imPC@ndo EN

CVE Tracker

56.415 CVE

CVE-2010-4701
Alta 7.6

Heap-based buffer overflow in the CDrawPoly::Serialize function in fxscover.exe in Microsoft Windows Fax Services Cover Page Editor 5.2 r2 in Windows XP Professional SP3, Server 2003 R2 Enterprise Edition SP2, and Windows 7 Professional allows remote attackers…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_xp
0.48EPSS
CVE-2022-31698
Media 5.3

The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted hea…

vmware cloud_foundation · vmware vcenter_server
0.48EPSS
CVE-2012-3569
Alta 9.3

Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.

vmware ovf_tool · vmware player · vmware workstation
0.48EPSS
CVE-2004-0121
Alta 7.5

Argument injection vulnerability in Microsoft Outlook 2002 does not sufficiently filter parameters of mailto: URLs when using them as arguments when calling OUTLOOK.EXE, which allows remote attackers to use script code in the Local Machine zone and execute arb…

microsoft office · microsoft outlook
0.48EPSS
CVE-2017-8620
Alta 8.1

Windows Search in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it improperly ha…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 3
0.48EPSS
CVE-2024-25065
Critica 9.1

Possible path traversal in Apache OFBiz allowing authentication bypass. Users are recommended to upgrade to version 18.12.12, that fixes the issue.

apache ofbiz
0.48EPSS
CVE-2005-0063
Alta 7.5

The document processing application used by the Windows Shell in Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code by modifying the CLSID stored in a file so that it is processed by HTML Application H…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 2
0.48EPSS
CVE-2015-3093
Alta 10.0

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to e…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.48EPSS
CVE-2015-3089
Alta 10.0

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow attackers to e…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.48EPSS
CVE-2011-0592
Alta 9.3

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, related to …

adobe acrobat · adobe acrobat_reader
0.48EPSS
CVE-2011-0591
Alta 9.3

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a crafted Universal 3D (U3D) file that triggers a buffer overflow during decompression, related to …

adobe acrobat · adobe acrobat_reader
0.48EPSS
CVE-2000-0114
Media 5.0

Frontpage Server Extensions allows remote attackers to determine the name of the anonymous account via an RPC POST request to shtml.dll in the /_vti_bin/ virtual directory.

microsoft internet_information_server
0.48EPSS
CVE-2015-6099
Media 4.3

Cross-site scripting (XSS) vulnerability in ASP.NET in Microsoft .NET Framework 4, 4.5, 4.5.1, 4.5.2, and 4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka ".NET Elevation of Privilege Vulnerability."

microsoft .net_framework
0.48EPSS
CVE-2011-1248
Alta 9.3

WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, r…

microsoft windows_server_2003 · microsoft windows_server_2008
0.48EPSS
CVE-2018-8544
Alta 8.8

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.48EPSS
CVE-2018-7719
Alta 7.5

Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.

acrolinx acrolinx_server
0.48EPSS
CVE-2009-2514
Alta 9.3

win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenTy…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.47EPSS
CVE-2006-4193
Alta 7.5

Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.d…

microsoft ie · microsoft internet_explorer
0.47EPSS
CVE-2005-0688
Media 5.0

Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the SYN flag set and the same destination and source address and port, aka a reoccurrence of the "Lan…

microsoft windows_2003_server · microsoft windows_xp
0.47EPSS
CVE-2021-34481
Alta 8.8

A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could the…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.47EPSS
CVE-2020-16875
Alta 8.4

<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitatio…

microsoft exchange_server
0.47EPSS
CVE-2005-2118
Media 5.1

Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote user-assisted attackers to execute arbitrary commands via a crafted shortcut (.lnk) file with long font properties that lead to a buffer overflow when the user views th…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.47EPSS
CVE-2005-1208
Alta 10.0

Integer overflow in Microsoft Windows 98, 2000, XP SP2 and earlier, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via a crafted compiled Help (.CHM) file with a large size field that triggers a heap-based buffer overflow, as…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_xp
0.47EPSS
CVE-2012-4157
Alta 10.0

Adobe Reader and Acrobat 9.x before 9.5.2 and 10.x before 10.1.4 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2051, CVE-2012-…

adobe acrobat · adobe acrobat_reader
0.47EPSS
CVE-2017-11812
Alta 7.5

ChakraCore and Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Me…

microsoft chakracore · microsoft edge
0.47EPSS