imPC@ndo EN

CVE Tracker

56.554 CVE

CVE-2015-0037
Alta 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE…

microsoft internet_explorer
0.27EPSS
CVE-2020-11996
Alta 7.5

A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connec…

apache tomcat · canonical ubuntu_linux · debian debian_linux · netapp oncommand_system_manager · e altri 4
0.27EPSS
CVE-2013-0030
Alta 9.3

The Vector Markup Language (VML) implementation in Microsoft Internet Explorer 6 through 10 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via a crafted web site, aka "VML Memory Corruption Vulnerability."

microsoft internet_explorer
0.27EPSS
CVE-2013-0079
Alta 9.3

Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."

microsoft office_filter_pack · microsoft visio · microsoft visio_viewer
0.27EPSS
CVE-2002-0980
Alta 7.5

The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message …

microsoft internet_explorer
0.27EPSS
CVE-2003-0809
Alta 7.5

Internet Explorer 5.01 through 6.0 does not properly handle object tags returned from a Web server during XML data binding, which allows remote attackers to execute arbitrary code via an HTML e-mail message or web page.

microsoft ie · microsoft internet_explorer
0.27EPSS
CVE-2001-0004
Media 5.0

IIS 5.0 and 4.0 allows remote attackers to read the source code for executable web server programs by appending "%3F+.htr" to the requested URL, which causes the files to be parsed by the .HTR ISAPI extension, aka a variant of the "File Fragment Reading via .H…

microsoft internet_information_server · microsoft internet_information_services
0.27EPSS
CVE-2010-0265
Alta 9.3

Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."

microsoft producer · microsoft windows_movie_maker · microsoft windows_vista · microsoft windows_xp
0.27EPSS
CVE-2008-1448
Alta 7.1

The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Internet Explorer Security Zone to UNC share pathnames, which allows remote attackers to bypass intended access rest…

microsoft outlook_express · microsoft windows_mail
0.27EPSS
CVE-2005-1935
Alta 7.5

Heap-based buffer overflow in the BERDecBitString function in Microsoft ASN.1 library (MSASN1.DLL) allows remote attackers to execute arbitrary code via nested constructed bit strings, which leads to a realloc of a non-null pointer and causes the function to o…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.27EPSS
CVE-2003-1048
Alta 7.8

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

microsoft internet_explorer · microsoft outlook · microsoft windows_98 · microsoft windows_98se · e altri 4
0.27EPSS
CVE-2015-1650
Alta 9.3

Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Serve…

microsoft office · microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · e altri 2
0.27EPSS
CVE-2016-3199
Alta 8.8

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.27EPSS
CVE-2020-17103
Alta 7.0

Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.27EPSS
CVE-2011-0979
Alta 9.3

Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; and Excel Viewer SP2 do not properly handle errors during the parsing of Office Art records in Excel spreadsheets, which allows…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 1
0.27EPSS
CVE-2010-0018
Alta 9.3

Integer overflow in the Embedded OpenType (EOT) Font Engine (t2embed.dll) in Microsoft Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attac…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · e altri 2
0.27EPSS
CVE-2025-20282
Critica 10.0

A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device and then execute those files on the underlying operating system as root. This vulnerability is …

cisco identity_services_engine · cisco identity_services_engine_passive_identity_connector
0.27EPSS
CVE-2000-0071
Media 5.0

IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensions.

microsoft internet_information_server · microsoft internet_information_services
0.27EPSS
CVE-2023-21689
Critica 9.8

Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · e altri 9
0.27EPSS
CVE-2004-0117
Alta 7.5

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

microsoft netmeeting · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · e altri 2
0.27EPSS
CVE-2014-4061
Media 6.8

Microsoft SQL Server 2008 SP3, 2008 R2 SP2, and 2012 SP1 does not properly control use of stack memory for processing of T-SQL batch commands, which allows remote authenticated users to cause a denial of service (daemon hang) via a crafted T-SQL statement, aka…

microsoft sql_server
0.26EPSS
CVE-2015-3134
Alta 10.0

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allow attackers to e…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.26EPSS
CVE-2003-0531
Alta 7.5

Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to access and execute script in the My Computer domain using the browser cache via crafted Content-Type and Content-Disposition headers, aka the "Browser Cache Script Execution in My Computer Z…

microsoft ie · microsoft internet_explorer
0.26EPSS
CVE-2009-2523
Alta 10.0

The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW met…

microsoft windows_2000
0.26EPSS
CVE-2009-1135
Alta 9.0

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, which allows remote attackers to gain the privileges of an arbitrary account, and access published web pages, vi…

microsoft isa_server
0.26EPSS