57.136 CVE seguite
777 Sfruttate ora
184 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.136 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2002-0644 | HIGH 7.5 | microsoft data_engine Buffer overflow in several Database Consistency Checkers (DBCCs) for Microsoft SQL Server 2000 and Microsoft Desktop Engine (MSDE) 2000 allows members of the db_owner and db_ddladmin roles to execute arbitrary code. | 11,4% | — |
| CVE-2004-0726 | HIGH 7.5 | microsoft windows_2000 The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel. | 11,4% | — |
| CVE-2010-3269 | HIGH 9.3 | cisco webex_advanced_recording_format_player Multiple stack-based buffer overflows in the Cisco WebEx Recording Format (WRF) and Advanced Recording Format (ARF) Players T27LB before SP21 EP3 and T27LC before SP22 allow remote attackers to execute arbitrary code via a crafted (1) .wrf or (2) .arf file, re | 11,4% | — |
| CVE-2011-1894 | MED 4.3 | microsoft windows_2003_server The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly handle a MIME format in a request for embedded conte | 11,4% | — |
| CVE-2022-24104 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th | 11,4% | — |
| CVE-2013-6408 | MED 6.4 | apache solr The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity refer | 11,4% | — |
| CVE-2013-6407 | MED 6.4 | apache solr The UpdateRequestHandler for XML in Apache Solr before 4.1 allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | 11,4% | — |
| CVE-2000-0506 | HIGH 10.0 | linux linux_kernel The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by setting the capabilities to prevent a setuid program from dropping privileges, aka the "Linux kernel setuid/setcap vulnerability." | 11,4% | — |
| CVE-2016-0036 | HIGH 8.1 | microsoft windows_10 The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote authenticated users to execute arbitrary code via crafted data, aka "Remote Desktop Protocol (RDP) Elevation | 11,4% | — |
| CVE-2002-0242 | HIGH 7.5 | microsoft internet_explorer Cross-site scripting vulnerability in Internet Explorer 6 earlier allows remote attackers to execute arbitrary script via an Extended HTML Form, whose output from the remote server is not properly cleansed. | 11,4% | — |
| CVE-2014-6318 | MED 4.3 | microsoft windows_7 The audit logon feature in Remote Desktop Protocol (RDP) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly log unauthorized | 11,4% | — |
| CVE-2016-2210 | HIGH 7.3 | symantec advanced_threat_protection Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Sym | 11,4% | — |
| CVE-2024-26160 | MED 5.5 | microsoft windows_11_22h2 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 11,4% | — |
| CVE-2010-0987 | HIGH 8.8 | adobe shockwave_player Heap-based buffer overflow in Adobe Shockwave Player before 11.5.7.609 might allow remote attackers to execute arbitrary code via crafted embedded fonts in a Shockwave file. | 11,4% | — |
| CVE-2002-2100 | MED 5.0 | microsoft outlook Microsoft Outlook 2002 allows remote attackers to embed bypass the file download restrictions for attachments via an HTML email message that uses an IFRAME to reference malicious content. | 11,4% | — |
| CVE-2026-50656 | HIGH 7.8 | microsoft malware_protection_engine Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | 11,4% | — |
| CVE-2001-0723 | MED 6.4 | microsoft internet_explorer Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript, aka the "Second Cookie Handling Vulnerability." | 11,4% | — |
| CVE-2001-0643 | MED 5.0 | microsoft internet_explorer Internet Explorer 5.5 does not display the Class ID (CLSID) when it is at the end of the file name, which could allow attackers to trick the user into executing dangerous programs by making it appear that the document is of a safe file type. | 11,4% | — |
| CVE-2015-3081 | MED 4.3 | adobe air Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 al | 11,4% | — |
| CVE-2019-1102 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. | 11,3% | — |
| CVE-2021-26432 | CRIT 9.8 | microsoft windows_10 Windows Services for NFS ONCRPC XDR Driver Remote Code Execution Vulnerability | 11,3% | — |
| CVE-2014-3575 | MED 4.3 | apache openoffice The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects. | 11,3% | — |
| CVE-2023-46261 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46259 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |
| CVE-2023-46257 | CRIT 9.8 | ivanti avalanche An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | 11,3% | — |