56.712 CVE seguite
777 Sfruttate ora
183 Usate dai ransomware
Ultima sincronia
CVE Tracker
56.712 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2011-4404 | MED 5.0 | vmware vcenter_update_manager The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attackers to conduct directory traversal attacks and read arbitrary files via unspecified | 59,7% | — |
| CVE-2018-8033 | HIGH 7.5 | apache ofbiz In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain | 59,6% | — |
| CVE-2017-11870 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vul | 59,6% | — |
| CVE-2017-11841 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka " | 59,6% | — |
| CVE-2017-11840 | HIGH 7.5 | microsoft chakracore ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka " | 59,6% | — |
| CVE-2011-4317 | MED 4.3 | apache http_server The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for | 59,6% | — |
| CVE-2019-9511 | HIGH 7.5 | apache traffic_server Some HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of service. The attacker requests a large amount of data from a specified resource over multiple streams. They manipu | 59,5% | — |
| CVE-2020-1300 | HIGH 8.8 | microsoft windows_10 A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and tr | 59,5% | — |
| CVE-2006-0988 | HIGH 7.8 | microsoft windows_2000 The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Server service on Windows NT 4.0, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows | 59,5% | — |
| CVE-2013-3138 | HIGH 7.1 | microsoft windows_7 Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted T | 59,4% | — |
| CVE-2016-1285 | MED 6.8 | canonical ubuntu_linux named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to | 59,1% | — |
| CVE-2021-33742 | HIGH 7.5 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 59,1% | |
| CVE-2008-4037 | HIGH 9.3 | microsoft windows Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote SMB servers to execute arbitrary code on a client machine by replaying the NTLM credentials of a client user, as demonstrat | 59,1% | — |
| CVE-2008-2463 | MED 6.8 | microsoft office_snapshot_viewer_activex The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a craf | 59,1% | — |
| CVE-2019-0190 | HIGH 7.5 | apache http_server A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4. | 59,1% | — |
| CVE-2021-24086 | HIGH 7.5 | microsoft windows_10 Windows TCP/IP Denial of Service Vulnerability | 59,0% | — |
| CVE-2007-3386 | MED 4.3 | apache tomcat Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an h | 59,0% | — |
| CVE-2023-31102 | HIGH 7.8 | 7-zip 7-zip Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive. | 58,9% | — |
| CVE-2025-24054 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. | 58,9% | |
| CVE-2003-0605 | HIGH 7.5 | microsoft windows_2000 The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and local attackers to use the DoS to hijack the epmapper pipe to gain privileges, via certain messages to the __RemoteGetClassObject interface tha | 58,8% | — |
| CVE-2006-1364 | HIGH 7.5 | microsoft asp.net Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM components in ASP.NET, which allows remote attackers to cause a denial of service (resource consumption or crash) by repeatedly requesting each | 58,7% | — |
| CVE-2002-0654 | MED 5.0 | apache http_server Apache 2.0 through 2.0.39 on Windows, OS2, and Netware allows remote attackers to determine the full pathname of the server via (1) a request for a .var file, which leaks the pathname in the resulting error message, or (2) via an error message that occurs when | 58,7% | — |
| CVE-2004-1305 | MED 5.0 | microsoft windows_2000 The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to b | 58,6% | — |
| CVE-2018-0780 | MED 5.3 | microsoft chakracore Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Info | 58,6% | — |
| CVE-2009-0557 | HIGH 7.8 | microsoft office Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel View | 58,6% |