imPC@ndo EN

CVE Tracker

56.413 CVE

CVE-2002-0148
Alta 7.5

Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to execute arbitrary script as other users via an HTTP error page.

microsoft internet_information_server · microsoft internet_information_services
0.61EPSS
CVE-2006-1189
Alta 10.0

Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Pars…

microsoft internet_explorer
0.61EPSS
CVE-2005-2087
Media 5.0

Internet Explorer 5.01 SP4 up to 6 on various Windows operating systems, including IE 6.0.2900.2180 on Windows XP, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs …

microsoft ie · microsoft internet_explorer
0.61EPSS
CVE-2021-27084
Alta 7.8

Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability

microsoft maven_for_java
0.61EPSS
CVE-2019-1252
Media 6.5

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1286.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.61EPSS
CVE-2006-1190
Alta 10.0

Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote…

microsoft internet_explorer
0.61EPSS
CVE-2010-0239
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Router Advertisement packets, which allows remote attackers to execute arbitrary cod…

microsoft windows_server_2008 · microsoft windows_vista
0.61EPSS
CVE-2025-29971
Alta 7.5

Out-of-bounds read in Web Threat Defense (WTD.sys) allows an unauthorized attacker to deny service over a network.

microsoft windows_11_22h2 · microsoft windows_11_23h2 · microsoft windows_11_24h2
0.61EPSS
CVE-2021-26424
Critica 9.9

Windows TCP/IP Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.61EPSS
CVE-2023-28502
Critica 9.8

Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow in the "udadmin" service that can lead to remote code execution as the root user.

rocketsoftware unidata · rocketsoftware universe
0.61EPSS
CVE-2004-0549
Alta 10.0

The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6, allows remote attackers to execute arbitrary code in the Local Security context by using the showModalDialog method and modifying the locat…

microsoft internet_explorer
0.61EPSS
CVE-2015-6096
Media 4.3

The XML DTD parser in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to read arbitrary files via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE…

microsoft .net_framework
0.61EPSS
CVE-2010-0258
Alta 7.8

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 …

microsoft excel · microsoft office · microsoft office_compatibility_pack · microsoft office_excel_viewer · e altri 2
0.61EPSS
CVE-2011-1260
Alta 9.3

Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability.…

microsoft internet_explorer
0.61EPSS
CVE-2007-1751
Alta 9.3

Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to access an uninitialized or deleted object, related to prototype variables and table cells, aka "Uninitialized Memory Corruption Vulnera…

microsoft internet_explorer
0.61EPSS
CVE-2020-27128
Media 6.5

A vulnerability in the application data endpoints of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to write arbitrary files to an affected system. The vulnerability is due to improper validation of requests to APIs. An attacker co…

cisco sd-wan
0.61EPSS
CVE-2018-3639
Media 5.5

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-c…

arm cortex-a · canonical ubuntu_linux · debian debian_linux · intel atom_c · e altri 278
0.61EPSS
CVE-2021-30181
Critica 9.8

Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these rules, Dubb…

apache dubbo
0.61EPSS
CVE-2006-1314
Alta 7.5

Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that trigger…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.61EPSS
CVE-2011-1996
Alta 9.3

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Option Element Remote Code Execution Vulnerability."

microsoft internet_explorer
0.60EPSS
CVE-2021-30180
Critica 9.8

Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. These rules are used by the customers when making a request in order to find the right endpoint. When parsing these YAML rules, Dubbo custome…

apache dubbo
0.60EPSS
CVE-2010-0478
Alta 9.3

Stack-based buffer overflow in nsum.exe in the Windows Media Unicast Service in Media Services for Microsoft Windows 2000 Server SP4 allows remote attackers to execute arbitrary code via crafted packets associated with transport information, aka "Media Service…

microsoft windows_2000
0.60EPSS
CVE-2025-25256
Critica 9.8

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through 7.3.1, 7.2.0 through 7.2.5, 7.1.0 through 7.1.7, 7.0.0 through 7.0.3 and before 6.7.9 allows an una…

fortinet fortisiem
0.60EPSS
CVE-2004-0575
Alta 10.0

Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffe…

microsoft windows_2003_server · microsoft windows_xp
0.60EPSS
CVE-2019-17567
Media 5.3

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass throug…

apache http_server · fedoraproject fedora · oracle enterprise_manager_ops_center · oracle instantis_enterprisetrack · e altri 1
0.60EPSS