EN

CVE Tracker

56.560 CVE

CVE-2016-0051
Alta 7.8

The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.23EPSS
CVE-2018-8533
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affec…

microsoft sql_server_management_studio
0.23EPSS
CVE-2018-8532
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affec…

microsoft sql_server_management_studio
0.23EPSS
CVE-2018-8527
Media 5.5

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a reference to an external entity, aka "SQL Server Management Studio Information Disclosure Vulnerability." This affect…

microsoft sql_server_management_studio
0.23EPSS
CVE-2005-0452
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft ASP.NET (.Net) 1.0 and 1.1 to SP1 allow remote attackers to inject arbitrary HTML or web script via Unicode representations for ASCII fullwidth characters that are converted to normal ASCII chara…

microsoft asp.net
0.23EPSS
CVE-2011-1964
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Style Object Memory Corruption Vuln…

microsoft internet_explorer
0.23EPSS
CVE-2011-1963
Alta 9.3

Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "XSLT Memory Corruption Vulnerabilit…

microsoft internet_explorer
0.23EPSS
CVE-2010-1883
Alta 7.8

Integer overflow in the Embedded OpenType (EOT) Font Engine in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to execute arbitrary code via a cr…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.23EPSS
CVE-2002-0647
Alta 7.5

Buffer overflow in a legacy ActiveX control used to display specially formatted text in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code, aka "Buffer Overrun in Legacy Text Formatting ActiveX Control".

microsoft internet_explorer
0.23EPSS
CVE-2020-17526
Alta 7.7

Incorrect Session Validation in Apache Airflow Webserver versions prior to 1.10.14 with default config allows a malicious airflow user on site A where they log in normally, to access unauthorized Airflow Webserver on Site B through the session from Site A. Thi…

apache airflow
0.23EPSS
CVE-2006-3897
Media 5.0

Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.

microsoft internet_explorer
0.23EPSS
CVE-2003-0002
Media 6.8

Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 allows remote attackers to execute arbitrary script via the REASONTXT parameter.

microsoft content_management_server
0.23EPSS
CVE-2004-2289
Alta 10.0

Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

microsoft windows_xp
0.23EPSS
CVE-2013-3160
Media 5.0

Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External…

microsoft office · microsoft word · microsoft word_viewer
0.23EPSS
CVE-2020-1957
Critica 9.8

Apache Shiro before 1.5.2, when using Apache Shiro with Spring dynamic controllers, a specially crafted request may cause an authentication bypass.

apache shiro · debian debian_linux
0.23EPSS
CVE-2017-8501
Alta 7.8

Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · e altri 2
0.23EPSS
CVE-2009-2525
Alta 9.3

Microsoft Windows Media Runtime, as used in DirectShow WMA Voice Codec, Windows Media Audio Voice Decoder, and Audio Compression Manager (ACM), does not properly initialize unspecified functions within compressed audio files, which allows remote attackers to e…

microsoft windows_2000 · microsoft windows_media_format_runtime · microsoft windows_media_player · microsoft windows_server_2003 · e altri 3
0.23EPSS
CVE-2013-5528
Media 4.0

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui788…

cisco unified_communications_manager
0.23EPSS
CVE-2017-0130
Alta 7.5

The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerabili…

microsoft internet_explorer
0.23EPSS
CVE-2018-0796
Alta 8.8

Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerabilit…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.23EPSS
CVE-2009-2497
Alta 9.3

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0, 2.0 SP1, 2.0 SP2, 3.5, and 3.5 SP1, and Silverlight 2, does not properly handle interfaces, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (X…

microsoft .net_framework · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · e altri 3
0.23EPSS
CVE-2018-8136
Alta 7.8

A remote code execution vulnerability exists in the way that Windows handles objects in memory, aka "Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.23EPSS
CVE-2018-8154
Critica 9.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique fr…

microsoft exchange_server
0.23EPSS
CVE-2008-2281
Alta 9.3

Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing Ja…

microsoft ie · microsoft internet_explorer
0.23EPSS
CVE-2016-7264
Alta 7.1

Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted documen…

microsoft excel · microsoft excel_for_mac · microsoft excel_viewer · microsoft office_compatibility_pack
0.23EPSS