imPC@ndo IT

CVE Tracker

56.515 CVE

CVE-2003-0345
High 7.5

Buffer overflow in the SMB capability for Microsoft Windows XP, 2000, and NT allows remote attackers to cause a denial of service and possibly execute arbitrary code via an SMB packet that specifies a smaller buffer length than is required.

microsoft windows_2000 · microsoft windows_nt · microsoft windows_xp
0.35EPSS
CVE-2015-1648
Low 2.6

ASP.NET in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2, when the customErrors configuration is disabled, allows remote attackers to obtain sensitive configuration-file information via a crafted request, aka "ASP.NET Informat…

microsoft .net_framework
0.35EPSS
CVE-2020-9483
High 7.5

**Resolved** When use H2/MySQL/TiDB as Apache SkyWalking storage, the metadata query through GraphQL protocol, there is a SQL injection vulnerability, which allows to access unpexcted data. Apache SkyWalking 6.0.0 to 6.6.0, 7.0.0 H2/MySQL/TiDB storage implemen…

apache skywalking
0.35EPSS
CVE-2006-6334
Medium 6.8

Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data …

citrix presentation_server_client
0.35EPSS
CVE-2000-0913
Medium 5.0

mod_rewrite in Apache 1.3.12 and earlier allows remote attackers to read arbitrary files if a RewriteRule directive is expanded to include a filename whose name contains a regular expression.

apache http_server
0.35EPSS
CVE-2003-0824
Medium 5.0

Unknown vulnerability in the SmartHTML interpreter (shtml.dll) in Microsoft FrontPage Server Extensions 2000 and 2002, and Microsoft SharePoint Team Services 2002, allows remote attackers to cause a denial of service (response failure) via a certain request.

microsoft frontpage_server_extensions · microsoft sharepoint_team_services · microsoft windows_2000 · microsoft windows_xp
0.35EPSS
CVE-2022-24497
Critical 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.35EPSS
CVE-2008-0107
High 9.0

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote …

microsoft data_engine · microsoft sql_server · microsoft sql_server_desktop_engine · microsoft windows_server_2008 · and 2 more
0.35EPSS
CVE-2009-1929
High 9.3

Heap-based buffer overflow in the Microsoft Terminal Services Client ActiveX control running RDP 6.1 on Windows XP SP2, Vista SP1 or SP2, or Server 2008 Gold or SP2; or 5.2 or 6.1 on Windows XP SP3; allows remote attackers to execute arbitrary code via unspeci…

microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.35EPSS
CVE-2007-2224
High 9.3

Object linking and embedding (OLE) Automation, as used in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Office 2004 for Mac, and Visual Basic 6.0 allows remote attackers to execute arbitrary code via the substringData method on a TextNode object…

microsoft office · microsoft visual_basic
0.35EPSS
CVE-2018-1271
Medium 5.9

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on W…

oracle application_testing_suite · oracle big_data_discovery · oracle communications_converged_application_server · oracle communications_diameter_signaling_router · and 24 more
0.35EPSS
CVE-2006-4534
High 9.3

Unspecified vulnerability in Microsoft Word 2000, 2002, and Office 2003 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors involving a crafted file resulting in a malformed stack, as exploited by malware with names includin…

microsoft office
0.34EPSS
CVE-2025-21400
High 8.0

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.34EPSS
CVE-2015-2463
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 …

microsoft .net_framework · microsoft live_meeting · microsoft lync · microsoft lync_basic · and 10 more
0.34EPSS
CVE-2013-3940
High 9.3

Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 6 more
0.34EPSS
CVE-2009-0234
Medium 6.4

The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008 does not properly cache crafted DNS responses, which makes it easier for remote attackers to predict transaction IDs and…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008
0.34EPSS
CVE-2008-4019
High 9.3

Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; O…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 2 more
0.34EPSS
CVE-2010-0267
High 9.3

Microsoft Internet Explorer 6, 6 SP1, and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "U…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · and 3 more
0.34EPSS
CVE-2011-0026
High 9.3

Integer signedness error in the SQLConnectW function in an ODBC API (odbc32.dll) in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, allows remote attackers to execute arbitrary code via a long string in t…

microsoft data_access_components · microsoft windows_data_access_components
0.34EPSS
CVE-2003-0227
Medium 5.0

The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Services in Microsoft Windows NT 4.0 and 2000, nsiislog.dll, allows remote attackers to cause a denial of service in Internet Information Server (…

microsoft windows_2000 · microsoft windows_nt
0.34EPSS
CVE-2008-0082
High 10.0

An ActiveX control (Messenger.UIAutomation.1) in Windows Messenger 4.7 and 5.1 is marked as safe-for-scripting, which allows remote attackers to control the Messenger application, and "change state," obtain contact information, and establish audio or video con…

microsoft windows_messenger
0.34EPSS
CVE-2009-3676
High 7.1

The SMB client in the kernel in Microsoft Windows Server 2008 R2 and Windows 7 allows remote SMB servers and man-in-the-middle attackers to cause a denial of service (infinite loop and system hang) via a (1) SMBv1 or (2) SMBv2 response packet that contains (a)…

microsoft windows_7 · microsoft windows_server_2008
0.34EPSS
CVE-2010-0476
High 10.0

The SMB client in Microsoft Windows Server 2003 SP2, Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2 allows remote SMB servers and man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and reboot) …

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 1 more
0.34EPSS
CVE-2018-3991
Critical 10.0

An exploitable heap overflow vulnerability exists in the WkbProgramLow function of WibuKey Network server management, version 6.40.2402.500. A specially crafted TCP packet can cause a heap overflow, potentially leading to remote code execution. An attacker can…

siemens simatic_wincc_open_architecture · wibu wibukey
0.34EPSS
CVE-2009-2495
Medium 6.5

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensit…

microsoft visual_c\+\+ · microsoft visual_studio · microsoft visual_studio_.net
0.34EPSS