58.414 CVE seguite
792 Sfruttate ora
188 Usate dai ransomware
Ultima sincronia
CVE Tracker
58.414 CVE
Dieci fornitori seguiti per identificativo CPE, non per parola chiave: una CVE compare qui quando NVD dichiara quali prodotti tocca, di solito qualche giorno dopo la pubblicazione.
| Identificativo | Gravità, ordina dal più alto | Prodotto e difetto | EPSS, ordinato dal più basso | In KEV dal, ordina dal più alto |
|---|---|---|---|---|
| CVE-2023-26394 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic | 0,4% | — |
| CVE-2023-26390 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 0,4% | — |
| CVE-2023-26383 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 0,4% | — |
| CVE-2023-25872 | HIGH 7.8 | adobe substance_3d_stager Adobe Substance 3D Stager versions 2.0.0 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v | 0,4% | — |
| CVE-2023-21587 | HIGH 7.8 | adobe indesign Adobe InDesign version 18.0 (and earlier), 17.4 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in t | 0,4% | — |
| CVE-2023-20275 | MED 4.1 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. Thi | 0,4% | — |
| CVE-2022-37173 | HIGH 7.8 | vim gvim An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe. | 0,4% | — |
| CVE-2022-24540 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0,4% | — |
| CVE-2021-42108 | HIGH 7.8 | trendmicro apex_one Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first | 0,4% | — |
| CVE-2020-16120 | MED 5.1 | canonical ubuntu_linux Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unpr | 0,4% | — |
| CVE-2019-17351 | MED 6.5 | linux linux_kernel An issue was discovered in drivers/xen/balloon.c in the Linux kernel before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause a denial of service because of unrestricted resource consumption during the mapping of guest memory, aka CID-6ef3 | 0,4% | — |
| CVE-2019-15927 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 4.20.2. An out-of-bounds access exists in the function build_audio_procunit in the file sound/usb/mixer.c. | 0,4% | — |
| CVE-2018-5518 | MED 5.4 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.0.0-13.1.0.5 or 12.0.0-12.1.3.3, malicious root users with access to a VCMP guest can cause a disruption of service on adjacent VCMP guests running on the same host. Exploiting this vulnerability causes the vCMPd process on the adjacent VCMP gu | 0,4% | — |
| CVE-2017-16647 | MED 6.6 | linux linux_kernel drivers/net/usb/asix_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted USB device. | 0,4% | — |
| CVE-2017-16538 | MED 6.6 | linux linux_kernel drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device, related to a missing warm | 0,4% | — |
| CVE-2017-11473 | HIGH 7.8 | canonical ubuntu_linux Buffer overflow in the mp_override_legacy_irq() function in arch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local users to gain privileges via a crafted ACPI table. | 0,4% | — |
| CVE-2015-7613 | MED 6.9 | linux linux_kernel Race condition in the IPC object implementation in the Linux kernel through 4.2.3 allows local users to gain privileges by triggering an ipc_addid call that leads to uid and gid comparisons against uninitialized data, related to msg.c, shm.c, and util.c. | 0,4% | — |
| CVE-2015-7550 | MED 5.5 | linux linux_kernel The keyctl_read_key function in security/keys/keyctl.c in the Linux kernel before 4.3.4 does not properly use a semaphore, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impa | 0,4% | — |
| CVE-2012-6704 | HIGH 7.8 | linux linux_kernel The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other | 0,4% | — |
| CVE-2011-4916 | MED 5.5 | linux linux_kernel Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /dev/pts/ and /dev/tty*. | 0,4% | — |
| CVE-2009-0747 | MED 4.9 | linux linux_kernel The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU con | 0,4% | — |
| CVE-2006-1855 | LOW 2.1 | linux linux_kernel choose_new_parent in Linux kernel before 2.6.11.12 includes certain debugging code, which allows local users to cause a denial of service (panic) by causing certain circumstances involving termination of a parent process. | 0,4% | — |
| CVE-2006-0456 | LOW 2.1 | linux linux_kernel The strnlen_user function in Linux kernel before 2.6.16 on IBM S/390 can return an incorrect value, which allows local users to cause a denial of service via unknown vectors. | 0,4% | — |
| CVE-2006-0038 | MED 6.9 | linux linux_kernel Integer overflow in the do_replace function in netfilter for Linux before 2.6.16-rc3, when using "virtualization solutions" such as OpenVZ, allows local users with CAP_NET_ADMIN rights to cause a buffer overflow in the copy_from_user function. | 0,4% | — |
| CVE-2002-1574 | MED 4.6 | linux linux_kernel Buffer overflow in the ixj telephony card driver in Linux before 2.4.20 has unknown impact and attack vectors. | 0,4% | — |