57.971 CVE seguite
784 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
57.971 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più alto | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2019-19048 | HIGH 7.5 | canonical ubuntu_linux A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c in the Linux kernel before 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864. | 3,8% | — |
| CVE-2017-3160 | HIGH 7.4 | apache cordova After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, the scripts will fetch Gradle on the first build. However, since the default URI is not using https, it is vulnerable to a MiTM and the Gradle | 3,8% | — |
| CVE-2012-0418 | HIGH 9.3 | novell groupwise Unspecified vulnerability in the client in Novell GroupWise 8.0 before Support Pack 3 and 2012 before Support Pack 1 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted file. | 3,8% | — |
| CVE-2017-6758 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote attacker to access arbitrary files in the context of the web root directory structure on an affected device. The vulnerability is | 3,8% | — |
| CVE-2003-1604 | HIGH 7.5 | linux linux_kernel The redirect_target function in net/ipv4/netfilter/ipt_REDIRECT.c in the Linux kernel before 2.6.0 allows remote attackers to cause a denial of service (NULL pointer dereference and OOPS) by sending packets to an interface that has a 0.0.0.0 IP address, a rela | 3,8% | — |
| CVE-2014-7284 | MED 6.4 | linux linux_kernel The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers | 3,8% | — |
| CVE-2018-8314 | MED 4.7 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows fails a check, allowing a sandbox escape, aka "Windows Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, | 3,7% | — |
| CVE-2019-1854 | MED 4.1 | cisco telepresence_video_communication_server A vulnerability in the management web interface of Cisco Expressway Series could allow an authenticated, remote attacker to perform a directory traversal attack against an affected device. The vulnerability is due to insufficient input validation on the web in | 3,7% | — |
| CVE-2017-3100 | MED 6.5 | adobe flash_player Adobe Flash Player versions 26.0.0.131 and earlier have an exploitable memory corruption vulnerability in the Action Script 2 BitmapData class. Successful exploitation could lead to memory address disclosure. | 3,7% | — |
| CVE-2014-3501 | MED 4.3 | apache cordova Apache Cordova Android before 3.5.1 allows remote attackers to bypass the HTTP whitelist and connect to arbitrary servers by using JavaScript to open WebSocket connections through WebView. | 3,7% | — |
| CVE-2013-5122 | CRIT 9.8 | cisco linksys_e4200_firmware Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access | 3,7% | — |
| CVE-2010-2959 | HIGH 7.2 | debian debian_linux Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.53, 2.6.32.x before 2.6.32.21, 2.6.34.x before 2.6.34.6, and 2.6.35.x before 2.6.35.4 allows attackers to execute arbitrary code or cause a | 3,7% | — |
| CVE-2016-1329 | CRIT 9.8 | samsung x14j_firmware Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, | 3,7% | — |
| CVE-2010-2739 | HIGH 7.2 | microsoft windows_2003_server Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP2, Vista Business SP1, Windows 7, and Server 2008 SP2 allows local users to cause a denial of service (crash) and possibly execute arbitrary | 3,7% | — |
| CVE-2007-6372 | HIGH 7.8 | juniper junos Unspecified vulnerability in Juniper JUNOS 7.3 through 8.4 allows remote attackers to cause a denial of service (crash) via malformed BGP packets, possibly BGP UPDATE packets that trigger session flapping. | 3,7% | — |
| CVE-2019-9197 | HIGH 8.8 | unity3d unity_editor The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code. | 3,7% | — |
| CVE-2010-0536 | HIGH 9.3 | apple quicktime Apple QuickTime before 7.6.6 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted BMP image. | 3,7% | — |
| CVE-2018-0222 | CRIT 10.0 | cisco digital_network_architecture_center A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to log in to an affected system by using an administrative account that has default, static user credentials. The vulnerability is due to the pre | 3,7% | — |
| CVE-2002-2438 | HIGH 7.5 | linux linux_kernel TCP firewalls could be circumvented by sending a SYN Packets with other flags (like e.g. RST flag) set, which was not correctly discarded by the Linux TCP stack after firewalling. | 3,7% | — |
| CVE-2001-1122 | LOW 2.1 | microsoft windows_nt Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsass.exe) by running the NT4ALL exploit program in 'SPECIAL' mode. | 3,7% | — |
| CVE-2021-30617 | MED 6.5 | fedoraproject fedora Chromium: CVE-2021-30617 Policy bypass in Blink | 3,7% | — |
| CVE-2020-1012 | HIGH 8.8 | microsoft internet_explorer <p>An elevation of privilege vulnerability exists in the way that the Wininit.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>There are multiple ways an attacker could | 3,7% | — |
| CVE-2022-21986 | HIGH 7.5 | fedoraproject fedora .NET Denial of Service Vulnerability | 3,7% | — |
| CVE-2010-3873 | MED 5.0 | debian debian_linux The X.25 implementation in the Linux kernel before 2.6.36.2 does not properly parse facilities, which allows remote attackers to cause a denial of service (heap memory corruption and panic) or possibly have unspecified other impact via malformed (1) X25_FAC_CA | 3,7% | — |
| CVE-2024-38059 | HIGH 7.8 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 3,7% | — |