imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2006-2389
Alta 9.3

Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to…

microsoft office
0.39EPSS
CVE-2008-1442
Alta 9.3

Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory C…

microsoft internet_explorer
0.39EPSS
CVE-2008-0114
Alta 9.3

Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.

microsoft excel · microsoft excel_viewer · microsoft office
0.39EPSS
CVE-2014-0253
Media 5.0

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resou…

microsoft .net_framework
0.39EPSS
CVE-2020-3240
Alta 7.3

Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulne…

cisco ucs_director · cisco ucs_director_express_for_big_data
0.39EPSS
CVE-2006-0005
Alta 9.3

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EM…

microsoft windows-nt · microsoft windows_2000 · microsoft windows_2000_advanced_server · microsoft windows_2003_server · e altri 3
0.39EPSS
CVE-2021-28476
Critica 9.9

Windows Hyper-V Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server_2008 · e altri 3
0.39EPSS
CVE-2005-0048
Alta 7.5

Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vuln…

microsoft windows_2000 · microsoft windows_xp
0.39EPSS
CVE-2011-1255
Alta 9.3

The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not pr…

microsoft internet_explorer
0.39EPSS
CVE-2013-3195
Alta 10.0

The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does no…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · e altri 4
0.38EPSS
CVE-2004-0566
Alta 7.5

Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.

microsoft internet_explorer
0.38EPSS
CVE-2011-1871
Alta 7.8

Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service V…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.38EPSS
CVE-2014-0271
Alta 9.3

The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerabil…

microsoft internet_explorer · microsoft vbscript
0.38EPSS
CVE-2018-4162
Alta 8.8

An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected.…

apple icloud · apple iphone_os · apple itunes · apple safari · e altri 4
0.38EPSS
CVE-2000-0305
Alta 7.8

Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.

be beos · microsoft terminal_server · microsoft windows_2000 · microsoft windows_95 · e altri 2
0.38EPSS
CVE-2022-37985
Media 5.5

Windows Graphics Component Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.38EPSS
CVE-2004-0978
Alta 10.0

Heap-based buffer overflow in the Hrtbeat.ocx (Heartbeat) ActiveX control for Internet Explorer 5.01 through 6, when users who visit online gaming sites that are associated with MSN, allows remote attackers to execute arbitrary code via the SetupData parameter…

microsoft internet_explorer
0.38EPSS
CVE-2021-34850
Alta 7.8

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.…

foxit pdf_reader · foxitsoftware pdf_editor
0.38EPSS
CVE-2012-0163
Alta 9.3

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly validate function parameters, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET appl…

microsoft .net_framework
0.38EPSS
CVE-2002-0419
Media 5.0

Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily conduct brute force attacks via responses from the server in which (2) in certain configurations, the server IP address is provided as the …

microsoft internet_information_server · microsoft internet_information_services
0.38EPSS
CVE-2013-0090
Alta 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."

microsoft internet_explorer
0.38EPSS
CVE-2015-5254
Critica 9.8

Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

apache activemq · fedoraproject fedora · redhat openshift
0.38EPSS
CVE-2018-8474
Alta 7.5

A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messages, aka "Lync for Mac 2011 Security Feature Bypass Vulnerability." This affects Microsoft Lync.

microsoft lync_for_mac
0.38EPSS
CVE-2025-53778
Alta 8.8

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · e altri 11
0.38EPSS
CVE-2015-5549
Alta 10.0

Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allow attackers to execute arbitrary code or cause a denial …

adobe air · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player
0.38EPSS