imPC@ndo EN

CVE Tracker

56.515 CVE

CVE-2008-2258
Alta 9.3

Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific order…

microsoft internet_explorer
0.35EPSS
CVE-2002-0053
Alta 7.5

Buffer overflow in SNMP agent service in Windows 95/98/98SE, Windows NT 4.0, Windows 2000, and Windows XP allows remote attackers to cause a denial of service or execute arbitrary code via a malformed management request. NOTE: this candidate may be split or m…

microsoft windows_2000 · microsoft windows_95 · microsoft windows_98 · microsoft windows_98se · e altri 2
0.35EPSS
CVE-2000-0380
Alta 7.1

The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a denial of service by requesting a URL that contains a %% string.

cisco ios
0.35EPSS
CVE-2015-6152
Alta 9.3

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-6162.

microsoft internet_explorer
0.35EPSS
CVE-2021-42756
Critica 9.8

Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.2.6 and below, 6.3.16 and below, 6.4 all versions may allow an unauthenticated remote attacker to achieve arbit…

fortinet fortiweb
0.35EPSS
CVE-2010-2103
Media 4.3

Cross-site scripting (XSS) vulnerability in axis2-admin/axis2-admin/engagingglobally in the administration console in Apache Axis2/Java 1.4.1, 1.5.1, and possibly other versions, as used in SAP Business Objects 12, 3com IMC, and possibly other products, allows…

apache axis2
0.35EPSS
CVE-2013-0019
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer COmWindowProxy Use After Free Vulnerability."

microsoft internet_explorer
0.35EPSS
CVE-2007-3027
Alta 9.3

Race condition in Microsoft Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code by causing Internet Explorer to install multiple language packs in a way that triggers memory corruption, aka "Language Pack Installation Vulnerabili…

microsoft internet_explorer
0.35EPSS
CVE-2016-0971
Alta 8.8

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.…

adobe air_desktop_runtime · adobe air_sdk · adobe air_sdk_\&_compiler · adobe flash_player · e altri 1
0.35EPSS
CVE-2009-0230
Alta 9.0

The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote authenticated users to gain privileges via a crafted RPC message that triggers loading of a DLL file from an a…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server · microsoft windows_server_2008 · e altri 2
0.35EPSS
CVE-2007-2221
Alta 9.3

Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows …

microsoft internet_explorer
0.35EPSS
CVE-2006-0013
Media 6.5

Buffer overflow in the Web Client service (WebClnt.dll) for Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote authenticated users or Guests to execute arbitrary code via crafted RPC requests, a different vulnerability than CVE-2005-120…

microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2000-0025
Media 5.0

IIS 4.0 and Site Server 3.0 allow remote attackers to read source code for ASP files if the file is in a virtual directory whose name includes extensions such as .com, .exe, .sh, .cgi, or .dll, aka the "Virtual Directory Naming" vulnerability.

microsoft internet_information_server · microsoft site_server · microsoft site_server_commerce
0.35EPSS
CVE-2017-11282
Critica 9.8

Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.

adobe flash_player · redhat enterprise_linux_desktop · redhat enterprise_linux_server · redhat enterprise_linux_workstation
0.35EPSS
CVE-2008-0118
Alta 9.3

Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted Office document that triggers memory corruption from an…

microsoft office
0.35EPSS
CVE-2009-0226
Alta 9.3

Stack-based buffer overflow in the PowerPoint 4.2 conversion filter in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a long string in sound data in a file that uses a PowerPoint 4.0 native fi…

microsoft office_powerpoint
0.35EPSS
CVE-2006-2378
Media 6.8

Buffer overflow in the ART Image Rendering component (jgdw400.dll) in Microsoft Windows XP SP1 and Sp2, Server 2003 SP1 and earlier, and Windows 98 and Me allows remote attackers to execute arbitrary code via a crafted ART image that causes heap corruption.

microsoft ie · microsoft internet_explorer · microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2016-9150
Critica 9.8

Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspeci…

paloaltonetworks pan-os
0.35EPSS
CVE-2014-1770
Alta 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript code that interacts improperly with a CollectGarbage function call on a CMarkup object allocated by the CMarkup::C…

microsoft internet_explorer
0.35EPSS
CVE-2016-1000031
Critica 9.8

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

apache commons_fileupload
0.35EPSS
CVE-2018-12848
Critica 9.8

Adobe Acrobat and Reader versions 2018.011.20058 and earlier, 2017.011.30099 and earlier, and 2015.006.30448 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

adobe acrobat_dc · adobe acrobat_reader_dc
0.35EPSS
CVE-2002-0055
Media 5.0

SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.

microsoft exchange_server · microsoft windows_2000 · microsoft windows_xp
0.35EPSS
CVE-2019-16451
Critica 9.8

Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a heap overflow vulnerability. Successful exploitation could lead to…

adobe acrobat_dc · adobe acrobat_reader_dc
0.35EPSS
CVE-2006-4689
Media 5.0

Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWa…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.35EPSS
CVE-2001-1186
Media 5.0

Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value that is larger than the size of the request, which prevents IIS from timing out the connection.

microsoft internet_information_services
0.35EPSS