imPC@ndo IT

CVE Tracker

56.554 CVE

CVE-2011-0346
High 8.1

Use-after-free vulnerability in the ReleaseInterface function in MSHTML.DLL in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the DOM implementat…

microsoft internet_explorer
0.31EPSS
CVE-2001-0727
High 7.5

Internet Explorer 6.0 allows remote attackers to execute arbitrary code by modifying the Content-Disposition and Content-Type header fields in a way that causes Internet Explorer to believe that the file is safe to open without prompting the user, aka the "Fil…

microsoft internet_explorer
0.31EPSS
CVE-2007-4891
Medium 6.8

A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to exec…

microsoft visual_studio
0.31EPSS
CVE-2004-0845
Medium 6.4

Internet Explorer 5.01, 5.5, and 6 does not properly cache SSL content, which allows remote attackers to obtain information or spoof content via a web site with the same host name as the target web site, whose content is cached and reused when the user visits …

microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2007-0945
High 9.3

Microsoft Internet Explorer 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and 7 on Windows Vista allows remote attackers to execute arbitrary code via certain property methods that may trigger memory corruption, aka "…

microsoft internet_explorer
0.31EPSS
CVE-2007-0946
High 9.3

Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two …

microsoft internet_explorer
0.31EPSS
CVE-2005-2089
Medium 4.3

Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes IIS to …

microsoft internet_information_services
0.31EPSS
CVE-2007-0427
High 9.3

Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitrary code via a help project (.HPJ) file with a long HLP field in the OPTIONS section.

microsoft html_help_workshop
0.31EPSS
CVE-2014-4072
Medium 5.0

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 does not properly use a hash table for request data, which allows remote attackers to cause a denial of service (resource consumption and ASP.NET performance degradation) …

microsoft .net_framework
0.31EPSS
CVE-2006-3651
High 9.3

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via a crafted mail merge file, a different vulnerability than CVE-2006-3647 and CVE-2006-4693.

microsoft office · microsoft word
0.31EPSS
CVE-2008-0020
High 9.3

Unspecified vulnerability in the Load method in the IPersistStreamInit interface in the Active Template Library (ATL), as used in the Microsoft Video ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2,…

microsoft windows_2003_server · microsoft windows_xp
0.31EPSS
CVE-2007-3029
High 9.3

Unspecified vulnerability in Microsoft Excel 2002 SP3 and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a malformed Excel file containing multiple active worksheets, which results in memory corruption.

microsoft excel · microsoft office
0.31EPSS
CVE-2007-0934
High 9.3

Unspecified vulnerability in Microsoft Visio 2002 allows remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted version number that triggers memory corruption.

microsoft visio
0.31EPSS
CVE-2007-0936
High 9.3

Multiple unspecified vulnerabilities in Microsoft Visio 2002 allow remote user-assisted attackers to execute arbitrary code via a Visio (.VSD, VSS, .VST) file with a crafted packed object that triggers memory corruption, aka "Visio Document Packaging Vulnerabi…

microsoft office · microsoft visio
0.31EPSS
CVE-2007-1750
High 9.3

Unspecified vulnerability in Microsoft Internet Explorer 6 allows remote attackers to execute arbitrary code via a crafted Cascading Style Sheets (CSS) tag that triggers memory corruption.

microsoft internet_explorer
0.31EPSS
CVE-2007-1205
High 9.3

Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.31EPSS
CVE-2010-2553
High 9.3

The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decompress media files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Cinepak Codec Decompression Vulnerability…

microsoft windows_7 · microsoft windows_vista · microsoft windows_xp
0.31EPSS
CVE-2017-3078
Critical 9.8

Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Texture Format (ATF) module. Successful exploitation could lead to arbitrary code execution.

adobe flash_player
0.31EPSS
CVE-2010-0017
High 9.3

Race condition in the SMB client implementation in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code, and in the SMB client implementation in Windows Vista Gold, SP1, and SP2 and …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.31EPSS
CVE-2017-2986
High 8.8

Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (FLV) codec. Successful exploitation could lead to arbitrary code execution.

adobe flash_player · adobe flash_player_desktop_runtime
0.31EPSS
CVE-1999-0077
Medium 5.0

Predictable TCP sequence numbers allow spoofing.

microsoft windows_nt
0.31EPSS
CVE-2008-0121
High 9.3

A "memory calculation error" in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with an invalid picture index that triggers memory corruption, aka "Memory Calculation Vulnerability."

microsoft office_powerpoint_viewer
0.31EPSS
CVE-2008-0119
High 9.3

Unspecified vulnerability in Microsoft Publisher in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 SP1 and earlier allows remote attackers to execute arbitrary code via a Publisher file with crafted object header data that triggers memory corruption, aka "…

microsoft office
0.31EPSS
CVE-2008-1434
High 9.3

Use-after-free vulnerability in Microsoft Word in Office 2000 and XP SP3, 2003 SP2 and SP3, and 2007 Office System SP1 and earlier allows remote attackers to execute arbitrary code via an HTML document with a large number of Cascading Style Sheets (CSS) select…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft word_viewer
0.31EPSS
CVE-2008-0109
High 9.3

Word in Microsoft Office 2000 SP3, XP SP3, Office 2003 SP2, and Office Word Viewer 2003 allows remote attackers to execute arbitrary code via crafted fields within the File Information Block (FIB) of a Word file, which triggers length calculation errors and me…

microsoft office · microsoft word
0.31EPSS