imPC@ndo EN

CVE Tracker

56.420 CVE

CVE-2015-5557
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.45EPSS
CVE-2015-5556
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.45EPSS
CVE-2015-5551
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.45EPSS
CVE-2015-5550
Alta 10.0

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.45EPSS
CVE-2019-7089
Alta 7.5

Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a data leakage (sensitive) vulnerability. Successful exploitation could lead to information disclo…

adobe acrobat_dc · adobe acrobat_reader_dc
0.45EPSS
CVE-2000-0868
Media 5.0

The default configuration of Apache 1.3.12 in SuSE Linux 6.4 allows remote attackers to read source code for CGI scripts by replacing the /cgi-bin/ in the requested URL with /cgi-bin-sdb/.

apache http_server · suse suse_linux
0.45EPSS
CVE-2023-34051
Critica 9.8

VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

vmware aria_operations_for_logs
0.45EPSS
CVE-2003-0469
Alta 7.5

Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via cut-and-paste operation, as demonstrated in Internet Explorer 5.0 using…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · e altri 3
0.45EPSS
CVE-2011-0661
Alta 10.0

The SMB Server service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate fields in SMB requests, which allows remote att…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · e altri 2
0.45EPSS
CVE-2007-0039
Alta 7.8

The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CD…

microsoft exchange_server
0.45EPSS
CVE-2005-1987
Alta 7.5

Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using …

microsoft exchange_server · microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.44EPSS
CVE-2016-3301
Alta 7.8

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for …

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · e altri 8
0.44EPSS
CVE-2008-3479
Alta 10.0

Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters…

microsoft windows_2000
0.44EPSS
CVE-2007-3101
Media 4.3

Multiple cross-site scripting (XSS) vulnerabilities in certain JSF applications in Apache MyFaces Tomahawk before 1.1.6 allow remote attackers to inject arbitrary web script via the autoscroll parameter, which is injected into Javascript that is sent to the cl…

apache myfaces_tomahawk
0.44EPSS
CVE-2015-5562
Alta 10.0

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code by leveraging an u…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.44EPSS
CVE-2007-3111
Alta 10.0

Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.

microsoft internet_explorer · provideo camimage_activex_control
0.44EPSS
CVE-2024-50379
Critica 9.8

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat…

apache tomcat · netapp bootstrap_os
0.44EPSS
CVE-2018-3924
Alta 8.8

An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.5096. A specially crafted PDF document can trigger a previously freed object in memory to be reused, resulting in arbitrary code execut…

foxitsoftware foxit_reader · foxitsoftware phantompdf
0.44EPSS
CVE-2000-0951
Media 5.0

A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

microsoft internet_information_services
0.44EPSS
CVE-2023-33133
Alta 7.8

Microsoft Excel Remote Code Execution Vulnerability

microsoft 365_apps · microsoft excel · microsoft office_long_term_servicing_channel · microsoft office_online_server
0.44EPSS
CVE-2007-0024
Alta 9.3

Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page t…

microsoft ie · microsoft internet_explorer
0.44EPSS
CVE-2018-1306
Alta 7.5

The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to restrict path information provided during a file upload. An attacker could…

apache pluto
0.44EPSS
CVE-2021-24093
Alta 8.8

Windows Graphics Component Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.44EPSS
CVE-2014-0231
Media 5.0

The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a denial of service (process hang) via a request to a CGI script that does not read from its stdin file descriptor.

apache http_server
0.44EPSS
CVE-2005-2122
Alta 10.0

Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsyste…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.44EPSS