
Stack-based buffer overflow in StoryBoard Quick 6 Build 3786, and possibly StoryBoard Artist and StoryBoard Studio, allows remote attackers to execute arbitrary code via a long string in the string element field in a frame xml file.
network
powerproduction CWE-119
critical
9.3
2012-09-15 CVE-2011-5171 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cyberlink Power2Go 7.0/8.0
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary code via the (1) src and (2) name parameters in a p2g project file.
network
cyberlink CWE-119
critical
9.3
2012-09-15 CVE-2011-5170 Buffer Errors vulnerability in Castillobueno Ccmplayer 1.5
Stack-based buffer overflow in Castillo Bueno Systems CCMPlayer 1.5 allows remote attackers to execute arbitrary code via a long track name in an m3u playlist.
network
castillobueno CWE-119
critical
9.3
2012-09-15 CVE-2011-5167 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
network
oracle tidestone CWE-119
critical
9.3
2012-09-15 CVE-2011-5165 Buffer Errors vulnerability in Cleanersoft Free MP3 CD Ripper 1.1/2.5
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to execute arbitrary code via a crafted .wav file.
network
cleanersoft CWE-119
critical
9.3
2012-09-15 CVE-2011-5164 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Vandyke Absoluteftp
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command response.
network
vandyke CWE-119
critical
9.3