imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2018-1270
Critica 9.8

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious us…

debian debian_linux · oracle application_testing_suite · oracle big_data_discovery · oracle communications_converged_application_server · e altri 24
0.77EPSS
CVE-2017-0290
Alta 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft forefront_security · microsoft malware_protection_engine · microsoft windows_defender
0.77EPSS
CVE-1999-1011
Alta 10.0

The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x exposes unsafe methods, which allows remote attackers to execute arbitrary commands.

microsoft data_access_components · microsoft index_server · microsoft internet_information_server · microsoft site_server
0.77EPSS
CVE-2023-36899
Alta 8.8

ASP.NET Elevation of Privilege Vulnerability

microsoft .net_framework
0.77EPSS
CVE-2017-12243
Alta 7.8

A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on the de…

cisco firepower_4100_next-generation_firewall_firmware · cisco firepower_9300_security_appliance_firmware · cisco unified_computing_system_manager_firmware
0.77EPSS
CVE-2016-1287
Critica 9.8

Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 dev…

cisco adaptive_security_appliance_software
0.77EPSS
CVE-2016-3236
Critica 9.8

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.77EPSS
CVE-2021-39843
Alta 7.8

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploi…

adobe acrobat · adobe acrobat_dc · adobe acrobat_reader · adobe acrobat_reader_dc
0.77EPSS
CVE-2021-41303
Critica 9.8

Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0.

apache shiro · oracle financial_services_crime_and_compliance_management_studio
0.77EPSS
CVE-2000-0649
Bassa 2.6

IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page which is protected by basic authentication and has no realm defined.

microsoft internet_information_server · microsoft internet_information_services
0.77EPSS
CVE-2022-26937
Critica 9.8

Windows Network File System Remote Code Execution Vulnerability

microsoft windows_server · microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · e altri 2
0.77EPSS
CVE-2022-38053
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.76EPSS
CVE-2003-0714
Alta 7.5

The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer ove…

microsoft exchange_server
0.76EPSS
CVE-2021-21346
Media 6.1

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.76EPSS
CVE-2007-0042
Alta 7.8

Interpretation conflict in ASP.NET in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to access configuration files and obtain sensitive information, and possibly bypass security mechanisms that t…

microsoft .net_framework
0.76EPSS
CVE-2006-5745
Alta 7.6

Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments th…

microsoft xml_core_services
0.76EPSS
CVE-2002-1142
Alta 7.5

Heap-based buffer overflow in the Remote Data Services (RDS) component of Microsoft Data Access Components (MDAC) 2.1 through 2.6, and Internet Explorer 5.01 through 6.0, allows remote attackers to execute code via a malformed HTTP request to the Data Stub.

microsoft data_access_components · microsoft ie · microsoft internet_explorer
0.76EPSS
CVE-2021-21344
Media 5.3

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input st…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.76EPSS
CVE-2013-5486
Alta 10.0

Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOT…

cisco prime_data_center_network_manager
0.76EPSS
CVE-2023-32007
Alta 8.8

** UNSUPPORTED WHEN ASSIGNED ** The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACL…

apache spark
0.76EPSS
CVE-2007-6388
Media 4.3

Cross-site scripting (XSS) vulnerability in mod_status in the Apache HTTP Server 2.2.0 through 2.2.6, 2.0.35 through 2.0.61, and 1.3.2 through 1.3.39, when the server-status page is enabled, allows remote attackers to inject arbitrary web script or HTML via un…

apache http_server
0.76EPSS
CVE-2008-1232
Media 4.3

Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpS…

apache tomcat
0.76EPSS
CVE-2019-1937
Critica 9.8

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token w…

cisco integrated_management_controller_supervisor · cisco ucs_director · cisco ucs_director_express_for_big_data
0.76EPSS
CVE-2019-1439
Media 6.5

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.76EPSS
CVE-2015-0318
Alta 10.0

Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v…

adobe flash_player
0.76EPSS