imPC@ndo IT

CVE Tracker

56.415 CVE

CVE-2001-0538
High 10.0

Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page.

microsoft outlook
0.53EPSS
CVE-2017-18017
Critical 9.8

The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by le…

arista eos · canonical ubuntu_linux · debian debian_linux · f5 arx · and 25 more
0.53EPSS
CVE-2018-8021
Critical 9.8

Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

apache superset
0.53EPSS
CVE-2021-31213
High 7.8

Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability

microsoft remote
0.53EPSS
CVE-2020-24435
High 7.8

Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a heap-based buffer overflow vulnerability in the submitForm function, potentially resulting in arbitrary code execution in t…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.53EPSS
CVE-2008-2370
Medium 5.0

Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attack…

apache tomcat
0.53EPSS
CVE-2021-34478
High 7.8

Microsoft Office Remote Code Execution Vulnerability

microsoft 365_apps · microsoft office
0.53EPSS
CVE-2008-0108
High 9.3

Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft W…

microsoft office · microsoft works
0.53EPSS
CVE-2021-30641
Medium 5.3

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

apache http_server · debian debian_linux · fedoraproject fedora · oracle enterprise_manager_ops_center · and 2 more
0.53EPSS
CVE-2003-1041
High 7.5

Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not h…

microsoft ie · microsoft internet_explorer
0.53EPSS
CVE-2009-3958
High 10.0

Multiple stack-based buffer overflows in the NOS Microsystems getPlus Helper ActiveX control before 1.6.2.49 in gp.ocx in the Download Manager in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, might allow remote attackers …

adobe acrobat · adobe acrobat_reader
0.53EPSS
CVE-2017-8734
High 7.5

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Co…

microsoft edge
0.53EPSS
CVE-2010-1157
Low 2.6

Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field …

apache tomcat
0.53EPSS
CVE-2021-20081
High 7.2

Incomplete List of Disallowed Inputs in ManageEngine ServiceDesk Plus before version 11205 allows a remote, authenticated attacker to execute arbitrary commands with SYSTEM privileges.

zohocorp manageengine_servicedesk_plus
0.52EPSS
CVE-2016-0710
High 8.8

Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.

apache jetspeed
0.52EPSS
CVE-2008-3471
High 9.3

Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.52EPSS
CVE-2007-3898
Medium 6.4

The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors.…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003
0.52EPSS
CVE-2002-0147
High 7.5

Buffer overflow in the ASP data transfer mechanism in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to cause a denial of service or execute code, aka "Microsoft-discovered variant of Chunked Encoding buffer overrun."

microsoft internet_information_server · microsoft internet_information_services
0.52EPSS
CVE-2008-3013
High 9.3

gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 200…

microsoft digital_image_suite · microsoft forefront_client_security · microsoft internet_explorer · microsoft office · and 9 more
0.52EPSS
CVE-2018-25032
High 7.5

zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

apple mac_os_x · apple macos · azul zulu · debian debian_linux · and 23 more
0.52EPSS
CVE-2008-1898
High 9.3

A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface pro…

microsoft office · microsoft works
0.52EPSS
CVE-2020-1934
Medium 5.3

In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · and 7 more
0.52EPSS
CVE-2007-3034
High 9.3

Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted metafile (image) with a large record length value, which…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.52EPSS
CVE-2024-20440
High 7.5

A vulnerability in Cisco Smart Licensing Utility could allow an unauthenticated, remote attacker to access sensitive information. This vulnerability is due to excessive verbosity in a debug log file. An attacker could exploit this vulnerability by sending a…

cisco smart_license_utility
0.52EPSS
CVE-2022-36534
High 8.8

Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.

syncovery syncovery
0.52EPSS