imPC@ndo EN

CVE Tracker

56.554 CVE

CVE-1999-0737
Media 5.0

The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.

microsoft internet_information_server
0.28EPSS
CVE-2013-0006
Alta 8.8

Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."

microsoft expression_web · microsoft groove_server · microsoft office · microsoft office_compatibility_pack · e altri 11
0.28EPSS
CVE-2001-0875
Alta 7.5

Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the dialogue in a way that could fool users into thinking that the file type is safe to download.

microsoft internet_explorer
0.28EPSS
CVE-2007-5347
Media 6.8

Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," aka "DHTML Object Memory Corruption Vulnerability."

microsoft ie · microsoft internet_explorer
0.28EPSS
CVE-2008-1456
Alta 9.0

Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote authenticated users to execute arbitrary code via a crafted event subscription request that …

microsoft windows-nt · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · e altri 1
0.28EPSS
CVE-2026-49975
Alta 7.5

Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.

apache http_server · debian debian_linux
0.28EPSS
CVE-2009-0560
Alta 9.3

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel View…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · e altri 2
0.28EPSS
CVE-2009-0223
Alta 9.3

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a file that uses a PowerPoint 4.0 native file format, leading to memory corruption, aka "Legacy File Format Vulnerability,"…

microsoft office_powerpoint
0.28EPSS
CVE-2008-3474
Media 6.5

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy and obtain sensitive information via a crafted HTML document,…

microsoft internet_explorer
0.28EPSS
CVE-2018-15937
Alta 7.8

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2011-1347
Alta 8.8

Unspecified vulnerability in Microsoft Internet Explorer 8 on Windows 7 allows remote attackers to bypass Protected Mode and create arbitrary files by leveraging access to a Low integrity process, as demonstrated by Stephen Fewer as the third of three chained …

microsoft internet_explorer
0.28EPSS
CVE-2001-0239
Alta 7.5

Microsoft Internet Security and Acceleration (ISA) Server 2000 Web Proxy allows remote attackers to cause a denial of service via a long web request with a specific type.

microsoft isa_server
0.28EPSS
CVE-2011-1999
Alta 9.3

Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."

microsoft internet_explorer
0.28EPSS
CVE-2017-3145
Alta 7.5

BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.…

debian debian_linux · isc bind · juniper junos · netapp data_ontap_edge · e altri 6
0.28EPSS
CVE-2023-52755
Critica 9.8

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab out of bounds write in smb_inherit_dacl() slab out-of-bounds write is caused by that offsets is bigger than pntsd allocation size. This patch add the check to validate 3 offs…

linux linux_kernel
0.28EPSS
CVE-2011-0034
Alta 9.3

Stack-based buffer overflow in the OpenType Compact Font Format (aka OTF or CFF) driver in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows re…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.28EPSS
CVE-2009-3720
Media 5.0

The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 se…

apache http_server · libexpat_project libexpat
0.28EPSS
CVE-2001-1451
Media 5.0

Memory leak in the SNMP LAN Manager (LANMAN) MIB extension for Microsoft Windows 2000 before SP3, when the Print Spooler is not running, allows remote attackers to cause a denial of service (memory consumption) via a large number of GET or GETNEXT requests.

microsoft windows_2000
0.28EPSS
CVE-2019-9517
Alta 7.5

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer …

apache http_server · apache traffic_server · apple swiftnio · canonical ubuntu_linux · e altri 19
0.28EPSS
CVE-2001-0341
Alta 7.5

Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attackers to execute arbitrary commands via a long registration request (URL) to fp30reg.dll.

microsoft frontpage_server_extensions · microsoft windows_2000 · microsoft windows_nt
0.28EPSS
CVE-2018-15931
Alta 7.8

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2018-15930
Alta 7.8

Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.

adobe acrobat_dc · adobe acrobat_reader_dc
0.28EPSS
CVE-2019-7107
Critica 9.8

Adobe InDesign versions 14.0.1 and below have an unsafe hyperlink processing vulnerability. Successful exploitation could lead to arbitrary code execution. Fixed in versions 13.1.1 and 14.0.2.

adobe indesign
0.28EPSS
CVE-2010-4566
Alta 9.3

The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and earlier, and the NTLM authentication component in Access Gateway Standard and Advanced Editions before Access Gateway 5.0, allows attackers…

citrix access_gateway
0.28EPSS
CVE-2006-5752
Media 4.3

Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecif…

apache http_server · canonical ubuntu_linux · fedoraproject fedora · redhat enterprise_linux_desktop · e altri 3
0.28EPSS