imPC@ndo EN

CVE Tracker

56.554 CVE

CVE-2006-3873
Alta 7.5

Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060912, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL in…

microsoft ie · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.29EPSS
CVE-2001-1319
Media 5.0

Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter type field, as demonstrated by the PROTOS LDAPv3 test suite.

microsoft exchange_server
0.29EPSS
CVE-2006-1313
Media 6.8

Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objects early" in certain cases, which results in memory corruption and allows remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 2
0.29EPSS
CVE-2012-1891
Critica 9.8

Heap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows remote attackers to execute arbitrary code via crafted XML data that triggers access to an uninitialized object in memory…

microsoft data_access_components · microsoft windows_data_access_components
0.29EPSS
CVE-2015-8043
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 a…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.29EPSS
CVE-2020-9480
Critica 9.8

In Apache Spark 2.4.5 and earlier, a standalone resource manager's master may be configured to require authentication (spark.authenticate) via a shared secret. When enabled, however, a specially-crafted RPC to the master can succeed in starting an application'…

apache spark · oracle business_intelligence
0.29EPSS
CVE-2007-3670
Media 4.3

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharact…

microsoft internet_explorer · mozilla firefox
0.29EPSS
CVE-2016-0198
Alta 7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office docu…

microsoft office · microsoft office_compatibility_pack · microsoft word · microsoft word_for_mac · e altri 1
0.29EPSS
CVE-2016-0150
Alta 7.5

HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."

microsoft windows_10
0.29EPSS
CVE-2010-3947
Alta 9.3

Heap-based buffer overflow in the TIFF image converter in the graphics filters in Microsoft Office XP SP3, Office Converter Pack, and Works 9 allows remote attackers to execute arbitrary code via a crafted TIFF image in an Office document, aka "TIFF Image Conv…

microsoft office · microsoft office_converter_pack · microsoft works
0.29EPSS
CVE-2011-1243
Alta 9.3

The Windows Messenger ActiveX control in msgsc.dll in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via unspecified vectors that "corrupt the system state," aka "Microsoft Windows Messenger ActiveX Control Vulnerability."

microsoft windows_xp
0.29EPSS
CVE-2010-0490
Alta 9.3

Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka…

microsoft internet_explorer · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · e altri 3
0.29EPSS
CVE-2023-20032
Critica 9.8

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated,…

cisco secure_endpoint · cisco secure_endpoint_private_cloud · cisco web_security_appliance · clamav clamav · e altri 1
0.29EPSS
CVE-2012-1885
Alta 9.3

Heap-based buffer overflow in Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Office 2008 and 2011 for Mac; and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel SerAuxErrBar…

microsoft excel · microsoft office · microsoft office_compatibility_pack
0.29EPSS
CVE-2010-0807
Alta 9.3

Microsoft Internet Explorer 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, leading to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

microsoft internet_explorer · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.29EPSS
CVE-2010-0491
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 6 SP1 allows remote attackers to execute arbitrary code by changing unspecified properties of an HTML object that has an onreadystatechange event handler, aka "HTML Object Memory Corr…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · e altri 1
0.29EPSS
CVE-2008-2254
Alta 9.3

Microsoft Internet Explorer 6 and 7 accesses uninitialized memory, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "HTML Object Memory Corruption Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2008-2256
Alta 9.3

Microsoft Internet Explorer 5.01, 6, and 7 does not properly handle objects that have been incorrectly initialized or deleted, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors, aka "Uninitialized…

microsoft internet_explorer
0.29EPSS
CVE-2015-1730
Alta 9.3

Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.29EPSS
CVE-2010-0488
Media 6.5

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 does not properly handle unspecified "encoding strings," which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted web site, aka "Post Encoding Informatio…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · e altri 3
0.29EPSS
CVE-2023-37941
Media 6.6

If an attacker gains write access to the Apache Superset metadata database, they could persist a specifically crafted Python object that may lead to remote code execution on Superset's web backend. The Superset metadata db is an 'internal' component that is t…

apache superset
0.29EPSS
CVE-2022-20759
Alta 8.8

A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privil…

cisco adaptive_security_appliance_software · cisco secure_firewall_threat_defense
0.29EPSS
CVE-2018-8273
Critica 9.8

A buffer overflow vulnerability exists in the Microsoft SQL Server that could allow remote code execution on an affected system, aka "Microsoft SQL Server Remote Code Execution Vulnerability." This affects Microsoft SQL Server.

microsoft sql_server
0.29EPSS
CVE-2012-0167
Alta 9.3

Heap-based buffer overflow in the Office GDI+ library in Microsoft Office 2003 SP3 and 2007 SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted EMF image in an Office document, aka "GDI+ Heap Overflow Vulnerability."

microsoft office
0.29EPSS
CVE-2006-2373
Alta 10.0

The Server Message Block (SMB) driver (MRXSMB.SYS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows local users to execute arbitrary code by calling the MrxSmbCscIoctlOpenForCopyChunk function with the METHOD_NEITHER method…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.29EPSS