imPC@ndo IT

CVE Tracker

56.468 CVE

CVE-2014-2815
High 8.8

Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."

microsoft onenote
0.44EPSS
CVE-2001-0877
Medium 5.0

Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic …

microsoft windows_98 · microsoft windows_98se · microsoft windows_me · microsoft windows_xp
0.44EPSS
CVE-2018-8625
High 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

microsoft internet_explorer
0.44EPSS
CVE-2008-0105
High 9.3

Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter In…

microsoft office · microsoft works
0.44EPSS
CVE-2006-3637
Medium 5.1

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering M…

microsoft ie · microsoft internet_explorer
0.44EPSS
CVE-2006-4704
Medium 6.8

Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instan…

microsoft visual_studio_.net
0.44EPSS
CVE-2016-0111
High 7.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.44EPSS
CVE-2018-0866
High 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting en…

microsoft internet_explorer
0.44EPSS
CVE-2022-21993
High 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.44EPSS
CVE-2017-8558
High 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511…

microsoft endpoint_protection · microsoft forefront_endpoint_protection · microsoft security_essentials · microsoft windows_defender · and 1 more
0.44EPSS
CVE-2000-0970
High 7.5

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vuln…

microsoft internet_information_server · microsoft internet_information_services
0.44EPSS
CVE-2023-6702
High 8.8

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

fedoraproject fedora · google chrome · microsoft edge_chromium
0.44EPSS
CVE-2016-3225
High 7.8

The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applicati…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2006-4696
High 9.0

Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.43EPSS
CVE-2017-0190
Medium 4.4

The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from pr…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2015-3106
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK b…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · and 1 more
0.43EPSS
CVE-2010-0010
Medium 6.8

Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a l…

apache http_server
0.43EPSS
CVE-2015-8434
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8431
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8430
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8429
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8428
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8427
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8426
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2015-8425
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS