imPC@ndo EN

CVE Tracker

56.541 CVE

CVE-2004-0571
Alta 10.0

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a diffe…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 3
0.31EPSS
CVE-2020-0729
Alta 8.8

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Co…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.31EPSS
CVE-2008-0470
Alta 9.3

A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteStr method.

comodo comodo_antivirus · microsoft activex
0.31EPSS
CVE-2003-1172
Media 5.0

Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter.

apache cocoon
0.31EPSS
CVE-2012-0021
Bassa 2.6

The log_cookie function in mod_log_config.c in the mod_log_config module in the Apache HTTP Server 2.2.17 through 2.2.21, when a threaded MPM is used, does not properly handle a %{}C format string, which allows remote attackers to cause a denial of service (da…

apache http_server
0.31EPSS
CVE-2023-21819
Alta 7.5

Windows Secure Channel Denial of Service Vulnerability

microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 3
0.31EPSS
CVE-2024-21318
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.31EPSS
CVE-2016-0974
Alta 8.8

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.…

adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 1
0.31EPSS
CVE-2002-2006
Media 5.0

The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.

apache tomcat
0.31EPSS
CVE-2007-0041
Alta 9.3

The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably…

microsoft .net_framework
0.31EPSS
CVE-2007-0043
Alta 9.3

The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably…

microsoft .net_framework
0.31EPSS
CVE-2022-20964
Media 6.3

A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user i…

cisco identity_services_engine
0.31EPSS
CVE-2011-4373
Critica 9.8

Adobe Reader and Acrobat before 9.5, and 10.x before 10.1.2, on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2011-4370 and CVE-2011-4…

adobe acrobat · adobe reader
0.31EPSS
CVE-2004-1049
Media 5.1

Integer overflow in the LoadImage API of the USER32 Lib for Microsoft Windows allows remote attackers to execute arbitrary code via a .bmp, .cur, .ico or .ani file with a large image size field, which leads to a buffer overflow, aka the "Cursor and Icon Format…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.31EPSS
CVE-2005-2700
Alta 10.0

ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access…

apache http_server · canonical ubuntu_linux · debian debian_linux
0.31EPSS
CVE-2021-36958
Alta 7.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…

microsoft windows
0.31EPSS
CVE-2009-1043
Alta 10.0

Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors triggered by clicking on a link, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

microsoft internet_explorer
0.31EPSS
CVE-1999-1375
Media 5.0

FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by specifying the name in the file parameter.

microsoft internet_information_server
0.31EPSS
CVE-2008-1086
Alta 9.3

The HxTocCtrl ActiveX control (hxvz.dll), as used in Microsoft Internet Explorer 5.01 SP4 and 6 SP1, in Windows XP SP2, Server 2003 SP1 and SP2, Vista SP1, and Server 2008, allows remote attackers to execute arbitrary code via malformed arguments, which trigge…

microsoft internet_explorer · microsoft windows-nt · microsoft windows_2003_server · microsoft windows_vista · e altri 1
0.31EPSS
CVE-2015-6131
Alta 9.3

Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted .mcl file, aka "Media Center Library Parsing RCE Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_vista
0.31EPSS
CVE-2014-4141
Alta 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.31EPSS
CVE-2015-6088
Media 4.3

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."

microsoft edge · microsoft internet_explorer
0.31EPSS
CVE-2011-0098
Alta 9.3

Integer signedness error in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allo…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 1
0.30EPSS
CVE-2009-1133
Alta 9.3

Heap-based buffer overflow in Microsoft Remote Desktop Connection (formerly Terminal Services Client) running RDP 5.0 through 6.1 on Windows, and Remote Desktop Connection Client for Mac 2.0, allows remote attackers to execute arbitrary code via unspecified pa…

microsoft windows_2000 · microsoft windows_server · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.30EPSS
CVE-2021-1531
Alta 8.8

A vulnerability in the web UI of Cisco Modeling Labs could allow an authenticated, remote attacker to execute arbitrary commands with the privileges of the web application on the underlying operating system of an affected Cisco Modeling Labs server. This vulne…

cisco modeling_labs
0.30EPSS