imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2015-4000
Low 3.7

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello wi…

apple iphone_os · apple mac_os_x · apple safari · canonical ubuntu_linux · and 21 more
1.00EPSS
CVE-2017-12635
Critical 9.8

Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.1 to submit _users documents with duplicate keys for 'roles' used for access control within the database, incl…

apache couchdb
1.00EPSS
CVE-2012-1459
Medium 4.3

The TAR file parser in AhnLab V3 Internet Security 2011.01.18.00, Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4,…

ahnlab v3_internet_security · alwil avast_antivirus · anti-virus vba32 · antiy avl_sdk · and 30 more
1.00EPSS
CVE-2022-39952
Critical 9.8

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute u…

fortinet fortinac
1.00EPSS
CVE-2012-1446
Medium 4.3

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Norman Antivirus 6.06.12, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, McAfee Gateway (fo…

aladdin esafe · antiy avl_sdk · ca etrust_vet_antivirus · cat quick_heal · and 10 more
1.00EPSS
CVE-2008-2938
Medium 4.3

Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the U…

apache tomcat
1.00EPSS
CVE-2019-0232
High 8.1

When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Window…

apache tomcat
1.00EPSS
CVE-2012-1443
Medium 4.3

The RAR file parser in ClamAV 0.96.4, Rising Antivirus 22.83.00.03, Quick Heal (aka Cat QuickHeal) 11.00, G Data AntiVirus 21, AVEngine 20101.3.0.103 in Symantec Endpoint Protection 11, Command Antivirus 5.2.11.5, Ikarus Virus Utilities T3 Command Line Scanner…

ahnlab v3_internet_security · aladdin esafe · alwil avast_antivirus · anti-virus vba32 · and 31 more
1.00EPSS
CVE-2014-0094
Medium 5.0

The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via the class parameter, which is passed to the getClass method.

apache struts
1.00EPSS
CVE-2021-25646
High 8.8

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possibl…

apache druid
0.99EPSS
CVE-2021-21978
Critical 9.8

VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input validation and lack of authorization leading to arbitrary file upload in logupload web application. An unauthorized attacker with network acces…

vmware view_planner
0.99EPSS
CVE-2011-3192
High 7.8

The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited i…

apache http_server · canonical ubuntu_linux · opensuse opensuse · suse linux_enterprise_server · and 1 more
0.99EPSS
CVE-2020-9496
Medium 6.1

XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03

apache ofbiz
0.99EPSS
CVE-2012-1442
Medium 4.3

The ELF file parser in Quick Heal (aka Cat QuickHeal) 11.00, McAfee Anti-Virus Scanning Engine 5.400.0.1158, McAfee Gateway (formerly Webwasher) 2010.1C, eSafe 7.0.17.0, Kaspersky Anti-Virus 7.0.0.125, F-Secure Anti-Virus 9.0.16160.0, Sophos Anti-Virus 4.61.0,…

aladdin esafe · antiy avl_sdk · cat quick_heal · f-secure f-secure_anti-virus · and 7 more
0.99EPSS
CVE-2019-11477
High 7.5

Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fix…

canonical ubuntu_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · and 20 more
0.99EPSS
CVE-2003-0352
High 7.5

Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary code via a malformed message, as exploited by the Blaster/MSblast/LovSAN and Nachi/Welchia worms.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.98EPSS
CVE-2012-1457
Medium 4.3

The TAR file parser in Avira AntiVir 7.11.1.163, Antiy Labs AVL SDK 2.0.3.7, avast! Antivirus 4.8.1351.0 and 5.0.677.0, AVG Anti-Virus 10.0.0.1190, Bitdefender 7.2, Quick Heal (aka Cat QuickHeal) 11.00, ClamAV 0.96.4, Command Antivirus 5.2.11.5, Emsisoft Anti-…

aladdin esafe · alwil avast_antivirus · anti-virus vba32 · antiy avl_sdk · and 24 more
0.98EPSS
CVE-2009-1122
High 7.5

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode URLs, which allows remote attackers to bypass authentication, and possibly read or create files, via a crafted HTTP request, aka "IIS 5.0 Web…

microsoft internet_information_services
0.98EPSS
CVE-2009-1535
High 7.5

The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-based protection mechanisms, and list folders or read, create, or modify files, via a %c0%af (Unicode / character) at an arbitrary position …

microsoft internet_information_services
0.98EPSS
CVE-2019-1821
High 8.8

A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating s…

cisco evolved_programmable_network_manager · cisco network_level_service · cisco prime_infrastructure
0.98EPSS
CVE-2012-0392
Medium 6.8

The CookieInterceptor component in Apache Struts before 2.3.1.1 does not use the parameter-name whitelist, which allows remote attackers to execute arbitrary commands via a crafted HTTP Cookie header that triggers Java code execution through a static method.

apache struts
0.98EPSS
CVE-2019-5736
High 8.6

runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of contain…

apache mesos · canonical ubuntu_linux · d2iq dc\/os · d2iq kubernetes_engine · and 15 more
0.98EPSS
CVE-2014-0112
High 7.5

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via a crafted request. NOTE: this vulnerability exists becau…

apache struts
0.98EPSS
CVE-2021-44832
Medium 6.6

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of…

apache log4j · cisco cloudcenter · debian debian_linux · fedoraproject fedora · and 18 more
0.98EPSS
CVE-2012-1462
Medium 4.3

The ZIP file parser in AhnLab V3 Internet Security 2011.01.18.00, AVG Anti-Virus 10.0.0.1190, Quick Heal (aka Cat QuickHeal) 11.00, Emsisoft Anti-Malware 5.1.0.1, eSafe 7.0.17.0, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.…

ahnlab v3_internet_security · aladdin esafe · avg avg_anti-virus · cat quick_heal · and 6 more
0.98EPSS