EN

CVE Tracker

56.560 CVE

CVE-2016-3255
Alta 7.5

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, a…

microsoft .net_framework
0.25EPSS
CVE-2000-0328
Media 5.0

Windows NT 4.0 generates predictable random TCP initial sequence numbers (ISN), which allows remote attackers to perform spoofing and session hijacking.

microsoft windows_nt
0.25EPSS
CVE-2009-1923
Alta 9.3

Heap-based buffer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 and Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted WINS replication packet that triggers an incorrect buffer-length…

microsoft windows_2000 · microsoft windows_2003_server
0.25EPSS
CVE-2008-4265
Alta 9.3

Microsoft Office Excel 2000 SP3 allows remote attackers to execute arbitrary code via a crafted Excel spreadsheet that contains a malformed object, which triggers memory corruption during the loading of records from this spreadsheet, aka "File Format Parsing V…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · e altri 1
0.25EPSS
CVE-2014-6369
Alta 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2007-0468
Media 6.8

Stack-based buffer overflow in rcdll.dll in msdev.exe in Visual C++ (MSVC) in Microsoft Visual Studio 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a long file path in the "1 TYPELIB MOVEABLE PURE" option in an RC file.

microsoft visual_studio
0.25EPSS
CVE-2007-0026
Alta 7.6

The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2025-24071
Media 6.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_11_23h2 · e altri 7
0.25EPSS
CVE-2012-0185
Alta 9.3

Heap-based buffer overflow in Microsoft Excel 2007 SP2 and SP3 and 2010 Gold and SP1, Excel Viewer, and Office Compatibility Pack SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet that triggers incorrect handling of memory…

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.25EPSS
CVE-2011-2004
Alta 7.1

Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a crafted TrueType font file, aka "TrueType Font Parsing Vuln…

microsoft windows_7 · microsoft windows_server_2008
0.25EPSS
CVE-2023-24949
Alta 7.8

Windows Kernel Elevation of Privilege Vulnerability

microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 4
0.25EPSS
CVE-2020-17527
Alta 7.5

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated wit…

apache tomcat · debian debian_linux · netapp element_plug-in · netapp oncommand_system_manager · e altri 8
0.25EPSS
CVE-1999-0448
Media 5.0

IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.

microsoft internet_information_server
0.25EPSS
CVE-2008-2248
Media 4.3

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.

microsoft exchange_server · microsoft outlook_web_access
0.25EPSS
CVE-2010-4182
Alta 9.3

Untrusted search path vulnerability in the Data Access Objects (DAO) library (dao360.dll) in Microsoft Windows XP Professional SP3, Windows Server 2003 R2 Enterprise Edition SP3, Windows Vista Business SP1, and Windows 7 Professional allows local users, and po…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_vista · microsoft windows_xp
0.25EPSS
CVE-2015-7652
Alta 9.3

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Adobe AIR SDK before 19.0.0.241, and Adobe AIR SDK & Compiler before 19.0.0.241 a…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.25EPSS
CVE-2002-2029
Alta 7.5

PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arbitrary files and possibly execute arbitrary programs via an HTTP request for php.exe with a filename in the query string.

apache http_server
0.25EPSS
CVE-2015-2548
Alta 9.3

Use-after-free vulnerability in the Tablet Input Band in Windows Shell in Microsoft Windows Vista SP2 and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Microsoft Tablet Input Band Use After Free Vulnerability."

microsoft windows_7 · microsoft windows_vista
0.25EPSS
CVE-2017-2932
Alta 8.8

Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript MovieClip class. Successful exploitation could lead to arbitrary code execution.

adobe flash_player
0.25EPSS
CVE-2018-0806
Alta 8.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code …

microsoft office · microsoft office_compatibility_pack · microsoft word
0.25EPSS
CVE-2006-0032
Media 4.3

Cross-site scripting (XSS) vulnerability in the Indexing Service in Microsoft Windows 2000, XP, and Server 2003, when the Encoding option is set to Auto Select, allows remote attackers to inject arbitrary web script or HTML via a UTF-7 encoded URL, which is in…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.25EPSS
CVE-2008-2247
Media 4.3

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability than CVE-2008-2248.

microsoft exchange_server
0.25EPSS
CVE-2014-4129
Alta 9.3

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.25EPSS
CVE-2012-2522
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a malformed virtual function table after this table's deletion, aka "Virtual Function Table Corruption Remo…

microsoft internet_explorer
0.25EPSS
CVE-2018-8162
Alta 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Excel. This CVE ID is uni…

microsoft excel · microsoft office · microsoft office_for_mac
0.24EPSS