58.650 CVE seguite
799 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.650 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2016-3301 | HIGH 7.8 | microsoft live_meeting The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for | 44,5% | — |
| CVE-2008-3479 | HIGH 10.0 | microsoft windows_2000 Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters | 44,5% | — |
| CVE-2007-3101 | MED 4.3 | apache myfaces_tomahawk Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the cl | 44,5% | — |
| CVE-2020-13933 | HIGH 7.5 | apache shiro Apache Shiro before 1.6.0, when using Apache Shiro, a specially crafted HTTP request may cause an authentication bypass. | 44,4% | — |
| CVE-2015-5562 | HIGH 10.0 | adobe air Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code by leveraging an u | 44,4% | — |
| CVE-2007-3111 | HIGH 10.0 | microsoft internet_explorer Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value. | 44,4% | — |
| CVE-2007-0024 | HIGH 9.3 | microsoft ie Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page t | 44,2% | — |
| CVE-2000-0951 | MED 5.0 | microsoft internet_information_services A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search. | 44,1% | — |
| CVE-2023-33133 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 44,0% | — |
| CVE-2007-0612 | HIGH 7.8 | microsoft ie Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1 | 43,9% | — |
| CVE-2000-0413 | MED 5.0 | microsoft frontpage The shtml.exe program in the FrontPage extensions package of IIS 4.0 and 5.0 allows remote attackers to determine the physical path of HTML, HTM, ASP, and SHTML files by requesting a file that does not exist, which generates an error message that reveals the p | 43,9% | — |
| CVE-2014-0231 | MED 5.0 | apache http_server The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor. | 43,8% | — |
| CVE-2023-6702 | HIGH 8.8 | fedoraproject fedora Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 43,8% | — |
| CVE-2014-2815 | HIGH 8.8 | microsoft onenote Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability." | 43,8% | — |
| CVE-2020-1301 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 1.0 (SMBv1) server handles certain requests, aka 'Windows SMB Remote Code Execution Vulnerability'. | 43,8% | — |
| CVE-2001-0877 | MED 5.0 | microsoft windows_98 Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic | 43,8% | — |
| CVE-2018-8625 | HIGH 7.5 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10. | 43,8% | — |
| CVE-2008-0105 | HIGH 9.3 | microsoft office Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter In | 43,8% | — |
| CVE-2006-3637 | MED 5.1 | microsoft ie Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering M | 43,8% | — |
| CVE-2018-3924 | HIGH 8.8 | foxitsoftware foxit_reader An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execut | 43,7% | — |
| CVE-2011-3416 | HIGH 8.5 | microsoft windows_7 The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access to arbitrary user accounts via a crafted username, aka "ASP.Net Forms Authenticat | 43,7% | — |
| CVE-2018-0866 | HIGH 7.5 | microsoft internet_explorer Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting en | 43,6% | — |
| CVE-2006-5559 | HIGH 9.3 | microsoft data_access_components The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the secon | 43,6% | — |
| CVE-2022-21993 | HIGH 7.5 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability | 43,6% | — |
| CVE-2025-30065 | CRIT 9.8 | apache parquet_java Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code Users are recommended to upgrade to version 1.15.1, which fixes the issue. | 43,6% | — |