imPC@ndo EN

CVE Tracker

56.362 CVE

CVE-2021-22555
Sfruttata Alta 8.3

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

brocade fabric_operating_system · linux linux_kernel · netapp aff_500f_firmware · netapp aff_a250_firmware · e altri 17
0.79EPSS
CVE-2021-21975
Ransomware Alta 7.5

Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack to steal administrative credent…

vmware cloud_foundation · vmware vrealize_operations_manager · vmware vrealize_suite_lifecycle_manager
0.78EPSS
CVE-2011-3402
Sfruttata Alta 8.8

Unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows r…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.78EPSS
CVE-2023-24880
Ransomware Media 4.4

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · e altri 6
0.78EPSS
CVE-2017-0261
Sfruttata Alta 7.8

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0262 and…

microsoft office
0.78EPSS
CVE-2013-1347
Sfruttata Alta 8.8

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.

microsoft internet_explorer
0.78EPSS
CVE-2021-1732
Ransomware Alta 7.8

Windows Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1803 · microsoft windows_10_1809 · microsoft windows_10_1909 · microsoft windows_10_2004 · e altri 5
0.78EPSS
CVE-2014-6352
Sfruttata Alta 7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the …

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 4
0.78EPSS
CVE-2013-3897
Sfruttata Alta 8.8

Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onp…

microsoft internet_explorer
0.77EPSS
CVE-2014-1761
Sfruttata Alta 7.8

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web A…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_web_apps_server · e altri 3
0.77EPSS
CVE-2022-41080
Ransomware Alta 8.8

Microsoft Exchange Server Elevation of Privilege Vulnerability

microsoft exchange_server
0.77EPSS
CVE-2026-50522
Sfruttata Critica 9.8

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

microsoft sharepoint_server
0.77EPSS
CVE-2008-0015
Sfruttata Alta 8.8

Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in the MPEG2TuneRequest ActiveX control in msvidctl.dll in DirectShow, in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista G…

microsoft windows_2003_server · microsoft windows_xp
0.77EPSS
CVE-2022-44698
Ransomware Media 5.4

Windows SmartScreen Security Feature Bypass Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h1 · e altri 6
0.76EPSS
CVE-2015-0016
Sfruttata Alta 7.8

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attacker…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 4
0.76EPSS
CVE-2018-8298
Sfruttata Alta 7.5

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8283, CV…

microsoft chakracore
0.75EPSS
CVE-2012-0391
Sfruttata Critica 9.8

The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during certain exception handling for mismatched data types of properties, which allows remote attackers to execute arbitrary Java code via a craft…

apache struts
0.75EPSS
CVE-2015-3043
Sfruttata Critica 9.8

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited …

adobe flash_player · novell suse_linux_enterprise_desktop · novell suse_linux_enterprise_workstation_extension · opensuse evergreen · e altri 7
0.74EPSS
CVE-2021-42287
Ransomware Alta 7.5

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · e altri 1
0.74EPSS
CVE-2021-40449
Ransomware Alta 7.8

Win32k Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_1909 · e altri 15
0.74EPSS
CVE-2013-2551
Ransomware Alta 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013…

microsoft internet_explorer
0.74EPSS
CVE-2019-12991
Sfruttata Alta 8.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.74EPSS
CVE-2018-8414
Sfruttata Alta 8.8

A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows 10 Servers, Windows 10.

microsoft windows_10_1703 · microsoft windows_10_1709 · microsoft windows_10_1803 · microsoft windows_server_1709 · e altri 1
0.74EPSS
CVE-2013-3918
Sfruttata Alta 8.8

The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, an…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 6
0.74EPSS
CVE-2019-1458
Ransomware Alta 7.8

An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_7 · microsoft windows_8.1 · e altri 4
0.74EPSS