imPC@ndo EN

CVE Tracker

56.415 CVE

CVE-2020-9484
Alta 7.0

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager…

apache tomcat · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 22
0.57EPSS
CVE-2004-0842
Alta 7.5

Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer over…

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s3400 · e altri 3
0.57EPSS
CVE-2008-1087
Alta 9.3

Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 2008 allows remote attackers to execute arbitrary code via an EMF image file with crafted filename parameters, aka "GDI Stack Overflow Vulnerab…

microsoft windows-nt · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · e altri 1
0.57EPSS
CVE-2015-3080
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.57EPSS
CVE-2006-3086
Alta 9.3

Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrat…

microsoft hyperlink_object_library
0.56EPSS
CVE-2022-23253
Media 6.5

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.56EPSS
CVE-2011-2882
Alta 9.3

Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Edition 8.1 before 8.1-67.7, 9.0 before 9.0-70.5, and 9.1 before 9.1-96.4 allows remote attackers to execute arbitrary code via crafted HTTP h…

citrix access_gateway
0.56EPSS
CVE-2016-0784
Media 6.5

Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.

apache openmeetings
0.56EPSS
CVE-2022-22972
Critica 9.8

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to a…

vmware cloud_foundation · vmware identity_manager · vmware vrealize_automation · vmware vrealize_suite_lifecycle_manager · e altri 1
0.56EPSS
CVE-2025-48988
Alta 7.5

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time th…

apache tomcat
0.56EPSS
CVE-2022-38044
Alta 7.8

Windows CD-ROM File System Driver Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.56EPSS
CVE-2019-9516
Media 6.5

Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. So…

apache traffic_server · apple swiftnio · canonical ubuntu_linux · debian debian_linux · e altri 15
0.56EPSS
CVE-2013-6397
Media 4.3

Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. …

apache solr
0.56EPSS
CVE-2018-0935
Alta 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting en…

microsoft internet_explorer
0.56EPSS
CVE-2014-9708
Media 5.0

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".

embedthis appweb · juniper junos · oracle enterprise_communications_broker
0.56EPSS
CVE-2018-14007
Critica 9.8

Citrix XenServer 7.1 and newer allows Directory Traversal.

citrix xenserver
0.56EPSS
CVE-2018-8011
Alta 7.5

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

apache http_server · netapp cloud_backup
0.56EPSS
CVE-2008-3704
Alta 9.3

Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 …

microsoft visual_basic · microsoft visual_foxpro · microsoft visual_studio · microsoft visual_studio_.net
0.56EPSS
CVE-2006-3280
Alta 7.5

Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Locatio…

microsoft internet_explorer
0.56EPSS
CVE-2017-8635
Alta 7.5

Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the …

microsoft edge · microsoft internet_explorer
0.56EPSS
CVE-2000-0408
Media 5.0

IIS 4.05 and 5.0 allow remote attackers to cause a denial of service via a long, complex URL that appears to contain a large number of file extensions, aka the "Malformed Extension Data in URL" vulnerability.

microsoft internet_information_server · microsoft internet_information_services
0.56EPSS
CVE-2026-33824
Critica 9.8

Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · e altri 9
0.56EPSS
CVE-2023-21742
Alta 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_foundation · microsoft sharepoint_server
0.56EPSS
CVE-2013-0025
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer SLayoutRun Use After Free Vulnerability."

microsoft internet_explorer
0.56EPSS
CVE-2016-5387
Alta 8.1

The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's…

apache http_server · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 16
0.56EPSS