imPC@ndo IT

CVE Tracker

56.415 CVE

CVE-2021-27068
High 8.8

Visual Studio Remote Code Execution Vulnerability

microsoft visual_studio_2019
0.54EPSS
CVE-2002-1143
Medium 5.0

Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in …

microsoft excel · microsoft word
0.54EPSS
CVE-2023-32029
High 7.8

Microsoft Excel Remote Code Execution Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_long_term_servicing_channel · and 1 more
0.54EPSS
CVE-2002-1254
High 7.5

Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached…

microsoft ie · microsoft internet_explorer
0.54EPSS
CVE-2023-39456
High 7.5

Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2. Users are recommended to upgrade to version 9.2.3, which fixes the issue.

apache traffic_server · fedoraproject fedora
0.53EPSS
CVE-2006-5583
High 10.0

Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability."

microsoft windows_2003_server
0.53EPSS
CVE-2020-35452
High 7.3

Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler…

apache http_server · debian debian_linux · fedoraproject fedora · oracle enterprise_manager_ops_center · and 2 more
0.53EPSS
CVE-2021-23017
High 7.7

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

f5 nginx · fedoraproject fedora · netapp ontap_select_deploy_administration_utility · openresty openresty · and 9 more
0.53EPSS
CVE-2011-0104
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka "…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.53EPSS
CVE-2016-2211
High 7.8

The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) fo…

symantec advanced_threat_protection · symantec csapi · symantec data_center_security_server · symantec endpoint_protection · and 14 more
0.53EPSS
CVE-2020-1074
High 7.8

<p>A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system.</p> <p>An attacker could explo…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.53EPSS
CVE-2005-1978
High 7.5

COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.53EPSS
CVE-1999-0191
Medium 6.4

IIS newdsn.exe CGI script allows remote users to overwrite files.

microsoft internet_information_server
0.53EPSS
CVE-2002-0072
Medium 5.0

The w3svc.dll ISAPI filter in Front Page Server Extensions and ASP.NET for Internet Information Server (IIS) 4.0, 5.0, and 5.1 does not properly handle the error condition when a long URL is provided, which allows remote attackers to cause a denial of service …

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2002-0149
High 7.5

Buffer overflow in ASP Server-Side Include Function in IIS 4.0, 5.0 and 5.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via long file names.

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2010-0248
High 8.1

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka…

microsoft internet_explorer
0.53EPSS
CVE-2018-0840
High 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote cod…

microsoft edge · microsoft internet_explorer
0.53EPSS
CVE-2002-0073
Medium 5.0

The FTP service in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows attackers who have established an FTP session to cause a denial of service via a specially crafted status request containing glob characters.

microsoft internet_information_server · microsoft internet_information_services
0.53EPSS
CVE-2009-1955
High 7.5

The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted …

apache apr-util · apache http_server · apple mac_os_x · canonical ubuntu_linux · and 4 more
0.53EPSS
CVE-2021-34501
High 7.8

Microsoft Excel Remote Code Execution Vulnerability

microsoft 365_apps · microsoft excel · microsoft office · microsoft office_online_server
0.53EPSS
CVE-2021-22160
Critical 9.8

If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the token is not validated if the algorithm of the presented token is set to "none". This allows an attacker to connect to Pulsar instances as …

apache pulsar
0.53EPSS
CVE-2024-38023
High 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.53EPSS
CVE-2007-5348
High 9.3

Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe…

microsoft digital_image_suite · microsoft forefront_client_security · microsoft internet_explorer · microsoft office · and 12 more
0.53EPSS
CVE-2022-35823
High 8.8

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.53EPSS
CVE-2019-10097
High 7.2

In Apache HTTP Server 2.4.32-2.4.39, when mod_remoteip was configured to use a trusted intermediary proxy server using the "PROXY" protocol, a specially crafted PROXY header could trigger a stack buffer overflow or NULL pointer deference. This vulnerability co…

apache http_server · oracle communications_element_manager · oracle communications_session_report_manager · oracle communications_session_route_manager · and 4 more
0.53EPSS