imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2021-21345
Media 5.8

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed inpu…

apache activemq · apache jmeter · debian debian_linux · fedoraproject fedora · e altri 12
0.72EPSS
CVE-2014-0307
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a certain sequence of manipulations of a TextRange element, aka "Internet Explorer Memory Corru…

microsoft internet_explorer
0.72EPSS
CVE-2017-8740
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit…

microsoft edge
0.72EPSS
CVE-2017-8729
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerabilit…

microsoft edge
0.72EPSS
CVE-2006-7196
Media 4.3

Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time …

apache tomcat
0.72EPSS
CVE-2024-20697
Alta 7.3

Windows libarchive Remote Code Execution Vulnerability

microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_server_2022_23h2
0.72EPSS
CVE-2017-8636
Alta 7.5

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the …

microsoft edge · microsoft internet_explorer
0.72EPSS
CVE-2010-2263
Media 5.0

nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or unparsed content of arbitrary files under the web document root by appending ::$DATA to the URI.

f5 nginx
0.72EPSS
CVE-2007-2815
Alta 10.0

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configuration, which allows remote attackers to bypass NTLM and basic authentication mechanisms and access private web …

microsoft internet_information_services
0.72EPSS
CVE-2007-1070
Alta 10.0

Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance Filer 5.61 and 5.62, allow remote attackers to execute arbitrary code via crafted RPC requests to TmRpcSrv.dll that trigger overflows when ca…

trend_micro serverprotect
0.72EPSS
CVE-2009-3672
Alta 9.3

Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or (2) are deleted, which allows remote attackers to execute arbitrary code via vectors involving a call to the getElementsByTagName method fo…

microsoft internet_explorer
0.72EPSS
CVE-2013-1966
Alta 9.3

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.

apache struts
0.72EPSS
CVE-2023-0210
Alta 7.5

A bug affects the Linux kernel’s ksmbd NTLMv2 authentication and is known to crash the OS immediately in Linux-based systems.

linux linux_kernel
0.72EPSS
CVE-2010-3973
Alta 9.3

The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in Microsoft Windows XP SP2 and SP3 allows remote attackers to execute arbitrary code via a crafted argument to the AddContextRef method, possi…

microsoft wmi_administrative_tools
0.72EPSS
CVE-2015-0072
Media 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFR…

microsoft internet_explorer
0.72EPSS
CVE-2006-0564
Alta 7.5

Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included in the Microsoft HTML Help 1.4 SDK, allows context-dependent attackers to execute arbitrary code via a .hhp file with a long Contents file f…

microsoft html_help · microsoft html_help_workshop
0.72EPSS
CVE-2017-8641
Alta 7.5

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the …

microsoft edge · microsoft internet_explorer
0.72EPSS
CVE-2016-7241
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.71EPSS
CVE-2016-3247
Alta 7.5

Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.71EPSS
CVE-2021-28480
Critica 9.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.71EPSS
CVE-2010-2703
Alta 10.0

Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.

hp openview_network_node_manager
0.71EPSS
CVE-2011-3400
Alta 9.3

Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote attackers to execute arbitrary code via a crafted object in a file, aka "OLE Property Vulnerability."

microsoft windows_server_2003 · microsoft windows_xp
0.71EPSS
CVE-2019-0547
Critica 9.8

A memory corruption vulnerability exists in the Windows DHCP client when an attacker sends specially crafted DHCP responses to a client, aka "Windows DHCP Client Remote Code Execution Vulnerability." This affects Windows 10, Windows 10 Servers.

microsoft windows_10
0.71EPSS
CVE-2018-8229
Alta 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.71EPSS
CVE-2017-8755
Alta 7.5

Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripti…

microsoft edge
0.71EPSS