imPC@ndo EN

CVE Tracker

56.453 CVE

CVE-2017-0061
Media 5.3

The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted we…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2011-2001
Alta 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function T…

microsoft internet_explorer
0.43EPSS
CVE-2013-3894
Alta 8.1

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a cr…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · e altri 4
0.43EPSS
CVE-2006-3869
Alta 7.5

Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on…

microsoft ie
0.43EPSS
CVE-2008-4841
Alta 9.3

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exp…

microsoft wordpad
0.43EPSS
CVE-2020-4000
Alta 8.8

The SD-WAN Orchestrator 3.3.2 prior to 3.3.2 P3, 3.4.x prior to 3.4.4, and 4.0.x prior to 4.0.1 allows for executing files through directory traversal. An authenticated SD-WAN Orchestrator user is able to traversal directories which may lead to code execution …

vmware sd-wan_orchestrator
0.43EPSS
CVE-2007-0612
Alta 7.8

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1…

microsoft ie · microsoft internet_explorer
0.43EPSS
CVE-2004-0897
Alta 10.0

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

microsoft windows_2003_server · microsoft windows_xp
0.43EPSS
CVE-2006-3449
Alta 7.5

Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2…

microsoft powerpoint
0.43EPSS
CVE-2016-2171
Alta 7.5

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.

apache jetspeed
0.43EPSS
CVE-2018-0114
Alta 7.5

A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens using a key that is embedded within the token. The vulnerability is due to node-jose following the JSON Web Signature (JW…

cisco node-jose
0.43EPSS
CVE-2022-33980
Critica 9.8

Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configurat…

apache commons_configuration · debian debian_linux · netapp snapcenter
0.43EPSS
CVE-2018-8464
Alta 7.5

An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.

microsoft edge
0.43EPSS
CVE-1999-0891
Media 5.0

The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.

microsoft internet_explorer
0.43EPSS
CVE-2011-0978
Alta 9.3

Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via ve…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.43EPSS
CVE-2019-12988
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.43EPSS
CVE-2019-12987
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 3 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.43EPSS
CVE-2017-0090
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0087
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0086
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0083
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0072
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2015-3082
Media 6.4

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allow remote attacke…

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.43EPSS
CVE-2016-7274
Alta 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary cod…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · e altri 4
0.42EPSS
CVE-2011-1975
Alta 9.3

Untrusted search path vulnerability in the Data Access Tracing component in Windows Data Access Components (Windows DAC) 6.0 in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 allows local users to gain privileges via a Trojan horse DLL …

microsoft windows_7 · microsoft windows_server_2008
0.42EPSS