imPC@ndo IT

CVE Tracker

56.515 CVE

CVE-2015-3118
High 10.0

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.40EPSS
CVE-2006-3493
Medium 5.1

Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted…

microsoft office
0.40EPSS
CVE-2003-0715
High 10.0

Heap-based buffer overflow in the Distributed Component Object Model (DCOM) interface in the RPCSS Service allows remote attackers to execute arbitrary code via a malformed DCERPC DCOM object activation request packet with modified length fields, a different v…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.40EPSS
CVE-2005-1665
Medium 5.0

The __VIEWSTATE functionality in Microsoft ASP.NET 1.x, when not cryptographically signed, allows remote attackers to cause a denial of service (CPU consumption) via deeply nested markup.

microsoft asp.net
0.40EPSS
CVE-2006-2111
Medium 4.3

A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain…

microsoft outlook_express
0.40EPSS
CVE-2006-2383
High 9.3

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4 and 6 SP1 and earlier allows remote attackers to execute arbitrary code via "unexpected data" related to "parameter validation" in the DXImageTransform.Microsoft.Light ActiveX control, which cau…

microsoft internet_explorer
0.40EPSS
CVE-2011-0567
High 9.3

AcroRd32.dll in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image that triggers an i…

adobe acrobat · adobe acrobat_reader
0.40EPSS
CVE-2006-4695
High 9.3

Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via a crafted URL, aka "Office Web Components URL Parsing Vulnerability."

microsoft office_web_components
0.40EPSS
CVE-2011-0600
High 9.3

The U3D component in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a 3D file with an invalid Parent Node count that triggers an incorrect size ca…

adobe acrobat · adobe acrobat_reader
0.40EPSS
CVE-2010-3217
High 9.3

Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."

microsoft word
0.40EPSS
CVE-2020-17525
High 7.5

Subversion's mod_authz_svn module will crash if the server is using in-repository authz rules with the AuthzSVNReposRelativeAccessFile option and a client sends a request for a non-existing repository URL. This can lead to disruption for users of the service. …

apache subversion · debian debian_linux
0.40EPSS
CVE-2016-3371
Medium 5.5

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.40EPSS
CVE-2021-37580
Critical 9.8

A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass authentication. This issue affected Apache ShenYu 2.3.0 and 2.4.0

apache shenyu
0.40EPSS
CVE-2002-1973
High 7.5

Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Class (MFC) static libraries in Visual C++ 5.0, and 6.0 before SP3, as used in multiple products including BadBlue, allows remote attackers to…

microsoft foundation_class_library · working_resources_inc. badblue
0.40EPSS
CVE-2022-23277
High 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.40EPSS
CVE-1999-0154
Medium 5.0

IIS 2.0 and 3.0 allows remote attackers to read the source code for ASP pages by appending a . (dot) to the end of the URL.

microsoft internet_information_server · microsoft internet_information_services
0.40EPSS
CVE-2020-1313
High 7.8

An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'.

microsoft windows_10 · microsoft windows_server_2016
0.40EPSS
CVE-2018-0833
Medium 5.3

The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2 allows a denial of service vulnerability due to how specially crafted requests are handled, aka "SMBv2/SMBv3 Null Dereference Denial of Ser…

microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012
0.40EPSS
CVE-2008-3475
High 8.8

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML do…

microsoft internet_explorer
0.40EPSS
CVE-2002-0150
High 7.5

Buffer overflow in Internet Information Server (IIS) 4.0, 5.0, and 5.1 allows remote attackers to spoof the safety check for HTTP headers and cause a denial of service or execute arbitrary code via HTTP header field values.

microsoft internet_information_server · microsoft internet_information_services
0.40EPSS
CVE-2010-1900
High 9.3

Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not prop…

microsoft office · microsoft office_compatibility_pack · microsoft office_word_viewer · microsoft open_xml_file_format_converter · and 2 more
0.40EPSS
CVE-2005-2678
Medium 5.0

Microsoft IIS 5.1 and 6 allows remote attackers to spoof the SERVER_NAME variable to bypass security checks and conduct various attacks via a GET request with an http://localhost URI, which makes it appear as if the request is coming from localhost.

microsoft internet_information_server · microsoft internet_information_services
0.40EPSS
CVE-2021-34480
Medium 6.8

Scripting Engine Memory Corruption Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.40EPSS
CVE-2004-0727
High 7.5

Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another f…

microsoft internet_explorer
0.40EPSS
CVE-2002-0022
High 7.5

Buffer overflow in the implementation of an HTML directive in mshtml.dll in Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via a web page that specifies embedded ActiveX controls in a way that causes 2 Unicode strings to be con…

microsoft internet_explorer
0.40EPSS