imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2015-3183
Media 5.0

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size …

apache http_server
0.73EPSS
CVE-2011-3389
Media 4.3

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-mi…

canonical ubuntu_linux · debian debian_linux · google chrome · haxx curl · e altri 11
0.73EPSS
CVE-2016-7202
Alta 7.5

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability…

microsoft edge
0.73EPSS
CVE-2004-0204
Alta 7.5

Directory traversal vulnerability in the web viewers for Business Objects Crystal Reports 9 and 10, and Crystal Enterprise 9 or 10, as used in Visual Studio .NET 2003 and Outlook 2003 with Business Contact Manager, Microsoft Business Solutions CRM 1.2, and oth…

bea weblogic_server · borland_software j_builder · businessobjects crystal_enterprise · businessobjects crystal_enterprise_java_sdk · e altri 5
0.73EPSS
CVE-2023-36039
Alta 8.0

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.73EPSS
CVE-2019-10072
Alta 7.5

The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were…

apache tomcat
0.73EPSS
CVE-2020-13945
Media 6.5

In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the default token is allowed to access APISIX management data. This affects versions 1.2, 1.3, 1.4, 1.5.

apache apisix
0.73EPSS
CVE-2008-0356
Alta 10.0

Buffer overflow in the Independent Management Architecture (IMA) service in Citrix Presentation Server (MetaFrame Presentation Server) 4.5 and earlier, Access Essentials 2.0 and earlier, and Desktop Server 1.0 allows remote attackers to execute arbitrary code …

citrix access_essentials · citrix desktop_server · citrix metaframe_presentation_server · citrix presentation_server
0.73EPSS
CVE-2016-0117
Alta 7.8

The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remote Code Execution Vulnerability."

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012
0.73EPSS
CVE-2020-1421
Alta 8.8

A remote code execution vulnerability exists in Microsoft Windows that could allow remote code execution if a .LNK file is processed.An attacker who successfully exploited this vulnerability could gain the same user rights as the local user, aka 'LNK Remote Co…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.73EPSS
CVE-2007-0038
Alta 9.3

Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · microsoft windows_xp
0.73EPSS
CVE-2017-5637
Alta 7.5

Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper server if abused, which leads to the server unable to serve legitimate client requests. Apache ZooKeeper thru version 3.4.9 and 3.5.2 suffe…

apache zookeeper · debian debian_linux
0.73EPSS
CVE-2019-0199
Alta 7.5

The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open …

apache tomcat
0.73EPSS
CVE-2013-2115
Alta 8.1

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2…

apache struts
0.73EPSS
CVE-2021-22992
Critica 9.8

On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before 12.1.5.3, and 11.6.x before 11.6.5.3, a malicious HTTP response to an Advanced WAF/BIG-IP ASM virtual server with Login Page configur…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_advanced_web_application_firewall · f5 big-ip_analytics · e altri 10
0.73EPSS
CVE-2023-22374
Alta 8.5

A format string vulnerability exists in iControl SOAP that allows an authenticated attacker to crash the iControl SOAP CGI process or, potentially execute arbitrary code. In appliance mode BIG-IP, a successful exploit of this vulnerability can allow the attac…

f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · f5 big-ip_analytics · f5 big-ip_application_acceleration_manager · e altri 8
0.73EPSS
CVE-2000-0945
Alta 10.0

The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication when the enable password is not set, via a URL containing the /exec/ directory.

cisco catalyst_3500_xl
0.73EPSS
CVE-2004-0899
Media 5.0

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a …

microsoft windows_nt
0.73EPSS
CVE-2008-6505
Media 5.0

Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote attackers to read arbitrary files via a ..%252f (encoded dot dot slash) in a URI with a /struts/ path, related to (1) FilterDispatcher in 2.0.…

apache struts
0.73EPSS
CVE-2003-0001
Media 5.0

Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote attackers to obtain information from previous packets or kernel memory by using malformed packets, as demonstrated by Etherleak.

freebsd freebsd · linux linux_kernel · microsoft windows_2000 · microsoft windows_2000_terminal_services · e altri 1
0.73EPSS
CVE-2013-5331
Alta 9.3

Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote…

adobe air · adobe air_sdk · adobe flash_player
0.72EPSS
CVE-2021-1472
Media 5.3

Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote attacker could execute arbitrary commands or bypass authentication and upload files on an affected device. For more information about these…

cisco rv160_firmware · cisco rv160w_firmware · cisco rv260_firmware · cisco rv260p_firmware · e altri 5
0.72EPSS
CVE-2020-11991
Alta 7.5

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to access any file on the server system.

apache cocoon
0.72EPSS
CVE-1999-0256
Alta 7.5

Buffer overflow in War FTP allows remote execution of commands.

jgaa warftpd · microsoft windows_95 · microsoft windows_nt
0.72EPSS
CVE-2004-1134
Alta 10.0

Buffer overflow in the Microsoft W3Who ISAPI (w3who.dll) allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long query string.

microsoft w3who.dll
0.72EPSS