imPC@ndo EN

CVE Tracker

56.517 CVE

CVE-2009-0084
Alta 9.3

Use-after-free vulnerability in DirectShow in Microsoft DirectX 8.1 and 9.0 allows remote attackers to execute arbitrary code via an MJPEG file or video stream with a malformed Huffman table, which triggers an exception that frees heap memory that is later acc…

microsoft directx
0.32EPSS
CVE-2007-2219
Alta 9.3

Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.32EPSS
CVE-2022-24463
Media 6.5

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.32EPSS
CVE-2008-3473
Alta 9.3

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, …

microsoft internet_explorer
0.32EPSS
CVE-2017-0094
Alta 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.32EPSS
CVE-2012-5613
Media 6.0

MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to users who should not have administrative privileges, allows remote authenticated users to gain privileges by leveraging t…

mariadb mariadb · oracle mysql
0.32EPSS
CVE-2006-1305
Media 4.3

Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers…

microsoft office · microsoft outlook
0.32EPSS
CVE-2013-3860
Alta 7.8

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, which allows remote attackers to cause a denial of service (application crash or hang) via a crafted signed XML document, a…

microsoft .net_framework
0.32EPSS
CVE-2013-3120
Alta 9.3

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and …

microsoft internet_explorer
0.32EPSS
CVE-2015-8413
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.32EPSS
CVE-2015-8412
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.32EPSS
CVE-2015-8411
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.32EPSS
CVE-2015-8410
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.32EPSS
CVE-2015-8048
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.32EPSS
CVE-2009-1137
Alta 9.3

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability,"…

microsoft office_powerpoint
0.32EPSS
CVE-2009-0222
Alta 9.3

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to a "pointer overwrite" and memory corruption, aka "Legacy F…

microsoft office_powerpoint
0.32EPSS
CVE-2006-1191
Media 4.0

Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has n…

microsoft internet_explorer
0.32EPSS
CVE-2001-0663
Media 5.0

Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote Desktop Protocol (RDP) packets.

microsoft windows_2000 · microsoft windows_nt
0.32EPSS
CVE-2009-2505
Alta 10.0

The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary c…

microsoft windows_server_2008 · microsoft windows_vista
0.32EPSS
CVE-2009-0880
Media 6.8

Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to load and execute arbitrary local DLL code via a .. (dot dot) in a /CIMListener/ URI in an M-POST request.

ibm director
0.32EPSS
CVE-2008-0011
Alta 9.3

Microsoft DirectX 8.1 through 9.0c, and DirectX on Microsoft XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008, does not properly perform MJPEG error checking, which allows remote attackers to execute arbitrary code via a crafted MJP…

microsoft directx
0.32EPSS
CVE-1999-0524
Media 4.0

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

apple mac_os_x · apple macos · cisco ios · hp hp-ux · e altri 10
0.32EPSS
CVE-2017-0236
Alta 7.5

A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228…

microsoft edge
0.32EPSS
CVE-2013-0007
Alta 9.3

Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."

microsoft expression_web · microsoft groove_server · microsoft office · microsoft office_compatibility_pack · e altri 11
0.32EPSS
CVE-2002-0736
Alta 10.0

Microsoft BackOffice 4.0 and 4.5, when configured to be accessible by other systems, allows remote attackers to bypass authentication and access the administrative ASP pages via an HTTP request with an authorization type (auth_type) that is not blank.

microsoft backoffice
0.32EPSS