IT

CVE Tracker

56.560 CVE

CVE-2002-0369
High 10.0

Buffer overflow in ASP.NET Worker Process allows remote attackers to cause a denial of service (restart) and possibly execute arbitrary code via a routine that processes cookies while in StateServer mode.

microsoft .net_framework
0.24EPSS
CVE-2007-6250
High 9.3

Stack-based buffer overflow in AOL AOLMediaPlaybackControl (AOLMediaPlaybackControl.exe), as used by AmpX ActiveX control (AmpX.dll), might allow remote attackers to execute arbitrary code via the AppendFileToPlayList method.

aol aolmediaplaybackcontrol · microsoft ampx
0.24EPSS
CVE-2024-43452
High 7.5

Windows Registry Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · microsoft windows_11_22h2 · and 7 more
0.24EPSS
CVE-2010-0917
High 7.6

Stack-based buffer overflow in VBScript in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, might allow user-assisted remote attackers to execute arbitrary code via a long string in the fourth argument (aka helpf…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.24EPSS
CVE-2009-3560
Medium 5.0

The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a …

apache http_server · libexpat_project libexpat
0.24EPSS
CVE-2005-0054
Medium 5.1

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to spoof a less restrictive security zone and execute arbitrary code via an HTML page containing URLs that contain hostnames that have been double hex encoded, which are decoded twice to generate a mal…

microsoft ie · microsoft internet_explorer
0.24EPSS
CVE-2016-7117
Critical 9.8

Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

canonical ubuntu_linux · debian debian_linux · linux linux_kernel
0.24EPSS
CVE-2023-33299
Critical 9.8

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to execute unauthorized code or commands via specifically crafted request on inter-server communication port. Note Fo…

fortinet fortinac
0.24EPSS
CVE-2024-26230
High 7.8

Windows Telephony Server Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.24EPSS
CVE-2005-3357
Medium 5.4

mod_ssl in Apache 2.0 up to 2.0.55, when configured with an SSL vhost with access control and a custom error 400 error page, allows remote attackers to cause a denial of service (application crash) via a non-SSL request to an SSL port, which triggers a NULL po…

apache http_server
0.24EPSS
CVE-2006-3898
Medium 5.0

Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.

microsoft internet_explorer
0.24EPSS
CVE-2006-3899
Medium 5.0

Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid mem…

microsoft internet_explorer
0.24EPSS
CVE-2006-3605
Medium 5.0

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.

microsoft internet_explorer
0.24EPSS
CVE-2006-3512
Medium 5.0

Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.

microsoft internet_explorer
0.24EPSS
CVE-2006-3427
Medium 5.0

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by declaring the sourceURL attribute on an uninitialized DirectAnimation.StructuredGraphicsControl ActiveX Object, which triggers a null dereference.

microsoft internet_explorer
0.24EPSS
CVE-2012-0150
High 9.3

Buffer overflow in msvcrt.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, aka "Msvcrt.dll Buffer Overflow Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.24EPSS
CVE-2010-0821
High 9.3

Unspecified vulnerability in Microsoft Office Excel 2002 SP3, 2003 SP3, 2007 SP1 and SP2; Office 2004 for mac; Office 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and Powe…

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · and 1 more
0.24EPSS
CVE-2017-0292
High 7.8

Windows PDF in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows remote code execution if a user opens a specially crafted PDF file, aka "Windows PDF Remote Code Execution Vulnerabil…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 2 more
0.24EPSS
CVE-2013-0077
High 9.3

Quartz.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows remote attackers to execute arbitrary code via crafted media content in (1) a media file, (2) a media stream, or (3) a Microsoft Office documen…

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.24EPSS
CVE-2007-0087
High 7.8

Microsoft Internet Information Services (IIS), when accessed through a TCP connection with a large window size, allows remote attackers to cause a denial of service (network bandwidth consumption) via a Range header that specifies multiple copies of the same f…

microsoft internet_information_server
0.24EPSS
CVE-2010-2560
High 9.3

Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML …

microsoft internet_explorer
0.24EPSS
CVE-2011-0092
High 9.3

The LZW stream decompression functionality in ORMELEMS.DLL in Microsoft Visio 2002 SP2, 2003 SP3, and 2007 SP2 allows remote attackers to execute arbitrary code via a Visio file with a malformed VisioDocument stream that triggers an exception handler that acce…

microsoft visio
0.24EPSS
CVE-2012-0184
High 9.3

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 and 2011 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitra…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.24EPSS
CVE-2010-0487
High 9.3

The Authenticode Signature verification functionality in cabview.dll in Cabinet File Viewer Shell Extension 5.1, 6.0, and 6.1 in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.24EPSS
CVE-2012-4786
High 10.0

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.24EPSS