imPC@ndo IT

CVE Tracker

56.413 CVE

CVE-2003-0245
Medium 5.0

Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XM…

apache http_server
0.62EPSS
CVE-2017-11839
High 7.5

Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to take control of an affected system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Co…

microsoft edge
0.62EPSS
CVE-2024-43642
High 7.5

Windows SMB Denial of Service Vulnerability

microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_11_24h2 · microsoft windows_server_2022 · and 2 more
0.62EPSS
CVE-2023-38039
High 7.5

When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server…

fedoraproject fedora · haxx curl · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 6 more
0.62EPSS
CVE-2006-4446
Medium 5.0

Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a Spline function call whose first argument s…

microsoft ie
0.62EPSS
CVE-2009-2532
High 10.0

Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process the command value in an SMB Multi-Protocol Negotiate Request packet, which allows remote attackers to execute arbitrary code via a crafted SM…

microsoft windows_server_2008 · microsoft windows_vista
0.62EPSS
CVE-2017-6622
Critical 9.8

A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to bypass authentication and perform command injection with root privileges. The vulnerability is due to missing security constraint…

cisco prime_collaboration_provisioning
0.62EPSS
CVE-2023-28503
Critical 9.8

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from an authentication bypass vulnerability, where a special username with a deterministic password can be leveraged to bypa…

rocketsoftware unidata · rocketsoftware universe
0.62EPSS
CVE-2020-3495
Critical 9.9

A vulnerability in Cisco Jabber for Windows could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sending specially crafted …

cisco jabber
0.62EPSS
CVE-2018-8384
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-82…

microsoft chakracore
0.62EPSS
CVE-2016-1286
High 8.6

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · isc bind · and 10 more
0.62EPSS
CVE-2021-28325
Medium 6.5

Windows SMB Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 2 more
0.62EPSS
CVE-2009-1136
High 9.3

The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 and Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Offic…

microsoft isa_server · microsoft office · microsoft office_web_components · microsoft office_xp
0.62EPSS
CVE-2010-1892
High 7.8

The TCP/IP stack in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly handle malformed IPv6 packets, which allows remote attackers to cause a denial of service (system hang) via multiple crafted packets…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.62EPSS
CVE-2015-3088
High 10.0

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 1…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.62EPSS
CVE-2005-2120
Medium 6.5

Stack-based buffer overflow in the Plug and Play (PnP) service (UMPNPMGR.DLL) in Microsoft Windows 2000 SP4, and XP SP1 and SP2, allows remote or local authenticated attackers to execute arbitrary code via a large number of "\" (backslash) characters in a regi…

microsoft windows_2000 · microsoft windows_xp
0.62EPSS
CVE-2006-3441
High 10.0

Buffer overflow in the DNS Client service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted record response. NOTE: while MS06-041 implies that there is a single issue, there are …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.62EPSS
CVE-2008-0086
High 9.0

Buffer overflow in the convert function in Microsoft SQL Server 2000 SP4, 2000 Desktop Engine (MSDE 2000) SP4, and 2000 Desktop Engine (WMSDE) allows remote authenticated users to execute arbitrary code via a crafted SQL expression.

microsoft data_engine · microsoft sql_server · microsoft sql_server_desktop_engine · microsoft sql_server_express_edition
0.62EPSS
CVE-2006-1245
High 7.5

Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstr…

microsoft ie
0.62EPSS
CVE-2012-1875
High 9.3

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."

microsoft internet_explorer
0.62EPSS
CVE-2022-41076
High 8.5

PowerShell Remote Code Execution Vulnerability

microsoft powershell · microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · and 7 more
0.62EPSS
CVE-2021-34847
High 7.8

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

foxit pdf_reader · foxitsoftware pdf_editor
0.62EPSS
CVE-2020-3251
High 8.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.62EPSS
CVE-2005-2123
High 7.5

Multiple integer overflows in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allow remote attackers to execute arbitrary code via crafted Windows Metafile (WMF) and Enhanced Metafile (EMF) format images that …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.61EPSS
CVE-2024-1883
Medium 6.3

This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server. An attacker can exploit this weakness by crafting a malicious URL that contains a script. When an unsuspecting user clicks on this malicious link, it could potenti…

papercut papercut_mf · papercut papercut_ng
0.61EPSS