imPC@ndo IT

CVE Tracker

56.415 CVE

CVE-2015-5133
High 10.0

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary cod…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.51EPSS
CVE-2015-5132
High 10.0

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary cod…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.51EPSS
CVE-2015-5131
High 10.0

Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary cod…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.51EPSS
CVE-2007-4336
Medium 4.3

Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long S…

microsoft directx_media
0.51EPSS
CVE-2016-0957
High 7.5

Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

adobe dispatcher · adobe experience_manager
0.51EPSS
CVE-2022-22956
Critical 9.8

VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authent…

vmware identity_manager · vmware vrealize_automation · vmware workspace_one_access
0.51EPSS
CVE-2004-0120
Medium 5.0

The Microsoft Secure Sockets Layer (SSL) library, as used in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service via malformed SSL messages.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.51EPSS
CVE-2021-28474
High 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_foundation · microsoft sharepoint_server
0.51EPSS
CVE-2021-39840
High 7.8

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the …

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.51EPSS
CVE-2011-3639
Medium 4.3

The mod_proxy module in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x before 2.2.18, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a rever…

apache http_server · apache http_server2.0a1 · apache http_server2.0a2 · apache http_server2.0a3 · and 6 more
0.51EPSS
CVE-2005-0553
Medium 5.1

Race condition in the memory management routines in the DHTML object processor in Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail, aka "DHTML Object Memory Corruption Vulner…

microsoft ie · microsoft internet_explorer
0.51EPSS
CVE-2000-0457
High 7.5

ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" …

microsoft internet_information_server · microsoft internet_information_services
0.51EPSS
CVE-2021-33035
High 7.8

Apache OpenOffice opens dBase/DBF documents and shows the contents as spreadsheets. DBF are database files with data organized in fields. When reading DBF data the size of certain fields is not checked: the data is just copied into local variables. A carefully…

apache openoffice
0.51EPSS
CVE-2001-1410
Medium 5.0

Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createPopup method, which could allow attackers to simulate a victim's display and conduct unauthorized activities or steal sensitive data via soci…

microsoft internet_explorer
0.51EPSS
CVE-2013-1884
Medium 5.0

The mod_dav_svn Apache HTTPD server module in Subversion 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (segmentation fault and crash) via a log REPORT request with an invalid limit, which triggers an access of an uninitialized variab…

apache subversion
0.51EPSS
CVE-2016-3304
High 7.8

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allo…

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 4 more
0.51EPSS
CVE-2016-3303
High 7.8

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Viewer, Skype for Business 2016, Lync 2013 SP1, Lync 2010, Lync 2010 Attendee, and Live Meeting 2007 Console allo…

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 4 more
0.51EPSS
CVE-2018-8133
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.51EPSS
CVE-2017-0108
High 7.8

The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Live Meeting 2007; Silverlight 5; Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; and Windows 7 SP1 allows remote …

microsoft live_meeting · microsoft lync · microsoft office · microsoft silverlight · and 5 more
0.50EPSS
CVE-2022-23943
Critical 9.8

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

apache http_server · debian debian_linux · fedoraproject fedora · oracle http_server · and 1 more
0.50EPSS
CVE-2013-3128
High 9.3

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5, allo…

microsoft .net_framework · microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · and 5 more
0.50EPSS
CVE-2017-8751
High 7.5

Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique…

microsoft edge
0.50EPSS
CVE-2017-8594
High 7.5

Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memor…

microsoft internet_explorer
0.50EPSS
CVE-2015-5134
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.50EPSS
CVE-2015-5130
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.50EPSS