imPC@ndo EN

CVE Tracker

56.517 CVE

CVE-2007-1747
Alta 9.3

Unspecified vulnerability in MSO.dll in Microsoft Office 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and 2007 allows user-assisted remote attackers to execute arbitrary code via a malformed drawing object, which triggers memory corruption.

microsoft office
0.32EPSS
CVE-2011-0097
Alta 9.3

Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remo…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 1
0.32EPSS
CVE-2007-0215
Alta 7.6

Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.

microsoft excel · microsoft excel_viewer · microsoft office
0.32EPSS
CVE-2018-5065
Alta 8.8

Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

adobe acrobat_dc · adobe acrobat_reader_dc
0.32EPSS
CVE-2007-0066
Alta 7.1

The kernel in Microsoft Windows 2000 SP4, XP SP2, and Server 2003, when ICMP Router Discovery Protocol (RDP) is enabled, allows remote attackers to cause a denial of service via fragmented router advertisement ICMP packets that trigger an out-of-bounds read, a…

microsoft home_server · microsoft small_business_server · microsoft windows_2000 · microsoft windows_2003_server · e altri 2
0.32EPSS
CVE-2006-0004
Media 5.0

Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).

microsoft office
0.32EPSS
CVE-2008-5178
Alta 9.3

Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.

opera opera
0.32EPSS
CVE-2006-1192
Bassa 2.6

Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, …

canon network_camera_server_vb101 · microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2013-2088
Alta 7.1

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

apache subversion · collabnet subversion · opensuse opensuse
0.31EPSS
CVE-2006-6456
Alta 9.3

Unspecified vulnerability in Microsoft Word 2000, 2002, and 2003 and Word Viewer 2003 allows remote attackers to execute code via unspecified vectors related to malformed data structures that trigger memory corruption, a different vulnerability than CVE-2006-5…

microsoft office · microsoft word · microsoft word_viewer · microsoft works
0.31EPSS
CVE-2013-1325
Alta 9.3

Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Heap Overwrite Vulnerability."

microsoft office
0.31EPSS
CVE-2013-1324
Alta 9.3

Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Stack Buffer Overwrite Vulnerability."

microsoft office · microsoft office_2013_rt
0.31EPSS
CVE-1999-0678
Media 5.0

A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read documentation files for the entire server.

apache http_server
0.31EPSS
CVE-2006-0034
Alta 7.5

Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long …

microsoft distributed_transaction_coordinator · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · e altri 1
0.31EPSS
CVE-2007-0027
Alta 9.3

Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows remote attackers to execute arbitrary code via malformed IMDATA records that trigger memory corruption.

microsoft excel · microsoft excel_viewer · microsoft office · microsoft works
0.31EPSS
CVE-2002-0693
Alta 7.5

Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter …

microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_98 · microsoft windows_98se · e altri 3
0.31EPSS
CVE-2015-2460
Alta 9.3

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, …

microsoft .net_framework
0.31EPSS
CVE-2007-3493
Alta 7.5

A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienzo DMM and probably other products, allows remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the…

microsoft internet_explorer · nctsoft_products nctaudiostudio · nctsoft_products nctwavchunkseditor2.dll
0.31EPSS
CVE-2006-5994
Alta 9.3

Unspecified vulnerability in Microsoft Word 2000 and 2002, Office Word and Word Viewer 2003, Word 2004 and 2004 v. X for Mac, and Works 2004, 2005, and 2006 allows remote attackers to execute arbitrary code via a Word document with a malformed string that trig…

microsoft office · microsoft word · microsoft word_viewer · microsoft works
0.31EPSS
CVE-2006-5584
Alta 7.5

The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.

microsoft windows_2000
0.31EPSS
CVE-2007-3903
Media 6.8

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via uninitialized or deleted objects used in repeated calls to the (1) cloneNode or (2) nodeValue JavaScript function, a different issue than CVE-2007-3902 and CVE-2007-5344,…

microsoft ie · microsoft internet_explorer
0.31EPSS
CVE-2006-0143
Alta 7.5

Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 2
0.31EPSS
CVE-2019-0667
Alta 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows VBScript Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0665, CVE-2019-0666, CVE-2019-0772.

microsoft internet_explorer
0.31EPSS
CVE-2015-6168
Alta 9.3

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6153.

microsoft edge
0.31EPSS
CVE-2014-4109
Alta 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.31EPSS