imPC@ndo EN

CVE Tracker

56.554 CVE

CVE-2006-4702
Media 6.8

Buffer overflow in the Windows Media Format Runtime in Microsoft Windows Media Player (WMP) 6.4 and Windows XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted Advanced Systems Format (ASF) file.

microsoft windows_2003_server · microsoft windows_media_player · microsoft windows_xp
0.27EPSS
CVE-2025-11001
Alta 7.8

7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this product is required to exploit this vulnerability but…

7-zip 7-zip
0.27EPSS
CVE-2011-3411
Alta 9.3

Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that leverages incorrect handling of values in memory, aka "Publisher Invalid Pointer Vulnerability."

microsoft publisher
0.27EPSS
CVE-2002-0936
Media 5.0

The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).

apache tomcat
0.27EPSS
CVE-2001-1325
Alta 7.5

Internet Explorer 5.0 and 5.5, and Outlook Express 5.0 and 5.5, allow remote attackers to execute scripts when Active Scripting is disabled by including the scripts in XML stylesheets (XSL) that are referenced using an IFRAME tag, possibly due to a vulnerabili…

microsoft internet_explorer · microsoft outlook_express
0.27EPSS
CVE-2002-0867
Media 5.0

Microsoft Virtual Machine (VM) up to and including build 5.0.3805 allows remote attackers to cause a denial of service (crash) in Internet Explorer via invalid handle data in a Java applet, aka "Handle Validation Flaw."

microsoft virtual_machine
0.27EPSS
CVE-2016-0985
Alta 8.8

Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allow attackers to execu…

adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 1
0.27EPSS
CVE-2010-3138
Alta 9.3

Untrusted search path vulnerability in the Indeo Codec in iac25_32.ax in Microsoft Windows XP SP3 allows local users to gain privileges via a Trojan horse iacenc.dll file in the current working directory, as demonstrated by access through BS.Player or Media Pl…

bsplayer bs.player · microsoft windows_media_player · microsoft windows_xp
0.27EPSS
CVE-2008-4699
Alta 9.3

Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers to execute arbitrary programs via the ExecutePreferredApplication method.

microsoft peachtree_accounting
0.27EPSS
CVE-2017-3823
Alta 8.8

An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Dow…

cisco activetouch_general_plugin_container · cisco download_manager · cisco gpccontainer_class · cisco webex · e altri 2
0.27EPSS
CVE-2010-1248
Alta 9.3

Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Excel file with a malformed HFPicture (0x866) record, aka "Excel HFPicture Memory Corruption Vulnerability."

microsoft excel · microsoft office
0.27EPSS
CVE-2000-1034
Alta 10.0

Buffer overflow in the System Monitor ActiveX control in Windows 2000 allows remote attackers to execute arbitrary commands via a long LogFileName parameter in HTML source code, aka the "ActiveX Parameter Validation" vulnerability.

microsoft windows_2000
0.27EPSS
CVE-2014-7992
Media 5.0

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information from process memory via a session on TCP port 2067, aka Bug ID CSCur14014.

cisco ios
0.27EPSS
CVE-2020-8982
Alta 7.5

An unauthenticated arbitrary file read issue exists in all versions of Citrix ShareFile StorageZones (aka storage zones) Controller, including the most recent 5.10.x releases as of May 2020. RCE and file access is granted to everything hosted by ShareFile, be …

citrix sharefile_storagezones_controller
0.27EPSS
CVE-2008-1445
Alta 7.1

Active Directory on Microsoft Windows 2000 Server SP4, XP Professional SP2 and SP3, Server 2003 SP1 and SP2, and Server 2008 allows remote authenticated users to cause a denial of service (system hang or reboot) via a crafted LDAP request.

microsoft windows-nt · microsoft windows_2003_server · microsoft windows_xp
0.27EPSS
CVE-2025-20188
Critica 10.0

A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload …

cisco ios_xe
0.27EPSS
CVE-2016-4203
Critica 9.8

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (mem…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader_dc · adobe reader
0.27EPSS
CVE-2007-0943
Media 6.8

Unspecified vulnerability in Internet Explorer 5.01 and 6 SP1 allows remote attackers to execute arbitrary code via crafted Cascading Style Sheets (CSS) strings that trigger memory corruption during parsing, related to use of out-of-bounds pointers.

microsoft ie · microsoft internet_explorer
0.27EPSS
CVE-2020-17047
Alta 7.5

Windows Network File System Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.27EPSS
CVE-2000-0653
Media 5.0

Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the Outlook Express windows, aka the "Persistent Mail-Browser Link" vulnerability.

microsoft outlook_express
0.27EPSS
CVE-2009-0555
Alta 9.3

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly process Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary co…

microsoft windows_2000 · microsoft windows_media_format_runtime · microsoft windows_media_player · microsoft windows_server_2003 · e altri 3
0.27EPSS
CVE-2002-1567
Media 6.8

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.

apache tomcat
0.27EPSS
CVE-2017-11211
Alta 8.8

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable heap overflow vulnerability in the JPEG parser. Successful exploitation could lead to arbitrary code execution.

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc · e altri 1
0.27EPSS
CVE-2009-0233
Media 5.8

The DNS Resolver Cache Service (aka DNSCache) in Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not reuse cached DNS responses in all applicable situations, which makes it easi…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008
0.27EPSS
CVE-2006-3442
Alta 7.6

Unspecified vulnerability in Pragmatic General Multicast (PGM) in Microsoft Windows XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted multicast message.

microsoft windows_xp
0.27EPSS