57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-5155 | MED 6.2 | eeye blink Race condition in Blink Professional 4.6.1 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-spac | 0.3% | — |
| CVE-2010-5154 | MED 6.2 | bitdefender bitdefender_total_security_2010 Race condition in BitDefender Total Security 2010 13.0.20.347 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, vi | 0.3% | — |
| CVE-2010-5152 | MED 6.2 | avg internet_security Race condition in AVG Internet Security 9.0.791 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user | 0.3% | — |
| CVE-2010-5151 | MED 6.2 | avast\! avast\!_internet_security Race condition in avast! Internet Security 5.0.462 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain u | 0.3% | — |
| CVE-2010-5150 | MED 6.2 | 3dprotect 3d_eqsecure Race condition in 3D EQSecure Professional Edition 4.2 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certa | 0.3% | — |
| CVE-2010-4258 | MED 6.2 | fedoraproject fedora The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by | 2.7% | — |
| CVE-2010-4157 | MED 6.2 | fedoraproject fedora Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an | 0.5% | — |
| CVE-2010-2963 | MED 6.2 | canonical ubuntu_linux drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory l | 0.8% | — |
| CVE-2007-6753 | MED 6.2 | microsoft windows_2000 Untrusted search path vulnerability in Shell32.dll in Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2008, and Windows 7, when using an environment configured with a string such as %APPDATA% or %PROGRAMFILES% in a certain way, allows local u | 1.8% | — |
| CVE-2007-2040 | MED 6.2 | cisco wireless_lan_controller_software Cisco Aironet 1000 Series and 1500 Series Lightweight Access Points before 3.2.185.0, and 4.0.x before 4.0.206.0, have a hard-coded password, which allows attackers with physical access to perform arbitrary actions on the device, aka Bug ID CSCsg15192. | 0.4% | — |
| CVE-2007-1741 | MED 6.2 | apache http_server Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to gain privileges and execute arbitrary code by renaming directories or performing symlink attacks. NOTE: the rese | 0.5% | — |
| CVE-2007-1220 | MED 6.2 | microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code. | 1.4% | — |
| CVE-2007-0351 | MED 6.2 | zonelabs zonealarm Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in | 0.3% | — |
| CVE-2006-3626 | MED 6.2 | linux linux_kernel Race condition in Linux kernel 2.6.17.4 and earlier allows local users to gain root privileges by using prctl with PR_SET_DUMPABLE in a way that causes /proc/self/environ to become setuid root. | 2.2% | — |
| CVE-2005-0178 | MED 6.2 | linux linux_kernel Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores. | 0.4% | — |
| CVE-2004-1235 | MED 6.2 | avaya converged_communications_server Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor. | 2.9% | — |
| CVE-2004-1068 | MED 6.2 | linux linux_kernel A "missing serialization" error in the unix_dgram_recvmsg function in Linux 2.4.27 and earlier, and 2.6.x up to 2.6.9, allows local users to gain privileges via a race condition. | 0.4% | — |
| CVE-2001-1390 | MED 6.2 | linux linux_kernel Unknown vulnerability in binfmt_misc in the Linux kernel before 2.2.19, related to user pages. | 0.4% | — |
| CVE-2001-0005 | MED 6.2 | microsoft powerpoint Buffer overflow in the parsing mechanism of the file loader in Microsoft PowerPoint 2000 allows attackers to execute arbitrary commands. | 1.5% | — |
| CVE-1999-0700 | MED 6.2 | microsoft windows_2000 Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file. | 2.9% | — |
| CVE-2026-9989 | MED 6.3 | google chrome Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High) | 0.1% | — |
| CVE-2026-81997 | MED 6.3 | adobe acrobat Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue requ | 0.2% | — |
| CVE-2026-8010 | MED 6.3 | google chrome Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low) | 0.1% | — |
| CVE-2026-7977 | MED 6.3 | google chrome Inappropriate implementation in Canvas in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2026-7971 | MED 6.3 | google chrome Inappropriate implementation in ORB in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |