imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2003-0807
Media 5.0

Buffer overflow in the COM Internet Services and in the RPC over HTTP Proxy components for Microsoft Windows NT Server 4.0, NT 4.0 Terminal Server Edition, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service via a crafted request.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.40EPSS
CVE-2015-0252
Media 5.0

internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.

apache xerces-c\+\+ · debian debian_linux · fedoraproject fedora
0.40EPSS
CVE-2007-5461
Bassa 3.5

Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that sp…

apache tomcat
0.40EPSS
CVE-2007-3028
Media 5.0

The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4 does not properly check "the number of convertible attributes", which allows remote attackers to cause a denial of service (service unavailability) via a crafted LDAP request, re…

microsoft windows_2000
0.40EPSS
CVE-2016-8610
Alta 7.5

A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consum…

debian debian_linux · fujitsu m10-1_firmware · fujitsu m10-4_firmware · fujitsu m10-4s_firmware · e altri 41
0.40EPSS
CVE-2016-1104
Alta 7.5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in…

adobe flash_player · microsoft edge · microsoft internet_explorer
0.40EPSS
CVE-2016-1102
Alta 7.5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in…

adobe flash_player · microsoft edge · microsoft internet_explorer
0.40EPSS
CVE-2016-1096
Alta 7.5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in…

adobe flash_player · microsoft edge · microsoft internet_explorer
0.40EPSS
CVE-2016-6816
Alta 7.1

The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted …

apache tomcat
0.40EPSS
CVE-2004-0119
Alta 7.5

The Negotiate Security Software Provider (SSP) interface in Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service (crash from null dereference) or execute arbitrary code via a crafted SPNEGO NegTokenInit reques…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_xp
0.40EPSS
CVE-2017-0009
Media 4.3

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-201…

microsoft internet_explorer
0.40EPSS
CVE-2000-0834
Alta 7.5

The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM…

microsoft windows_2000
0.40EPSS
CVE-2006-0030
Media 5.1

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed graphic, which leads to memory corruption.

microsoft excel · microsoft office
0.40EPSS
CVE-2014-1806
Alta 10.0

The .NET Remoting implementation in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly restrict memory access, which allows remote attackers to execute arbitrary code via vectors involving malformed objects, aka "TypeFil…

microsoft .net_framework
0.40EPSS
CVE-2018-8284
Alta 8.1

A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET F…

microsoft .net_framework · microsoft project_server · microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · e altri 1
0.40EPSS
CVE-2019-12986
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 2 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.40EPSS
CVE-2019-12985
Critica 9.8

Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 1 of 6).

citrix netscaler_sd-wan · citrix sd-wan
0.40EPSS
CVE-2023-38146
Alta 8.8

Windows Themes Remote Code Execution Vulnerability

microsoft windows_11_21h2 · microsoft windows_11_22h2
0.39EPSS
CVE-2008-1444
Alta 9.3

Stack-based buffer overflow in Microsoft DirectX 7.0 and 8.1 on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a Synchronized Accessible Media Interchange (SAMI) file with crafted parameters for a Class Name variable, aka the "SAMI Form…

microsoft directx
0.39EPSS
CVE-2019-1936
Alta 7.2

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the…

cisco integrated_management_controller_supervisor · cisco ucs_director · cisco ucs_director_express_for_big_data
0.39EPSS
CVE-2009-1130
Alta 9.3

Heap-based buffer overflow in Microsoft Office PowerPoint 2002 SP3 and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a crafted structure in a Notes container in a PowerPoint file that causes Po…

microsoft office · microsoft office_powerpoint
0.39EPSS
CVE-2009-1138
Alta 10.0

The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows remote attackers to execute arbitrary code via a request that uses hexadecimal encoding, whose associated memory is not r…

microsoft windows_2000
0.39EPSS
CVE-2021-39275
Critica 9.8

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

apache http_server · debian debian_linux · fedoraproject fedora · netapp cloud_backup · e altri 7
0.39EPSS
CVE-2021-42727
Alta 7.8

Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a v…

adobe robohelp_server
0.39EPSS
CVE-2006-4110
Media 4.3

Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-i…

apache http_server
0.39EPSS