imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2019-0233
High 7.5

An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.

apache struts · oracle communications_policy_management · oracle financial_services_data_integration_hub · oracle financial_services_market_risk_measurement_and_management · and 1 more
0.68EPSS
CVE-2004-0574
High 10.0

The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Server 2003, Exchange 2000 Server, and Exchange Server 2003 allows remote attackers to execute arbitrary code via XPAT patterns, possibly relat…

microsoft exchange_server · microsoft windows_2000 · microsoft windows_nt · microsoft windows_server_2003
0.68EPSS
CVE-2013-4547
High 7.5

nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

f5 nginx · opensuse opensuse · suse lifecycle_management_server · suse studio_onsite · and 1 more
0.68EPSS
CVE-2018-8353
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer …

microsoft internet_explorer
0.68EPSS
CVE-2005-0803
Medium 5.0

The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (application crash) via a crafted Enhanced Metafile (EMF) file that causes invalid (1) end, (2) emreof, or (3) palent offsets to be used, aka…

microsoft windows_2000
0.68EPSS
CVE-2010-3970
High 9.3

Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor (aka graphics rendering engine) in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 allow…

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.68EPSS
CVE-2012-1447
Medium 4.3

The ELF file parser in Fortinet Antivirus 4.2.254.0, eSafe 7.0.17.0, Dr.Web 5.0.2.03300, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified e_version field. NOTE: this may later be SPLIT into multi…

aladdin esafe · drweb dr.web_antivirus · fortinet fortinet_antivirus · pandasecurity panda_antivirus
0.68EPSS
CVE-2017-8548
High 7.5

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Memory C…

microsoft edge
0.68EPSS
CVE-2020-0610
Critical 9.8

A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote C…

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.68EPSS
CVE-2023-3765
Critical 10.0

Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.

lfprojects mlflow
0.68EPSS
CVE-2010-3332
Medium 6.4

Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Internet Information Services (IIS), provides detailed error codes during decryption attempts, which allows remote attackers to decrypt and modify…

microsoft .net_framework
0.67EPSS
CVE-2022-41034
High 7.8

Visual Studio Code Remote Code Execution Vulnerability

microsoft visual_studio_code
0.67EPSS
CVE-2023-24950
Medium 6.5

Microsoft SharePoint Server Spoofing Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
0.67EPSS
CVE-1999-0612
Low 0.0

A version of finger is running that exposes valid user information to any entity on the network.

gnu finger_service · gnu fingerd · microsoft windows_2000 · microsoft windows_nt
0.67EPSS
CVE-2006-2086
High 7.5

Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, all…

juniper junipersetup_control
0.67EPSS
CVE-2010-1681
High 7.6

Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.

microsoft visio
0.67EPSS
CVE-2025-48976
High 7.5

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrad…

apache commons_fileupload
0.67EPSS
CVE-2022-25813
High 7.5

In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th…

apache ofbiz
0.67EPSS
CVE-2023-36606
High 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 8 more
0.67EPSS
CVE-2004-1050
High 10.0

Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability…

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s3400 · and 3 more
0.67EPSS
CVE-2009-0133
High 10.0

Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary code via a .hhp file with a long "Index file" field, possibly a related issue to CVE-2006-0564.

microsoft html_help_workshop
0.67EPSS
CVE-2000-0886
High 7.5

IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name is appended with operating system commands, aka the "Web Server File Request Parsing" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.67EPSS
CVE-2019-0618
High 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.67EPSS
CVE-2016-7190
High 7.5

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.67EPSS
CVE-2021-28560
High 8.8

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.67EPSS