imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2000-0854
Alta 10.0

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same director…

microsoft office
0.37EPSS
CVE-2017-12285
Media 5.3

A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected software do…

cisco prime_network_analysis_module
0.37EPSS
CVE-2008-0077
Alta 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, ak…

microsoft internet_explorer
0.37EPSS
CVE-2012-0393
Media 6.4

The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to create or overwrite arbitrary files via a crafted parameter that triggers the creation of a Java object.

apache struts
0.37EPSS
CVE-2006-1300
Media 5.0

Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."

microsoft .net_framework
0.37EPSS
CVE-2014-0118
Media 4.3

The deflate_in_filter function in mod_deflate.c in the mod_deflate module in the Apache HTTP Server before 2.4.10, when request body decompression is enabled, allows remote attackers to cause a denial of service (resource consumption) via crafted request data …

apache http_server · debian debian_linux · redhat jboss_enterprise_application_platform
0.37EPSS
CVE-2013-3868
Media 5.0

Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 and Active Directory Services on Windows Server 2008 SP2 and R2 SP1 and Server 2012 allow remote attackers …

microsoft active_directory_lightweight_directory_service · microsoft windows_7 · microsoft windows_8 · microsoft windows_server_2008 · e altri 2
0.37EPSS
CVE-2009-0220
Alta 9.3

Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a …

microsoft office_powerpoint
0.37EPSS
CVE-2007-0034
Alta 9.3

Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsof…

microsoft office · microsoft outlook
0.37EPSS
CVE-2025-68493
Alta 8.1

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes the issue.

apache struts
0.37EPSS
CVE-2005-2117
Media 5.1

Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_explorer · microsoft windows_xp
0.37EPSS
CVE-2010-0255
Media 4.3

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploi…

microsoft internet_explorer
0.37EPSS
CVE-2002-0023
Media 5.0

Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.

microsoft internet_explorer
0.37EPSS
CVE-2017-0008
Media 4.3

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CV…

microsoft internet_explorer
0.37EPSS
CVE-2022-24500
Alta 8.8

Windows SMB Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · e altri 6
0.37EPSS
CVE-2006-6723
Alta 7.8

The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) via a large maxlen value in an NetrWkstaUserEnum RPC request.

microsoft windows_2000 · microsoft windows_xp
0.37EPSS
CVE-2008-0102
Alta 10.0

Unspecified vulnerability in Microsoft Office Publisher 2000, 2002, and 2003 SP2 allows remote attackers to execute arbitrary code via a crafted .pub file, related to invalid "memory values," aka "Publisher Invalid Memory Reference Vulnerability."

microsoft publisher
0.37EPSS
CVE-2009-0561
Alta 9.3

Integer overflow in Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microso…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · e altri 2
0.37EPSS
CVE-2023-28231
Alta 8.8

DHCP Server Service Remote Code Execution Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · e altri 1
0.37EPSS
CVE-2025-21760
Alta 8.1

In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_rcu() and avoid a poten…

linux linux_kernel
0.37EPSS
CVE-2005-0055
Alta 7.5

Internet Explorer 5.01, 5.5, and 6 does not properly validate buffers when handling certain DHTML methods including the createControlRange Javascript function, which allows remote attackers to execute arbitrary code, aka the "DHTML Method Heap Memory Corruptio…

microsoft ie · microsoft internet_explorer
0.37EPSS
CVE-2008-1436
Alta 9.0

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalService accounts, which might allow context-dependent attackers to gain privileges by using one service process to…

microsoft windows-nt · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · e altri 1
0.37EPSS
CVE-2015-3042
Alta 10.0

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different v…

adobe flash_player · opensuse opensuse · redhat enterprise_linux_desktop_supplementary · redhat enterprise_linux_server_supplementary · e altri 4
0.37EPSS
CVE-2018-4985
Alta 7.5

Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

adobe acrobat_dc · adobe acrobat_reader_dc
0.37EPSS
CVE-2006-3638
Alta 7.5

Microsoft Internet Explorer 5.01 and 6 does not properly handle uninitialized COM objects, which allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code, as demonstrated by the Nth function in the DirectAnim…

microsoft ie · microsoft internet_explorer
0.37EPSS