imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2019-1619
Critica 9.8

A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. The v…

cisco data_center_network_manager
0.83EPSS
CVE-2019-9514
Alta 7.5

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depen…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · e altri 24
0.83EPSS
CVE-2012-0053
Media 4.3

protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a…

apache http_server · debian debian_linux · opensuse opensuse · redhat enterprise_linux_desktop · e altri 7
0.83EPSS
CVE-2005-0356
Media 5.0

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host t…

alaxala alaxala_networks · cisco agent_desktop · cisco aironet_ap1200 · cisco aironet_ap350 · e altri 72
0.83EPSS
CVE-2015-3105
Alta 10.0

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 18.0.0.144 on Windows and before 18.0.0.143 on OS X and Android, Adobe AIR SDK before 18.0.0.144 on Windows and …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 1
0.83EPSS
CVE-2004-0597
Alta 10.0

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk…

greg_roelofs libpng · microsoft msn_messenger · microsoft windows_98se · microsoft windows_me · e altri 2
0.83EPSS
CVE-2006-0003
Media 5.1

Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vector…

microsoft data_access_components
0.82EPSS
CVE-2018-16042
Media 6.5

Adobe Acrobat and Reader versions 2019.008.20081 and earlier, 2019.008.20080 and earlier, 2019.008.20081 and earlier, 2017.011.30106 and earlier version, 2017.011.30105 and earlier version, 2015.006.30457 and earlier, and 2015.006.30456 and earlier have a secu…

adobe acrobat_dc · adobe acrobat_reader_dc · adobe reader · iskysoft pdf_editor_6 · e altri 1
0.82EPSS
CVE-2020-26259
Media 6.8

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know fil…

apache struts · debian debian_linux · fedoraproject fedora · xstream xstream
0.82EPSS
CVE-2023-21716
Critica 9.8

Microsoft Word Remote Code Execution Vulnerability

microsoft office · microsoft office_long_term_servicing_channel · microsoft office_online_server · microsoft office_web_apps · e altri 4
0.82EPSS
CVE-2021-44224
Alta 8.2

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Sock…

apache http_server · apple mac_os_x · apple macos · debian debian_linux · e altri 8
0.82EPSS
CVE-2023-20888
Alta 8.8

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in …

vmware vrealize_network_insight
0.82EPSS
CVE-2009-2521
Media 5.0

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a…

microsoft internet_information_services
0.82EPSS
CVE-2018-0886
Alta 7.0

The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.82EPSS
CVE-2011-2140
Alta 10.0

Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows and Mac OS X and before 2.7.1.1961 on Android, allows attackers to execute arbitrary code or cause a denial of…

adobe adobe_air · adobe flash_player
0.82EPSS
CVE-2003-0818
Alta 7.5

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.82EPSS
CVE-2021-21351
Media 5.4

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. …

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.82EPSS
CVE-2017-0038
Media 5.5

gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.82EPSS
CVE-2022-44690
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_foundation · microsoft sharepoint_server
0.82EPSS
CVE-2023-21707
Alta 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.82EPSS
CVE-2016-0742
Alta 7.5

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

apple xcode · canonical ubuntu_linux · debian debian_linux · f5 nginx · e altri 2
0.82EPSS
CVE-2014-8440
Alta 10.0

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allow attackers to execu…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.82EPSS
CVE-2022-28732
Media 6.1

A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgr…

apache jspwiki
0.82EPSS
CVE-2009-2526
Alta 7.8

Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka…

microsoft windows_server_2008 · microsoft windows_vista
0.82EPSS
CVE-2015-6128
Alta 7.2

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.82EPSS