imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2024-26256
High 7.8

Libarchive Remote Code Execution Vulnerability

fedoraproject fedora · libarchive libarchive · microsoft windows_11_22h2 · microsoft windows_11_23h2 · and 1 more
0.88EPSS
CVE-2020-27131
High 8.1

Multiple vulnerabilities in the Java deserialization function that is used by Cisco Security Manager could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. These vulnerabilities are due to insecure deserialization …

cisco security_manager
0.88EPSS
CVE-2013-2028
High 7.5

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an…

f5 nginx · fedoraproject fedora
0.87EPSS
CVE-2024-36104
Critical 9.1

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.14. Users are recommended to upgrade to version 18.12.14, which fixes the issue.

apache ofbiz
0.87EPSS
CVE-2019-9515
High 7.5

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an e…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · and 18 more
0.87EPSS
CVE-2000-1209
High 10.0

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight …

compaq insight_manager · compaq insight_manager_xe · microsoft data_engine · microsoft msde
0.87EPSS
CVE-2015-3090
High 10.0

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to e…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.87EPSS
CVE-2009-3555
Critical 9.8

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Servi…

apache http_server · canonical ubuntu_linux · debian debian_linux · f5 nginx · and 4 more
0.87EPSS
CVE-2018-15381
Critical 9.8

A Java deserialization vulnerability in Cisco Unity Express (CUE) could allow an unauthenticated, remote attacker to execute arbitrary shell commands with the privileges of the root user. The vulnerability is due to insecure deserialization of user-supplied co…

cisco unity_express
0.87EPSS
CVE-2019-11358
Medium 6.1

jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Obje…

backdropcms backdrop · debian debian_linux · drupal drupal · fedoraproject fedora · and 101 more
0.87EPSS
CVE-2017-12611
Critical 9.8

In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag instead of string literals can lead to a RCE attack.

apache struts
0.87EPSS
CVE-2022-31706
Critical 9.8

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

vmware vrealize_log_insight
0.87EPSS
CVE-2008-5416
High 9.0

Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and…

microsoft sql_server
0.87EPSS
CVE-2018-4993
High 7.5

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an NTLM SSO hash theft vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.87EPSS
CVE-1999-0067
High 10.0

phf CGI program allows remote command execution through shell metacharacters.

apache http_server · ncsa ncsa_httpd
0.87EPSS
CVE-2018-0101
Critical 10.0

A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause a reload of the affected system or to remotely execute code. The vulnerability …

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.87EPSS
CVE-2005-4360
High 7.8

The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to prod…

microsoft internet_information_services
0.87EPSS
CVE-2020-13935
High 7.5

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid paylo…

apache tomcat · canonical ubuntu_linux · debian debian_linux · mcafee epolicy_orchestrator · and 14 more
0.87EPSS
CVE-2023-36035
High 8.0

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.87EPSS
CVE-2003-0718
Medium 5.0

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l…

microsoft internet_information_server · microsoft internet_information_services
0.87EPSS
CVE-2005-4560
High 7.5

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and…

microsoft windows_2003_server · microsoft windows_xp
0.86EPSS
CVE-2011-2110
High 10.0

Adobe Flash Player before 10.3.181.26 on Windows, Mac OS X, Linux, and Solaris, and 10.3.185.23 and earlier on Android, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in …

adobe flash_player
0.86EPSS
CVE-2000-0778
Medium 5.0

IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.

microsoft internet_information_services
0.86EPSS
CVE-2021-27907
Medium 5.4

Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describing chart's related information. Abusing this functionality, a malicious user could inject javascript code executing unwanted action in the c…

apache superset
0.86EPSS
CVE-2010-0483
High 7.6

vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC sha…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.86EPSS