imPC@ndo EN

CVE Tracker

56.415 CVE

CVE-2013-5704
Media 5.0

The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security is…

apache http_server · apple mac_os_x · apple mac_os_x_server · canonical ubuntu_linux · e altri 11
0.60EPSS
CVE-2020-3250
Critica 9.8

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.60EPSS
CVE-2025-31650
Alta 7.5

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfM…

apache tomcat
0.60EPSS
CVE-2013-0810
Alta 8.1

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote attackers to execute arbitrary code via a crafted screensaver in a theme file, aka "Windows Theme File Remote Code Execution Vulnerability."

microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.60EPSS
CVE-2005-0053
Alta 7.5

Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "Drag-and-Drop Vulnerability."

microsoft ie · microsoft internet_explorer · microsoft windows_2000 · microsoft windows_2003_server · e altri 4
0.60EPSS
CVE-2011-4404
Media 5.0

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified…

vmware vcenter_update_manager
0.60EPSS
CVE-2017-11870
Alta 7.5

ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vul…

microsoft chakracore · microsoft edge
0.60EPSS
CVE-2017-11841
Alta 7.5

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "…

microsoft chakracore · microsoft edge
0.60EPSS
CVE-2017-11840
Alta 7.5

ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "…

microsoft chakracore · microsoft edge
0.60EPSS
CVE-2011-4317
Media 4.3

The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for …

apache http_server
0.60EPSS
CVE-2019-9511
Alta 7.5

Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipu…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · e altri 16
0.60EPSS
CVE-2020-1300
Alta 8.8

A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and tr…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.60EPSS
CVE-2006-4868
Alta 9.3

Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language…

microsoft internet_explorer · microsoft outlook
0.60EPSS
CVE-2024-27136
Media 6.1

XSS in Upload page in Apache JSPWiki 2.12.1 and priors allows the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgrade to 2.12.2 or later.

apache jspwiki
0.59EPSS
CVE-2013-3138
Alta 7.1

Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted T…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2008 · e altri 1
0.59EPSS
CVE-2016-1285
Media 6.8

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to…

canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · isc bind · e altri 10
0.59EPSS
CVE-2008-4037
Alta 9.3

Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrat…

microsoft windows · microsoft windows_2000 · microsoft windows_server_2008 · microsoft windows_vista
0.59EPSS
CVE-2008-2463
Media 6.8

The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a craf…

microsoft office_snapshot_viewer_activex
0.59EPSS
CVE-2019-0190
Alta 7.5

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.…

apache http_server · oracle enterprise_manager_ops_center · oracle hospitality_guest_access · oracle instantis_enterprisetrack · e altri 1
0.59EPSS
CVE-2021-24086
Alta 7.5

Windows TCP/IP Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.59EPSS
CVE-2007-3386
Media 4.3

Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an h…

apache tomcat
0.59EPSS
CVE-2011-3414
Alta 7.8

The CaseInsensitiveHashProvider.getHashCode function in the HashTable implementation in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 computes hash values for form parameters without restricting the ability to trig…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.59EPSS
CVE-2003-0717
Alta 7.5

The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_me · microsoft windows_nt · e altri 1
0.59EPSS
CVE-2003-0605
Alta 7.5

The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface tha…

microsoft windows_2000
0.59EPSS
CVE-2006-1364
Alta 7.5

Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each…

microsoft asp.net
0.59EPSS