imPC@ndo EN

CVE Tracker

56.415 CVE

CVE-2011-0593
Alta 9.3

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, a different…

adobe acrobat · adobe acrobat_reader
0.50EPSS
CVE-1999-0449
Alta 7.8

The ExAir sample site in IIS 4 allows remote attackers to cause a denial of service (CPU consumption) via a direct request to the (1) advsearch.asp, (2) query.asp, or (3) search.asp scripts.

microsoft internet_information_server
0.50EPSS
CVE-2001-0876
Alta 7.5

Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arbitrary code via a NOTIFY directive with a long Location URL.

microsoft windows_98 · microsoft windows_98se · microsoft windows_me · microsoft windows_xp
0.49EPSS
CVE-2016-0015
Alta 7.8

DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "Direc…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · e altri 3
0.49EPSS
CVE-2018-0258
Critica 9.8

A vulnerability in the Cisco Prime File Upload servlet affecting multiple Cisco products could allow a remote attacker to upload arbitrary files to any directory of a vulnerable device (aka Path Traversal) and execute those files. This vulnerability affects th…

cisco prime_data_center_network_manager · cisco prime_infrastructure
0.49EPSS
CVE-2017-11890
Alta 7.5

Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow an attacker to execute arbitrary code in the context of the current user…

microsoft internet_explorer
0.49EPSS
CVE-2020-13950
Alta 7.5

Apache HTTP Server versions 2.4.41 to 2.4.46 mod_proxy_http can be made to crash (NULL pointer dereference) with specially crafted requests using both Content-Length and Transfer-Encoding headers, leading to a Denial of Service

apache http_server · debian debian_linux · fedoraproject fedora · oracle enterprise_manager_ops_center · e altri 2
0.49EPSS
CVE-2019-17570
Critica 9.8

An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RP…

apache xml-rpc · canonical ubuntu_linux · debian debian_linux · fedoraproject fedora · e altri 1
0.49EPSS
CVE-2008-4114
Alta 7.1

srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB W…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.49EPSS
CVE-2007-0069
Alta 9.3

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger mem…

microsoft windows_2003_server · microsoft windows_vista · microsoft windows_xp
0.49EPSS
CVE-2022-24760
Critica 10.0

Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that …

parseplatform parse-server
0.49EPSS
CVE-2010-0241
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when IPv6 is enabled, does not properly perform bounds checking on ICMPv6 Route Information packets, which allows remote attackers to execute arbitrary code v…

microsoft windows_server_2008 · microsoft windows_vista
0.49EPSS
CVE-2006-1315
Media 5.0

The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not prope…

microsoft server_service
0.49EPSS
CVE-2016-0736
Alta 7.5

In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured ciphers with possibly either CBC or ECB modes of operation (AES256-CBC by default), hence no selectable or builtin authenticated encryption. …

apache http_server
0.49EPSS
CVE-2004-0200
Alta 9.3

Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large i…

microsoft .net_framework · microsoft digital_image_pro · microsoft digital_image_suite · microsoft excel · e altri 20
0.49EPSS
CVE-2007-4776
Alta 9.3

Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to execute arbitrary code via a Visual Basic project (vbp) file containing a long Reference line, related to VBP_Open and OLE. NOTE: there are li…

microsoft visual_basic
0.49EPSS
CVE-2019-12992
Alta 8.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.49EPSS
CVE-2017-11793
Alta 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context…

microsoft internet_explorer
0.49EPSS
CVE-2018-8420
Alta 8.8

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server
0.49EPSS
CVE-2020-17117
Media 6.6

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.49EPSS
CVE-2010-0240
Alta 10.0

The TCP/IP implementation in Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2, when a custom network driver is used, does not properly handle local fragmentation of Encapsulating Security Payload (ESP) over UDP packets, which allows remo…

microsoft windows_server_2008 · microsoft windows_vista
0.49EPSS
CVE-2004-0841
Media 5.0

Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."

avaya definity_one_media_server · avaya ip600_media_servers · avaya modular_messaging_message_storage_server · avaya s3400 · e altri 3
0.49EPSS
CVE-2006-0025
Alta 9.3

Stack-based buffer overflow in Microsoft Windows Media Player 9 and 10 allows remote attackers to execute arbitrary code via a PNG image with a large chunk size.

microsoft windows_media_player
0.49EPSS
CVE-2007-2223
Alta 9.3

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

microsoft xml_core_services
0.49EPSS
CVE-2004-0216
Alta 10.0

Integer overflow in the Install Engine (inseng.dll) for Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via a malicious website or HTML email with a long .CAB file name, which triggers the integer overflow when calculating …

microsoft ie · microsoft internet_explorer
0.49EPSS