imPC@ndo IT

CVE Tracker

56.415 CVE

CVE-2015-5127
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.50EPSS
CVE-2017-8541
High 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft forefront_security · microsoft malware_protection_engine · microsoft windows_defender
0.50EPSS
CVE-2017-8538
High 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft forefront_security · microsoft malware_protection_engine · microsoft windows_defender
0.50EPSS
CVE-2010-3229
High 7.1

The Secure Channel (aka SChannel) security package in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when IIS 7.x is used, does not properly process client certificates during SSL and TLS handshakes, which allows rem…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.50EPSS
CVE-2010-0477
High 10.0

The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code via a crafted packet that causes the c…

microsoft windows_7 · microsoft windows_server_2008
0.50EPSS
CVE-2020-17518
High 7.5

Apache Flink 1.5.1 introduced a REST handler that allows you to write an uploaded file to an arbitrary location on the local file system, through a maliciously modified HTTP HEADER. The files can be written to any location accessible by Flink 1.5.1. All users …

apache flink
0.50EPSS
CVE-2022-37961
High 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.50EPSS
CVE-2021-21342
Medium 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream create…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 11 more
0.50EPSS
CVE-2021-26414
Medium 4.8

Windows DCOM Server Security Feature Bypass

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 6 more
0.50EPSS
CVE-2003-0309
High 7.5

Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to bypass security zone restrictions and execute arbitrary programs via a web document with a large number of duplicate file:// or other requests that point to the program and open multiple file down…

microsoft internet_explorer
0.50EPSS
CVE-2019-15980
High 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints and the Application Framework feature of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. To exploit…

cisco data_center_network_manager
0.50EPSS
CVE-2004-0572
High 10.0

Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.

microsoft grpconv
0.50EPSS
CVE-2023-28709
High 7.5

The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query str…

apache tomcat · debian debian_linux · netapp 7-mode_transition_tool
0.50EPSS
CVE-2005-1219
High 7.5

Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.

microsoft image_color_management
0.50EPSS
CVE-2016-6909
Critical 9.8

Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

fortinet fortios · fortinet fortiswitch
0.50EPSS
CVE-2016-3313
High 7.8

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office · microsoft word_for_mac · microsoft word_viewer
0.50EPSS
CVE-2002-1217
High 7.5

Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code, read arbitrary files, or conduct other unauthorized activities via script that accesses the Document prope…

microsoft internet_explorer
0.50EPSS
CVE-2017-8682
High 8.8

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Servi…

microsoft office_2007 · microsoft office_2010 · microsoft office_word_viewer · microsoft windows_10 · and 6 more
0.50EPSS
CVE-2018-15439
Critical 9.8

A vulnerability in the Cisco Small Business Switches software could allow an unauthenticated, remote attacker to bypass the user authentication mechanism of an affected device. The vulnerability exists because under specific circumstances, the affected softwar…

cisco sf200-24_firmware · cisco sf200-24fp_firmware · cisco sf200-24p_firmware · cisco sf200-48_firmware · and 110 more
0.50EPSS
CVE-2019-5436
High 7.8

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

debian debian_linux · f5 traffix_signaling_delivery_controller · fedoraproject fedora · haxx libcurl · and 7 more
0.50EPSS
CVE-2026-23918
High 8.8

Double Free and possible RCE vulnerability in Apache HTTP Server with the HTTP/2 protocol. This issue affects Apache HTTP Server: 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.

apache http_server
0.50EPSS
CVE-2002-0642
High 7.2

The registry key containing the SQL Server service account information in Microsoft SQL Server 2000, including Microsoft SQL Server Desktop Engine (MSDE) 2000, has insecure permissions, which allows local users to gain privileges, aka "Incorrect Permission on …

microsoft msde · microsoft sql_server
0.50EPSS
CVE-2019-0785
Critical 9.8

A memory corruption vulnerability exists in the Windows Server DHCP service when an attacker sends specially crafted packets to a DHCP failover server, aka 'Windows DHCP Server Remote Code Execution Vulnerability'.

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019
0.50EPSS
CVE-2018-3956
High 7.1

An exploitable out-of-bounds read vulnerability exists in the handling of certain XFA element attributes of Foxit Software's PDF Reader version 9.1.0.5096. A specially crafted PDF document can trigger an out-of-bounds read, which can disclose sensitive memory …

foxitsoftware phantompdf · foxitsoftware reader
0.50EPSS
CVE-2006-0006
High 9.3

Heap-based buffer overflow in the bitmap processing routine in Microsoft Windows Media Player 7.1 on Windows 2000 SP4, Media Player 9 on Windows 2000 SP4 and XP SP1, and Media Player 10 on XP SP1 and SP2 allows remote attackers to execute arbitrary code via a …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 3 more
0.50EPSS