EN

CVE Tracker

56.560 CVE

CVE-2019-1352
Alta 8.8

A remote code execution vulnerability exists when Git for Visual Studio improperly sanitizes input, aka 'Git for Visual Studio Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1349, CVE-2019-1350, CVE-2019-1354, CVE-2019-1387.

microsoft visual_studio_2017 · microsoft visual_studio_2019
0.24EPSS
CVE-2006-3101
Media 4.3

Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

cisco secure_access_control_server
0.24EPSS
CVE-2002-0190
Alta 7.5

Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitrary code under fewer security restrictions via a malformed web page that requires NetBIOS connectivity, aka "Zone Spoofing through Malformed Web Page" vulnerability.

microsoft internet_explorer
0.24EPSS
CVE-2006-4071
Bassa 2.6

Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF…

microsoft windows_2003_server · microsoft windows_xp
0.24EPSS
CVE-2013-0086
Media 5.0

Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."

microsoft sharepoint_foundation · microsoft sharepoint_server
0.24EPSS
CVE-1999-1376
Alta 10.0

Buffer overflow in fpcount.exe in IIS 4.0 with FrontPage Server Extensions allows remote attackers to execute arbitrary commands.

microsoft internet_information_server
0.24EPSS
CVE-2017-8717
Alta 7.8

The Microsoft JET Database Engine in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to take control of an affected system, due…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.24EPSS
CVE-2012-5611
Media 6.5

Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53 and other versions through 5.1.66, and MariaDB 5.5.2.x before 5.5.28a, 5.3.x before 5.3.11, 5.2.x before 5.2.13 and 5.1.x before 5.1.66, al…

mariadb mariadb · oracle mysql
0.24EPSS
CVE-2024-52046
Critica 9.8

The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process by se…

apache mina
0.24EPSS
CVE-2015-6135
Media 5.0

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine I…

microsoft jscript · microsoft vbscript
0.24EPSS
CVE-2010-3336
Alta 9.3

Microsoft Office XP SP3, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption, aka "MSO Large SPID Read AV V…

microsoft office · microsoft open_xml_file_format_converter
0.24EPSS
CVE-2010-3335
Alta 9.3

Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code via a crafted Office document that triggers m…

microsoft office · microsoft open_xml_file_format_converter
0.24EPSS
CVE-2013-3203
Alta 9.3

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-320…

microsoft internet_explorer
0.24EPSS
CVE-2025-31644
Alta 8.7

When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS Shell (tmsh) command which may allow an authenticated attacker with administrator role privileges to execute arbitrary system commands. A s…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · e altri 17
0.24EPSS
CVE-2002-0364
Alta 7.5

Buffer overflow in the chunked encoding transfer mechanism in IIS 4.0 and 5.0 allows attackers to execute arbitrary code via the processing of HTR request sessions, aka "Heap Overrun in HTR Chunked Encoding Could Enable Web Server Compromise."

microsoft internet_information_server · microsoft internet_information_services
0.24EPSS
CVE-2006-5574
Alta 9.3

Unspecified vulnerability in the Brazilian Portuguese Grammar Checker in Microsoft Office 2003 and the Multilingual Interface for Office 2003, Project 2003, and Visio 2003 allows user-assisted remote attackers to execute arbitrary code via crafted text that is…

microsoft office · microsoft office_multilingual_user_interface_pack · microsoft office_proofing_tools · microsoft project_multilingual_user_interface_pack · e altri 1
0.24EPSS
CVE-2020-2036
Alta 8.8

A reflected cross-site scripting (XSS) vulnerability exists in the PAN-OS management web interface. A remote attacker able to convince an administrator with an active authenticated session on the firewall management interface to click on a crafted link to that…

paloaltonetworks pan-os
0.24EPSS
CVE-2017-5972
Alta 7.5

The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demo…

linux linux_kernel
0.24EPSS
CVE-2003-0010
Alta 7.5

Integer overflow in JsArrayFunctionHeapSort function used by Windows Script Engine for JScript (JScript.dll) on various Windows operating system allows remote attackers to execute arbitrary code via a malicious web page or HTML e-mail that uses a large array i…

microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_98 · microsoft windows_98se · e altri 3
0.24EPSS
CVE-2018-0812
Alta 7.8

Equation Editor in Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Memory Corru…

microsoft office · microsoft office_compatibility_pack · microsoft word
0.24EPSS
CVE-2006-0014
Media 5.1

Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values.

microsoft outlook_express
0.24EPSS
CVE-2015-2526
Media 5.0

Microsoft .NET Framework 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to cause a denial of service to an ASP.NET web site via crafted requests, aka "MVC Denial of Service Vulnerability."

microsoft .net_framework
0.24EPSS
CVE-2015-2447
Alta 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2446.

microsoft internet_explorer
0.24EPSS
CVE-2023-36005
Alta 7.5

Windows Telephony Server Elevation of Privilege Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 9
0.24EPSS
CVE-2013-1281
Alta 7.1

The NFS server in Microsoft Windows Server 2008 R2 and R2 SP1 and Server 2012 allows remote attackers to cause a denial of service (NULL pointer dereference and reboot) via an attempted renaming of a file or folder located on a read-only share, aka "NULL Deref…

microsoft windows_server_2008 · microsoft windows_server_2012
0.24EPSS