imPC@ndo IT

CVE Tracker

56.515 CVE

CVE-2017-0011
Medium 4.3

Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and C…

microsoft edge
0.42EPSS
CVE-2004-0573
High 7.5

Buffer overflow in the converter for Microsoft WordPerfect 5.x on Office 2000, Office XP, Office 2003, and Works Suites 2001 through 2004 allows remote attackers to execute arbitrary code via a malicious document or website.

microsoft frontpage · microsoft office · microsoft publisher · microsoft word · and 1 more
0.42EPSS
CVE-2009-2494
Critical 9.8

The Active Template Library (ATL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via vectors related to erroneous free operations after re…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.42EPSS
CVE-2005-3644
High 7.8

PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 and earlier, allows remote attackers to cause a denial of service (memory consumption) via a DCE RPC request that specifies a large output bu…

microsoft windows_2000 · microsoft windows_xp
0.42EPSS
CVE-2002-0422
Low 2.6

IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (which may be obscured by NAT) via (1) a PROPFIND HTTP request with a blank Host header, which leaks the address in an HREF property in a 207 Mul…

microsoft internet_information_services
0.42EPSS
CVE-2018-1026
High 8.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-20…

microsoft office
0.42EPSS
CVE-2007-3282
High 7.8

Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the DeleteRecordSourceIfUnused method.

microsoft office · microsoft office_msodatasourcecontrol_activex
0.42EPSS
CVE-2008-0113
High 9.3

Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execute arbitrary code via an Excel document with malformed cell comments that trigger memory corruption from an "allocation error," aka "Microso…

microsoft excel_viewer
0.42EPSS
CVE-2013-2492
Medium 6.8

Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extractio…

firebirdsql firebird
0.42EPSS
CVE-2017-0121
Medium 4.3

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive info…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.42EPSS
CVE-2010-4172
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsLis…

apache tomcat
0.42EPSS
CVE-2012-2532
Medium 5.0

Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) processes unspecified commands before TLS is enabled for a session, which allows remote attackers to obtain sensitive information by reading the replies to these commands, aka "FTP Comma…

microsoft ftp_service
0.42EPSS
CVE-2006-0001
High 9.3

Stack-based buffer overflow in Microsoft Publisher 2000 through 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted PUB file, which causes an overflow when parsing fonts.

microsoft office · microsoft publisher
0.42EPSS
CVE-2011-2217
High 9.3

Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3…

tomsawyer get_extension_factory · vmware infrastructure · vmware virtual_infrastructure_client
0.42EPSS
CVE-2017-0017
Medium 6.1

The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is…

microsoft edge
0.42EPSS
CVE-2007-0031
High 9.3

Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-assisted remote attackers to execute arbitrary code via a BIFF8 spreadsheet with a PALETTE record that contains a large number of entries.

microsoft excel · microsoft excel_viewer · microsoft office · microsoft works
0.42EPSS
CVE-2007-6166
High 9.3

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type hea…

apple quicktime · apple safari
0.42EPSS
CVE-2006-5559
High 9.3

The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the secon…

microsoft data_access_components
0.42EPSS
CVE-2017-0088
High 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.42EPSS
CVE-2022-22721
Critical 9.1

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

apache http_server · apple mac_os_x · apple macos · debian debian_linux · and 4 more
0.42EPSS
CVE-2024-45387
Critical 9.9

An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-craf…

apache traffic_control
0.42EPSS
CVE-2000-0413
Medium 5.0

The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the p…

microsoft frontpage · microsoft internet_information_server · microsoft internet_information_services
0.42EPSS
CVE-2014-0256
Medium 5.0

Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."

microsoft windows_server_2008 · microsoft windows_server_2012
0.42EPSS
CVE-2014-0255
Medium 5.0

Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 allow remote attackers to cause a denial of service (iSCSI service outage) by sending many crafted packets, aka "iSCSI Target Remote Denial of Service Vulnerability."

microsoft windows_server_2008 · microsoft windows_server_2012
0.42EPSS
CVE-2020-3331
Critical 9.8

A vulnerability in the web-based management interface of Cisco RV110W Wireless-N VPN Firewall and Cisco RV215W Wireless-N VPN Router could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to im…

cisco rv110w_wireless-n_vpn_firewall_firmware · cisco rv215w_wireless-n_vpn_router_firmware
0.42EPSS