imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2016-1909
Critica 9.8

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the For…

fortinet fortios
0.71EPSS
CVE-2001-0540
Media 5.0

Memory leak in Terminal servers in Windows NT and Windows 2000 allows remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed Remote Desktop Protocol (RDP) requests to port 3389.

microsoft terminal_server
0.71EPSS
CVE-2002-0079
Alta 7.5

Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Server Pages allows attackers to cause a denial of service or execute arbitrary code.

microsoft internet_information_server · microsoft internet_information_services
0.71EPSS
CVE-2020-16952
Alta 8.6

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the ShareP…

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.71EPSS
CVE-2020-4211
Critica 9.8

IBM Spectrum Protect Plus 10.1.0 and 10.1.5 could allow a remote attacker to execute arbitrary code on the system. By using a specially crafted HTTP command, an attacker could exploit this vulnerability to execute arbitrary command on the system. IBM X-Force I…

ibm spectrum_protect
0.71EPSS
CVE-2015-2509
Alta 9.3

Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_vista
0.71EPSS
CVE-2018-8279
Alta 7.5

A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8125, CVE-2018-8262, CVE-…

microsoft chakracore · microsoft edge
0.71EPSS
CVE-2023-31102
Alta 7.8

Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.

7-zip 7-zip · netapp active_iq_unified_manager · netapp oncommand_workflow_automation
0.71EPSS
CVE-2019-0887
Alta 8.0

A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.

microsoft remote_desktop_client · microsoft windows_10 · microsoft windows_11_21h2 · microsoft windows_7 · e altri 6
0.71EPSS
CVE-2015-0096
Alta 9.3

Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain priv…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · e altri 5
0.71EPSS
CVE-2024-49112
Critica 9.8

Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 10
0.71EPSS
CVE-2017-12616
Alta 7.5

When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.

apache tomcat
0.71EPSS
CVE-2014-1762
Alta 7.5

Unspecified vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code with medium-integrity privileges and bypass a sandbox protection mechanism via unknown vectors, as demonstrated by ZDI during a Pwn4Fun comp…

microsoft internet_explorer
0.71EPSS
CVE-2020-17143
Alta 8.8

Microsoft Exchange Server Information Disclosure Vulnerability

microsoft exchange_server
0.71EPSS
CVE-2023-43622
Alta 7.5

An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" at…

apache http_server
0.71EPSS
CVE-2024-38063
Critica 9.8

Windows TCP/IP Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.71EPSS
CVE-2000-0884
Alta 7.5

IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary commands, via malformed URLs that contain UNICODE encoded characters, aka the "Web Server Folder Traversal" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.71EPSS
CVE-2007-6750
Media 5.0

The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris, related to the lack of the mod_reqtimeout module in versions before 2.2.15.

apache http_server
0.71EPSS
CVE-1999-0513
Media 5.0

ICMP messages to broadcast addresses are allowed, allowing for a Smurf attack that can cause a denial of service.

digital unix · freebsd freebsd · hp hp-ux · ibm aix · e altri 4
0.70EPSS
CVE-2015-0336
Alta 9.3

Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion," a different vulnerability than CVE-2015-…

adobe flash_player
0.70EPSS
CVE-2023-20864
Critica 9.8

VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.

vmware aria_operations_for_logs · vmware cloud_foundation
0.70EPSS
CVE-2020-13951
Alta 7.5

Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.

apache openmeetings
0.70EPSS
CVE-2016-7288
Alta 7.5

The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-72…

microsoft edge
0.70EPSS
CVE-2022-23270
Alta 8.1

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 5
0.70EPSS
CVE-2005-0045
Alta 7.5

The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 com…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.70EPSS