imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2002-0193
Alta 7.5

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for ha…

microsoft internet_explorer
0.33EPSS
CVE-2017-11779
Alta 8.1

The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly ha…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · e altri 1
0.33EPSS
CVE-2016-3203
Alta 7.8

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows PDF Remote Code Execution Vulnerability."

microsoft edge · microsoft windows_10 · microsoft windows_8.1 · microsoft windows_server_2012
0.33EPSS
CVE-2005-1980
Media 5.0

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.33EPSS
CVE-2014-1766
Alta 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWes…

microsoft internet_explorer
0.33EPSS
CVE-2009-1394
Alta 9.3

Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code by sending a long malformed string over the PlughNTCommand named pipe.

motorola timbuktu_pro
0.33EPSS
CVE-2011-0042
Alta 7.8

SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows …

microsoft windows_7 · microsoft windows_media_center_tv_pack · microsoft windows_vista · microsoft windows_xp · e altri 1
0.33EPSS
CVE-2004-1244
Alta 7.5

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

microsoft windows_media_player
0.33EPSS
CVE-2007-0028
Alta 9.3

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Mem…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft works
0.33EPSS
CVE-2002-1182
Media 5.0

IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

microsoft internet_information_services
0.33EPSS
CVE-2007-0220
Media 6.8

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, scrip…

microsoft exchange_server
0.33EPSS
CVE-2018-4956
Alta 7.5

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.33EPSS
CVE-2018-4949
Alta 7.5

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.33EPSS
CVE-2016-4228
Alta 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than…

adobe flash_player · adobe flash_player_desktop_runtime
0.33EPSS
CVE-2016-4226
Alta 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than…

adobe flash_player · adobe flash_player_desktop_runtime
0.33EPSS
CVE-2011-1772
Bassa 2.6

Multiple cross-site scripting (XSS) vulnerabilities in XWork in Apache Struts 2.x before 2.2.3, and OpenSymphony XWork in OpenSymphony WebWork, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) an action name, (2) the acti…

apache struts · opensymphony webwork · opensymphony xwork
0.33EPSS
CVE-2003-0806
Alta 7.5

Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_nt · microsoft windows_xp
0.33EPSS
CVE-2006-0010
Alta 9.3

Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 3
0.33EPSS
CVE-2022-31680
Critica 9.1

The vCenter Server contains an unsafe deserialisation vulnerability in the PSC (Platform services controller). A malicious actor with admin access on vCenter server may exploit this issue to execute arbitrary code on the underlying operating system that hosts …

vmware vcenter_server
0.33EPSS
CVE-2022-24502
Media 4.3

Windows HTML Platforms Security Feature Bypass Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 7
0.33EPSS
CVE-2010-1262
Alta 9.3

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of …

microsoft internet_explorer
0.33EPSS
CVE-2005-1205
Media 5.0

The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

microsoft windows_2003_server
0.33EPSS
CVE-2019-1068
Alta 8.8

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

microsoft sql_server
0.33EPSS
CVE-2008-4025
Alta 9.3

Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · e altri 3
0.33EPSS
CVE-2025-13315
Critica 9.8

Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.

lynxtechnology twonky_server
0.33EPSS