imPC@ndo IT

CVE Tracker

56.415 CVE

CVE-2005-2124
High 7.6

Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Win…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.56EPSS
CVE-2013-3520
High 7.5

VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.

vmware vcenter_chargeback_manager
0.56EPSS
CVE-2019-14322
High 7.5

In Pallets Werkzeug before 0.15.5, SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.

palletsprojects werkzeug
0.56EPSS
CVE-2002-0186
High 7.5

Buffer overflow in the SQLXML ISAPI extension of Microsoft SQL Server 2000 allows remote attackers to execute arbitrary code via data queries with a long content-type parameter, aka "Unchecked Buffer in SQLXML ISAPI Extension."

microsoft sql_server
0.55EPSS
CVE-2007-2931
High 9.3

Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.

microsoft msn_messenger · microsoft windows_live_messenger
0.55EPSS
CVE-2018-10956
High 7.5

IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.

ipconfigure orchid_core_vms
0.55EPSS
CVE-2021-29200
Critical 9.8

Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack

apache ofbiz
0.55EPSS
CVE-2010-0266
High 9.3

Microsoft Office Outlook 2002 SP3, 2003 SP3, and 2007 SP1 and SP2 does not properly verify e-mail attachments with a PR_ATTACH_METHOD property value of ATTACH_BY_REFERENCE, which allows user-assisted remote attackers to execute arbitrary code via a crafted mes…

microsoft outlook
0.55EPSS
CVE-2011-1966
High 10.0

The DNS server in Microsoft Windows Server 2008 SP2, R2, and R2 SP1 does not properly handle NAPTR queries that trigger recursive processing, which allows remote attackers to execute arbitrary code via a crafted query, aka "DNS NAPTR Query Vulnerability."

microsoft windows_server_2008
0.55EPSS
CVE-2006-1388
High 7.5

Unspecified vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to execute HTA files via unknown vectors.

microsoft ie · microsoft internet_explorer
0.55EPSS
CVE-2004-0942
Medium 5.0

Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP GET request with a MIME header containing multiple lines with a large number of space characters.

apache http_server
0.55EPSS
CVE-2021-44521
Critical 9.1

When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. …

apache cassandra
0.55EPSS
CVE-2022-43396
High 8.8

In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf.

apache kylin
0.55EPSS
CVE-2006-0988
High 7.8

The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt
0.55EPSS
CVE-2018-0834
High 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.55EPSS
CVE-2007-4790
High 7.5

Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the Microsoft Visual FoxPro 6.0 fpole 1.0 Type Library; and Internet Explorer 5.01, 6 SP1 and SP2, and 7; allows remote attackers to execute arb…

microsoft internet_explorer · microsoft visual_foxpro
0.55EPSS
CVE-2003-0347
High 10.0

Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3 allows remote attackers to execute arbitrary code via a document with a long ID parameter.

microsoft office · microsoft project · microsoft visio · microsoft visual_basic
0.55EPSS
CVE-2008-2168
Medium 4.3

Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page.

apache http_server
0.55EPSS
CVE-2025-21285
High 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 11 more
0.55EPSS
CVE-2016-3357
High 7.8

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on Sh…

microsoft office · microsoft office_web_apps · microsoft office_web_apps_server · microsoft sharepoint_foundation · and 2 more
0.55EPSS
CVE-2010-3863
Medium 5.0

Apache Shiro before 1.1.0, and JSecurity 0.9.x, does not canonicalize URI paths before comparing them to entries in the shiro.ini file, which allows remote attackers to bypass intended access restrictions via a crafted request, as demonstrated by the /./accoun…

apache shiro · jsecurity jsecurity
0.55EPSS
CVE-2010-2227
Medium 6.4

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted…

apache tomcat
0.55EPSS
CVE-2007-2222
High 9.3

Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers…

microsoft internet_explorer
0.55EPSS
CVE-2005-1984
High 7.5

Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.55EPSS
CVE-2013-1305
High 7.8

HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."

microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2012
0.55EPSS