imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2012-0394
Medium 6.8

The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers to execute arbitrary commands via unspecified vectors. NOTE: the vendor characterizes this behavior as not "a security vulnerability itsel…

apache struts
0.74EPSS
CVE-2017-8046
Critical 9.8

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

pivotal_software spring_data_rest · vmware spring_boot · vmware spring_data_rest
0.74EPSS
CVE-2020-10188
Critical 9.8

utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.

arista eos · debian debian_linux · fedoraproject fedora · juniper junos · and 2 more
0.74EPSS
CVE-2015-3087
High 10.0

Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.74EPSS
CVE-2012-0002
High 9.3

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly process packets in memory, which allows remo…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.74EPSS
CVE-2013-0081
Medium 5.0

Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoi…

microsoft sharepoint_foundation · microsoft sharepoint_portal_server · microsoft sharepoint_server · microsoft sharepoint_services
0.74EPSS
CVE-2007-2897
High 7.5

Microsoft Internet Information Services (IIS) 6.0 allows remote attackers to cause a denial of service (server instability or device hang), and possibly obtain sensitive information (device communication traffic); and might allow attackers with physical access…

microsoft internet_information_server
0.74EPSS
CVE-2016-9244
High 7.5

A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session …

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · and 6 more
0.74EPSS
CVE-2019-10098
Medium 6.1

In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an unexpected URL within the request URL.

apache http_server
0.74EPSS
CVE-2005-1213
High 7.5

Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.

microsoft outlook_express
0.74EPSS
CVE-2020-3248
Critical 9.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.74EPSS
CVE-2005-0059
High 10.0

Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.

microsoft windows_2000 · microsoft windows_98 · microsoft windows_98se · microsoft windows_xp
0.74EPSS
CVE-2014-0659
High 10.0

The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x through 2.0.2.1, and RVS4000 router with firmware through 2.0.3.2 allow remote attackers to read credential and configuration data, and exe…

cisco rvs4000 · cisco rvs4000_firmware · cisco wap4410n · cisco wap4410n_firmware · and 2 more
0.74EPSS
CVE-2013-1814
Medium 4.0

The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field …

apache rave
0.74EPSS
CVE-2012-0013
High 9.3

Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arb…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.74EPSS
CVE-2019-1234
High 7.5

A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.

microsoft azure_stack
0.74EPSS
CVE-2018-5390
High 7.5

Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.

a10networks advanced_core_operating_system · canonical ubuntu_linux · cisco collaboration_meeting_rooms · cisco digital_network_architecture_center · and 34 more
0.74EPSS
CVE-2005-3352
Medium 4.3

Cross-site scripting (XSS) vulnerability in the mod_imap module of Apache httpd before 1.3.35-dev and Apache httpd 2.0.x before 2.0.56-dev allows remote attackers to inject arbitrary web script or HTML via the Referer when using image maps.

apache http_server
0.74EPSS
CVE-2021-31195
Medium 6.5

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.74EPSS
CVE-2010-1240
High 9.3

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary loc…

adobe acrobat_reader
0.74EPSS
CVE-2008-0084
High 7.8

Unspecified vulnerability in the TCP/IP support in Microsoft Windows Vista allows remote DHCP servers to cause a denial of service (hang and restart) via a crafted DHCP packet.

microsoft windows_vista
0.74EPSS
CVE-2020-3239
High 8.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.74EPSS
CVE-2022-29885
High 7.5

The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the…

apache tomcat · debian debian_linux · oracle hospitality_cruise_shipboard_property_management_system
0.73EPSS
CVE-2020-4280
High 8.8

IBM QRadar SIEM 7.3 and 7.4 could allow a remote attacker to execute arbitrary commands on the system, caused by insecure deserialization of user-supplied content by the Java deserialization function. By sending a malicious serialized Java object, an attacker …

ibm qradar_security_information_and_event_manager
0.73EPSS
CVE-2009-3867
High 9.3

Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute a…

sun jdk · sun jre · sun sdk
0.73EPSS