57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-0310 | MED 6.6 | linux linux_kernel The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsock | 0.3% | — |
| CVE-2012-4467 | MED 6.6 | linux linux_kernel The (1) do_siocgstamp and (2) do_siocgstampns functions in net/socket.c in the Linux kernel before 3.5.4 use an incorrect argument order, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) vi | 0.5% | — |
| CVE-2012-4104 | MED 6.6 | cisco unified_computing_system Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary files via a full pathname in an image header, aka Bug ID CSCtq0 | 0.4% | — |
| CVE-2012-4089 | MED 6.6 | cisco unified_computing_system MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system la | 0.3% | — |
| CVE-2011-1603 | MED 6.6 | cisco skinny_client_control_protocol_software Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bug ID CSCtn65815. | 0.3% | — |
| CVE-2011-1602 | MED 6.6 | cisco skinny_client_control_protocol_software The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecified vectors, aka Bug ID CSCtf07426. | 0.3% | — |
| CVE-2010-4605 | MED 6.6 | ibm tivoli_storage_manager Unspecified vulnerability in the backup-archive client in IBM Tivoli Storage Manager (TSM) 5.3.x before 5.3.6.10, 5.4.x before 5.4.3.4, 5.5.x before 5.5.3, 6.1.x before 6.1.4, and 6.2.x before 6.2.2 on Unix and Linux allows local users to overwrite arbitrary f | 0.4% | — |
| CVE-2010-3437 | MED 6.6 | canonical ubuntu_linux Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2.6.36-rc6 allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference an | 2.4% | — |
| CVE-2009-3889 | MED 6.6 | linux linux_kernel The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the (1) behavior and (2) logging level of the driver by modifying this file. | 0.5% | — |
| CVE-2008-3003 | MED 6.6 | microsoft office Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain a | 1.7% | — |
| CVE-2007-1730 | MED 6.6 | linux linux_kernel Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later allows local users to read kernel memory or cause a denial of service (oops) via a negative optlen value. | 0.8% | — |
| CVE-2007-1271 | MED 6.6 | vmware esx Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors. | 0.4% | — |
| CVE-2007-1212 | MED 6.6 | microsoft windows_2000 Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via a crafted Enhanced Metafile (EMF) image format file. | 2.1% | — |
| CVE-2007-0084 | MED 6.6 | microsoft message_compiler Buffer overflow in the Windows NT Message Compiler (MC) 1.00.5239 on Microsoft Windows XP allows local users to gain privileges via a long MC-filename. NOTE: this issue has been disputed by a reliable third party who states that the compiler is not a privileg | 1.3% | — |
| CVE-2006-6797 | MED 6.6 | microsoft windows_xp The Client Server Run-Time Subsystem (CSRSS) in Microsoft Windows allows local users to cause a denial of service (crash) or read arbitrary memory from csrss.exe via crafted arguments to the NtRaiseHardError function with status 0x50000018, a different vulnera | 7.0% | — |
| CVE-2005-3806 | MED 6.6 | linux linux_kernel The IPv6 flow label handling code (ip6_flowlabel.c) in Linux kernels 2.4 up to 2.4.32 and 2.6 before 2.6.14 modifies the wrong variable in certain circumstances, which allows local users to corrupt kernel memory or cause a denial of service (crash) by triggeri | 0.4% | — |
| CVE-2003-1392 | MED 6.6 | microsoft all_windows CryptoBuddy 1.0 and 1.2 does not use the user-supplied passphrase to encrypt data, which could allow local users to use their own passphrase to decrypt the data. | 1.5% | — |
| CVE-2026-71339 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70330 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70304 | MED 6.7 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65799 | MED 6.7 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65798 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65797 | MED 6.7 | microsoft windows_10_1607 Numeric truncation error in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65795 | MED 6.7 | microsoft windows_10_1607 Relative path traversal in Windows DNS allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-65680 | MED 6.7 | microsoft onedrive Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally. | 0.3% | — |