imPC@ndo IT

CVE Tracker

56.434 CVE

CVE-2022-35748
High 7.5

HTTP.sys Denial of Service Vulnerability

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · and 1 more
0.47EPSS
CVE-2024-52012
Medium 5.4

Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API.  Commonly known as a "zipslip", maliciously constructed…

apache solr
0.47EPSS
CVE-2016-3316
High 7.8

Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft word · microsoft word_for_mac
0.47EPSS
CVE-2018-16843
High 7.5

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'l…

apple xcode · canonical ubuntu_linux · debian debian_linux · f5 nginx · and 1 more
0.47EPSS
CVE-2018-1323
High 7.5

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-worker map did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exp…

apache tomcat_jk_connector
0.47EPSS
CVE-2023-27363
High 7.8

Foxit PDF Reader exportXFAData Exposed Dangerous Method Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulner…

foxit pdf_editor · foxit pdf_reader
0.47EPSS
CVE-2004-0214
High 10.0

Buffer overflow in Microsoft Internet Explorer and Explorer on Windows XP SP1, WIndows 2000, Windows 98, and Windows Me may allow remote malicious servers to cause a denial of service (application crash) and possibly execute arbitrary code via long share names…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_98 · microsoft windows_me · and 1 more
0.47EPSS
CVE-2019-15984
High 7.2

Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to execute arbitrary SQL commands on an affected device. To exploit these vulnerabilities, an attacker would n…

cisco data_center_network_manager
0.47EPSS
CVE-2019-1636
High 7.8

A vulnerability in the Cisco Webex Teams client, formerly Cisco Spark, could allow an attacker to execute arbitrary commands on a targeted system. This vulnerability is due to unsafe search paths used by the application URI that is defined in Windows operating…

cisco webex_teams
0.47EPSS
CVE-2023-24998
High 7.5

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the …

apache commons_fileupload · debian debian_linux
0.47EPSS
CVE-2021-21349
Medium 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the …

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 13 more
0.47EPSS
CVE-2011-0096
Medium 6.1

The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for content blocks…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.47EPSS
CVE-2014-0282
High 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.47EPSS
CVE-2005-0050
High 10.0

The License Logging service for Windows NT Server, Windows 2000 Server, and Windows Server 2003 does not properly validate the length of messages, which leads to an "unchecked buffer" and allows remote attackers to cause a denial of service (crash) and possibl…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt
0.47EPSS
CVE-2021-21343
Medium 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream create…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · and 11 more
0.47EPSS
CVE-2007-4676
High 9.3

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.

apple mac_os_x · microsoft windows_vista · microsoft windows_xp
0.47EPSS
CVE-2007-4677
High 9.3

Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via an invalid color table size when parsing the color table atom (CTAB) in a movie file, related to the CTAB RGB values.

apple mac_os_x · microsoft windows_vista · microsoft windows_xp
0.47EPSS
CVE-2023-6184
Medium 5.0

Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting

citrix virtual_apps_and_desktops
0.47EPSS
CVE-2007-5000
Medium 4.3

Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitra…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · opensuse opensuse · and 3 more
0.47EPSS
CVE-2005-0051
High 7.5

The Server service (srvsvc.dll) in Windows XP SP1 and SP2 allows remote attackers to obtain sensitive information (users who are accessing resources) via an anonymous logon using a named pipe, which is not properly authenticated, aka the "Named Pipe Vulnerabil…

microsoft windows_xp
0.47EPSS
CVE-2002-0597
Medium 5.0

LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) via a stream of malformed data to microsoft-ds port 445.

microsoft windows_2000
0.47EPSS
CVE-2020-24437
High 7.8

Acrobat Reader DC versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.47EPSS
CVE-2022-47939
Critical 9.8

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.

linux linux_kernel
0.46EPSS
CVE-2018-8413
High 7.8

A remote code execution vulnerability exists when "Windows Theme API" does not properly decompress files, aka "Windows Theme API Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2019, Windows …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.46EPSS
CVE-2020-2039
Medium 5.3

An uncontrolled resource consumption vulnerability in Palo Alto Networks PAN-OS allows for a remote unauthenticated user to upload temporary files through the management web interface that are not properly deleted after the request is finished. It is possible …

paloaltonetworks pan-os
0.46EPSS