imPC@ndo IT

CVE Tracker

56.554 CVE

CVE-2022-28054
Critical 9.8

Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value.

vandyke vshell
0.31EPSS
CVE-2009-2506
High 9.3

Integer overflow in the text converters in Microsoft Office Word 2002 SP3 and 2003 SP3; Works 8.5; Office Converter Pack; and WordPad in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a DOC file with…

microsoft office_converter_pack · microsoft office_word · microsoft windows_2000 · microsoft windows_server_2003 · and 3 more
0.31EPSS
CVE-2009-2512
Critical 9.8

The Web Services on Devices API (WSDAPI) in Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 does not properly process the headers of WSD messages, which allows remote attackers to execute arbitrary code via a crafted (1) message or (2) response, …

microsoft windows_server_2008 · microsoft windows_vista
0.31EPSS
CVE-2020-0932
High 8.8

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-202…

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.31EPSS
CVE-2015-2474
High 9.0

Microsoft Windows Vista SP2 and Server 2008 SP2 allow remote authenticated users to execute arbitrary code via a crafted string in a Server Message Block (SMB) server error-logging action, aka "Server Message Block Memory Corruption Vulnerability."

microsoft windows_server_2008 · microsoft windows_vista
0.31EPSS
CVE-2016-9312
High 7.5

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

ntp ntp
0.31EPSS
CVE-2007-0218
High 9.3

Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.

microsoft internet_explorer
0.31EPSS
CVE-2008-2249
High 9.3

Integer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via a malformed header in a crafted WMF file, which triggers a buffer overflow…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.31EPSS
CVE-2006-4697
High 9.3

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might be related to CVE-2006-4193.

microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2010-2731
Medium 6.8

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.1 on Windows XP SP3, when directory-based Basic Authentication is enabled, allows remote attackers to bypass intended access restrictions and execute ASP files via a crafted request, …

0.31EPSS
CVE-2005-4131
Medium 6.8

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involvi…

microsoft excel
0.31EPSS
CVE-2008-3476
High 9.3

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle errors associated with access to uninitialized memory, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "HTML Objects Memory Corruption Vulnerability."

microsoft internet_explorer
0.31EPSS
CVE-2006-1311
High 9.3

The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary co…

microsoft learning_essentials · microsoft office · microsoft windows_2000 · microsoft windows_2003_server · and 1 more
0.31EPSS
CVE-2012-0006
Medium 5.0

The DNS server in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 does not properly handle objects in memory during record lookup, which allows remote attackers to cause a denial of service (daemon restart) via a crafted query, aka "DNS D…

microsoft windows_server_2003 · microsoft windows_server_2008
0.31EPSS
CVE-2013-4878
High 7.5

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a …

parallels parallels_plesk_panel · parallels parallels_small_business_panel
0.31EPSS
CVE-2009-0558
High 9.3

Array index error in Excel in Microsoft Office 2000 SP3 and Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac, allows remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Array Indexing…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · and 2 more
0.31EPSS
CVE-2009-0225
High 9.3

Microsoft Office PowerPoint 2002 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 95 native file format, leading to improper "array indexing" and memory corruption, aka "PP7 Memory Corruption Vulnera…

microsoft office_powerpoint
0.31EPSS
CVE-2006-5579
High 9.3

Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code by using JavaScript to cause certain errors simultaneously, which results in the access of previously freed memory, aka "Script Error Handling Memory Corruption Vulnerability."

microsoft internet_explorer
0.31EPSS
CVE-2008-3012
High 9.3

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 200…

microsoft digital_image_suite · microsoft forefront_client_security · microsoft internet_explorer · microsoft office · and 12 more
0.31EPSS
CVE-2007-1203
High 9.3

Unspecified vulnerability in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted set font value in an Excel file, which results in memory corruption.

microsoft excel · microsoft excel_viewer
0.31EPSS
CVE-2002-0074
High 7.5

Cross-site scripting vulnerability in Help File search facility for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to embed scripts into another user's session.

microsoft internet_information_server · microsoft internet_information_services
0.31EPSS
CVE-2002-0075
High 7.5

Cross-site scripting vulnerability for Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other web users via the error message used in a URL redirect (""302 Object Moved") message.

microsoft internet_information_server · microsoft internet_information_services
0.31EPSS
CVE-2018-5063
Medium 6.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.31EPSS
CVE-2018-12764
Medium 6.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.31EPSS
CVE-2018-8172
High 7.8

A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expressio…

microsoft expression_blend · microsoft visual_studio · microsoft visual_studio_2017
0.31EPSS