imPC@ndo IT

CVE Tracker

56.554 CVE

CVE-2011-2003
High 9.3

Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via …

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.28EPSS
CVE-2016-0060
High 8.8

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.28EPSS
CVE-2008-2752
High 7.1

Microsoft Word 2000 9.0.2812 and 2003 11.8106.8172 does not properly handle unordered lists, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .do…

microsoft word
0.28EPSS
CVE-2018-5068
High 7.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2018-12768
High 7.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2018-12767
High 7.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2018-12766
High 7.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2018-12765
High 7.5

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2007-3091
High 7.1

Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2; and 7 for Server 2008 SP2 allows remote attackers to execute arbitrary code or perform other actions upon a pa…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2008 · and 2 more
0.28EPSS
CVE-2008-4033
Medium 4.3

Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session s…

microsoft xml_core_services
0.28EPSS
CVE-2000-0304
Medium 5.0

Microsoft IIS 4.0 and 5.0 with the IISADMPWD virtual directory installed allows a remote attacker to cause a denial of service via a malformed request to the inetinfo.exe program, aka the "Undelimited .HTR Request" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.28EPSS
CVE-2015-5118
High 10.0

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 1…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.28EPSS
CVE-2010-0211
Critical 9.8

The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modr…

apple mac_os_x · apple mac_os_x_server · openldap openldap · opensuse opensuse · and 1 more
0.28EPSS
CVE-2019-0728
High 7.8

A remote code execution vulnerability exists in Visual Studio Code when it process environment variables after opening a project, aka 'Visual Studio Code Remote Code Execution Vulnerability'.

microsoft visual_studio_code
0.28EPSS
CVE-2011-1982
High 9.3

Microsoft Office 2007 SP2, and 2010 Gold and SP1, does not initialize an unspecified object pointer during the opening of Word documents, which allows remote attackers to execute arbitrary code via a crafted document, aka "Office Uninitialized Object Pointer V…

microsoft office
0.28EPSS
CVE-2006-4692
Medium 5.1

Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft Windows XP SP1 and SP2 and Server 2003 SP1 and earlier allows remote user-assisted attackers to execute arbitrary commands via a crafted file with a "/" (slash) charact…

microsoft windows_server_2003 · microsoft windows_xp
0.28EPSS
CVE-2015-2521
High 9.3

Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.28EPSS
CVE-2015-2520
High 9.3

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.28EPSS
CVE-2015-2467
High 9.3

Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.28EPSS
CVE-2003-0814
High 7.5

Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "…

microsoft ie · microsoft internet_explorer
0.28EPSS
CVE-2007-2353
Medium 5.0

Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which reveals the installation path in the resulting exception message.

apache axis
0.28EPSS
CVE-2001-0722
Medium 6.4

Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, aka the "First Cookie Handling Vulnerability."

microsoft internet_explorer
0.28EPSS
CVE-2013-3188
High 9.3

Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3189…

microsoft internet_explorer
0.28EPSS
CVE-2009-1141
High 9.3

Microsoft Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2 allows remote attackers to execute arbitrary code via unspecified DHTML function calls related to a tr element and the "insertion, deletion and attributes of a table cell," which trig…

microsoft internet_explorer
0.28EPSS
CVE-2022-20966
Medium 5.4

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to conduct cross-site scripting attacks against other users of the application web-based management interface. This vulnera…

cisco identity_services_engine
0.28EPSS