imPC@ndo IT

CVE Tracker

56.554 CVE

CVE-2011-0101
High 9.3

Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, double-byte characters, and an incorrect pointer calculation, aka "Excel …

microsoft excel
0.30EPSS
CVE-2023-36413
Medium 6.5

Microsoft Office Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.30EPSS
CVE-2008-0083
High 9.3

The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.30EPSS
CVE-2015-8046
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 a…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.30EPSS
CVE-2013-3137
Medium 4.3

Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability."

microsoft frontpage
0.30EPSS
CVE-2015-0064
High 9.3

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

microsoft office · microsoft office_compatibility_pack · microsoft sharepoint_server · microsoft web_applications · and 3 more
0.30EPSS
CVE-2021-44709
High 7.8

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a heap overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the c…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.30EPSS
CVE-2019-10086
High 7.3

In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default charac…

apache commons_beanutils · apache nifi · debian debian_linux · fedoraproject fedora · and 56 more
0.30EPSS
CVE-2017-0066
Medium 4.2

Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0…

microsoft edge
0.30EPSS
CVE-2017-2935
High 8.8

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the Flash Video container file format. Successful exploitation could lead to arbitrary code execution.

adobe flash_player
0.30EPSS
CVE-2017-2934
High 8.8

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Texture Format files. Successful exploitation could lead to arbitrary code execution.

adobe flash_player
0.30EPSS
CVE-2017-2933
High 8.8

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture compression. Successful exploitation could lead to arbitrary code execution.

adobe flash_player
0.30EPSS
CVE-2024-20337
High 8.2

A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of…

cisco secure_client
0.30EPSS
CVE-2020-11975
Critical 9.8

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.

apache unomi
0.30EPSS
CVE-2015-2431
High 9.3

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office Graphics Library (OGL) font, aka "Microsoft Office Gr…

microsoft live_meeting · microsoft lync · microsoft lync_basic · microsoft office
0.30EPSS
CVE-2016-1000
High 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before…

adobe air · adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · and 3 more
0.30EPSS
CVE-2016-0999
High 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before…

adobe air · adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · and 3 more
0.30EPSS
CVE-2006-1184
Medium 5.0

Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0, 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to cause a denial of service (crash) via a BuildContextW request with a large (1) UuidString or (2) GuidIn of a certain …

microsoft distributed_transaction_coordinator · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · and 1 more
0.30EPSS
CVE-2018-4982
High 8.8

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

adobe acrobat_dc · adobe acrobat_reader_dc
0.30EPSS
CVE-2019-1621
High 7.5

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to gain access to sensitive files on an affected device. The vulnerability is due to incorrect permissions setting…

cisco data_center_network_manager
0.30EPSS
CVE-2017-0561
Critical 9.8

A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the context of…

linux linux_kernel
0.30EPSS
CVE-2016-0997
High 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before…

adobe air · adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · and 3 more
0.30EPSS
CVE-2005-2090
Medium 4.3

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Con…

apache tomcat
0.30EPSS
CVE-2007-1499
Medium 4.3

Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of t…

microsoft ie
0.30EPSS
CVE-2008-2253
High 9.3

Unspecified vulnerability in Microsoft Windows Media Player 11 allows remote attackers to execute arbitrary code via a crafted audio-only file that is streamed from a Server-Side Playlist (SSPL) on Windows Media Server, aka "Windows Media Player Sampling Rate …

microsoft windows_media_player
0.30EPSS