imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2022-30522
Alta 7.5

If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

apache http_server · fedoraproject fedora · netapp clustered_data_ontap
0.90EPSS
CVE-2006-2372
Alta 10.0

Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

microsoft dhcp_client_service
0.90EPSS
CVE-2009-3103
Alta 10.0

Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v…

microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2023-46264
Critica 9.8

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

ivanti avalanche
0.90EPSS
CVE-2020-11984
Critica 9.8

Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 9
0.90EPSS
CVE-2012-1445
Media 4.3

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified abi field. NOTE: this may later be SPLIT into m…

aladdin esafe · fortinet fortinet_antivirus · pandasecurity panda_antivirus · rising-global rising_antivirus
0.90EPSS
CVE-2012-1439
Media 4.3

The ELF file parser in eSafe 7.0.17.0, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file with a modified padding field. NOTE: this may later be SPLIT in…

aladdin esafe · fortinet fortinet_antivirus · pandasecurity panda_antivirus · rising-global rising_antivirus
0.90EPSS
CVE-2020-17132
Critica 9.1

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.90EPSS
CVE-2010-0219
Alta 10.0

Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by uploading a…

apache axis2 · sap businessobjects
0.90EPSS
CVE-2020-9490
Alta 7.5

Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push of…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 21
0.90EPSS
CVE-2012-1423
Media 4.3

The TAR file parser in Command Antivirus 5.2.11.5, Emsisoft Anti-Malware 5.1.0.1, F-Prot Antivirus 4.6.2.117, Fortinet Antivirus 4.2.254.0, Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0, K7 AntiVirus 9.77.3565, NOD32 Antivirus 5795, Norman Antivirus …

authentium command_antivirus · emsisoft anti-malware · eset nod32_antivirus · f-prot f-prot_antivirus · e altri 7
0.90EPSS
CVE-2017-0004
Alta 7.5

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2015-7547
Alta 8.1

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via…

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · e altri 26
0.90EPSS
CVE-2023-21547
Alta 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 5
0.89EPSS
CVE-2015-2342
Alta 10.0

The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not restrict registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol.

vmware vcenter_server
0.89EPSS
CVE-2017-5645
Critica 9.8

In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.

apache log4j · netapp oncommand_api_services · netapp oncommand_insight · netapp oncommand_workflow_automation · e altri 75
0.89EPSS
CVE-2021-45456
Critica 9.8

Apache kylin checks the legitimacy of the project before executing some commands with the project name passed in by the user. There is a mismatch between what is being checked and what is being used as the shell command argument in DiagnosisService. This may c…

apache kylin
0.89EPSS
CVE-2023-20073
Media 5.3

A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insuffici…

cisco rv340_firmware · cisco rv340w_firmware · cisco rv345_firmware · cisco rv345p_firmware
0.89EPSS
CVE-2022-30216
Alta 8.8

Windows Server Service Tampering Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_server_2016 · microsoft windows_server_2022
0.89EPSS
CVE-2023-21769
Alta 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · e altri 8
0.89EPSS
CVE-2020-5398
Alta 7.5

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the…

netapp data_availability_services · netapp snapcenter · oracle application_testing_suite · oracle communications_billing_and_revenue_management_elastic_charging_engine · e altri 29
0.88EPSS
CVE-2020-3243
Critica 9.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.88EPSS
CVE-2011-3923
Critica 9.8

Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class and execute arbitrary commands.

apache struts · redhat jboss_enterprise_web_server
0.88EPSS
CVE-2012-1454
Media 4.3

The ELF file parser in Dr.Web 5.0.2.03300, eSafe 7.0.17.0, McAfee Gateway (formerly Webwasher) 2010.1C, Rising Antivirus 22.83.00.03, Fortinet Antivirus 4.2.254.0, and Panda Antivirus 10.0.2.7 allows remote attackers to bypass malware detection via an ELF file…

aladdin esafe · drweb dr.web_antivirus · fortinet fortinet_antivirus · mcafee gateway · e altri 2
0.88EPSS
CVE-2022-41622
Alta 8.8

In all versions,  BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · e altri 8
0.88EPSS