imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2008-4259
Alta 9.3

Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long n…

microsoft internet_explorer
0.33EPSS
CVE-2004-0963
Alta 10.0

Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file…

microsoft word
0.33EPSS
CVE-2003-0866
Media 5.0

The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.

apache tomcat
0.33EPSS
CVE-2010-2552
Alta 7.8

Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.33EPSS
CVE-2009-3830
Media 5.0

The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.

microsoft sharepoint_server
0.33EPSS
CVE-2008-3472
Alta 9.3

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, …

microsoft internet_explorer
0.33EPSS
CVE-2007-1644
Alta 10.0

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-m…

microsoft all_windows
0.33EPSS
CVE-2013-1017
Alta 9.3

Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.

apple quicktime
0.33EPSS
CVE-2009-0239
Media 4.3

Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result…

microsoft windows_search
0.33EPSS
CVE-2014-0002
Alta 7.5

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity declaration in conjunction with an entity ref…

apache camel
0.33EPSS
CVE-2016-3198
Media 6.5

Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

microsoft edge
0.32EPSS
CVE-2016-4229
Alta 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than…

adobe flash_player · adobe flash_player_desktop_runtime
0.32EPSS
CVE-2016-3345
Alta 8.8

The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via crafted …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.32EPSS
CVE-2008-0087
Alta 7.5

The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_vista · microsoft windows_xp
0.32EPSS
CVE-2018-5391
Alta 7.5

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various …

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 47
0.32EPSS
CVE-2015-3107
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK b…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 2
0.32EPSS
CVE-2009-0568
Alta 10.0

The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locati…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server · microsoft windows_server_2008 · e altri 2
0.32EPSS
CVE-2016-3277
Media 5.3

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

microsoft edge · microsoft internet_explorer
0.32EPSS
CVE-2013-3129
Alta 7.8

Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, and 4.5; Silverlight 5 before 5.1.20513.0; win32k.sys in the kernel-mode drivers, and GDI+, DirectWrite, and Journal, in Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP…

microsoft .net_framework · microsoft lync · microsoft lync_basic · microsoft office · e altri 10
0.32EPSS
CVE-2007-0033
Alta 9.3

Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.

microsoft office · microsoft outlook
0.32EPSS
CVE-2006-3639
Alta 7.5

Microsoft Internet Explorer 5.01 and 6 does not properly identify the originating domain zone when handling redirects, which allows remote attackers to read cross-domain web pages and possibly execute code via unspecified vectors involving a crafted web page, …

microsoft ie · microsoft internet_explorer
0.32EPSS
CVE-2015-2459
Alta 9.3

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to e…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.32EPSS
CVE-2015-2458
Alta 9.3

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to e…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 5
0.32EPSS
CVE-2024-38144
Alta 8.8

Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.32EPSS
CVE-2000-0495
Media 5.0

Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "Malformed Windows Media Encoder Request" vulnerability.

microsoft windows_media_services
0.32EPSS