Search

Found 167 results in 165ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2019-11043 critical 10.0 KEVEXPFIX arch arch sles rocky 4y ago In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
CVE-2022-0492 high 7.8 10.0 KEVEXPFIX sles rockydebian debian redhatnetapp 4y ago Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature.
CVE-2022-26486 high 9.5 KEVFIX debian debian sles rocky 4y ago Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
CVE-2022-26485 high 9.5 KEVFIX slesdebian debian rocky 4y ago Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
CVE-2019-16928 critical 10.0 KEVFIX arch archdebian debian 4y ago Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.
CVE-2016-5195 high 10.0 KEVEXPFIX slesarch archdebian debian 4y ago Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
CVE-2022-22620 medium 7.0 KEVFIX arch arch sles rocky 4y ago Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers t…
CVE-2019-10149 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2021-4102 critical 10.0 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-44228 critical 10.0 KEVEXPFIX arch archdebian debian sles 5y ago Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution.
CVE-2019-13272 high 10.0 KEVEXPFIX slesdebian debian rhel 5y ago Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.
CVE-2021-40438 high 9.5 KEVFIX debian debianarch arch sles 5y ago A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-22204 medium 8.0 KEVEXPFIX arch archdebian debian 5y ago Improper neutralization of user data in the DjVu file format in Exiftool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
CVE-2021-42013 critical 10.0 KEVEXPFIX arch archdebian debian 5y ago It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Al…
CVE-2021-41773 high 10.0 KEVEXPFIX debian debianarch arch sles 5y ago A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-li…
CVE-2021-38003 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine has a bug in JSON.stringify, where the internal TheHole value can leak to script code, causing memory corruption. This vulnerability could affect multiple web browsers that …
CVE-2021-38000 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium Intents contains an improper input validation vulnerability that allows a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page. This vulnerability could a…
CVE-2021-37976 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a c…
CVE-2021-37975 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-37973 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML pag…
CVE-2021-30858 medium 7.0 KEVFIX arch arch sles rocky 5y ago Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers t…
CVE-2021-30762 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS WebKit contains a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, in…
CVE-2021-30761 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS WebKit contains a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit,…
CVE-2021-30666 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS WebKit contains a buffer-overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, i…
CVE-2021-30665 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS, iPadOS, macOS, watchOS, and tvOS WebKit contain a memory corruption vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could imp…
CVE-2021-30663 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain an integer overflow vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impa…
CVE-2021-30661 medium 7.0 KEVFIX arch arch rockydebian debian 5y ago Apple iOS, iPadOS, macOS, tvOS, watchOS, and Safari WebKit Storage contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerabil…
CVE-2021-30633 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted H…
CVE-2021-30632 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains an out-of-bounds write vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2021-30563 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-30554 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium WebGL contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple we…
CVE-2021-30551 critical 10.0 KEVFIX arch archdebian debian sles 5y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2021-22205 critical 10.0 KEVEXPFIX arch arch 5y ago GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through Exi…
CVE-2021-21224 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to execute code inside a sandbox via a crafted HTML page. This vulnerability could affect multiple web …
CVE-2021-21220 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains an improper input validation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could af…
CVE-2021-21206 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple we…
CVE-2021-21193 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium Blink contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple we…
CVE-2021-21166 high 9.5 KEVFIX arch archdebian debian 5y ago Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web brow…
CVE-2021-21148 critical 10.0 KEVFIX arch archdebian debian sles 5y ago Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect m…
CVE-2021-1871 medium 7.0 KEVFIX arch arch sles rocky 5y ago Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including b…
CVE-2021-1870 medium 7.0 KEVFIX arch arch sles rocky 5y ago Apple iOS, iPadOS, and macOS WebKit contain an unspecified logic vulnerability that allows a remote attacker to execute code. This vulnerability could impact HTML parsers that use WebKit, including b…
CVE-2020-6820 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unsp…
CVE-2020-6819 critical 10.0 KEVFIX arch arch slesdebian debian 5y ago Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, caus…
CVE-2020-6418 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web…
CVE-2020-1472 medium 8.0 KEVEXPFIX arch arch sles rocky 5y ago Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An at…
CVE-2019-17026 critical 10.0 KEVEXPFIX arch archdebian debian rhel 5y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements.
CVE-2019-0211 high 10.0 KEVEXPFIX debian debianarch arch sles 5y ago In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scrip…
CVE-2018-6789 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Exim contains a buffer overflow vulnerability in the base64d function part of the SMTP listener that may allow for remote code execution.
CVE-2017-16651 high 10.0 KEVEXPFIX arch archdebian debian 5y ago Roundcube Webmail contains a file disclosure vulnerability caused by insufficient input validation in conjunction with file-based attachment plugins, which are used by default.
CVE-2021-39226 high 9.5 KEVFIX arch arch sles rocky 5y ago Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
CVE-2020-36193 medium 7.0 KEVFIX arch arch sles rocky 5y ago PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-sour…
CVE-2020-16009 critical 10.0 KEVFIX arch archdebian debian 6y ago Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multipl…
CVE-2020-16017 high 9.5 KEVFIX arch archdebian debian 6y ago Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page.
CVE-2020-16013 high 9.5 KEVFIX arch archdebian debian 6y ago Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could…
CVE-2020-28949 medium 8.0 KEVEXPFIX rockydebian debian rhel 6y ago PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and di…
CVE-2020-15999 critical 10.0 KEVFIX arch arch slesdebian debian 6y ago Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded int…
CVE-2019-5786 high 10.0 KEVEXPFIX arch archdebian debian 6y ago Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2020-1938 medium 8.0 KEVEXPFIX sles rockydebian debian 6y ago Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploit…
CVE-2020-11023 medium 8.0 KEVEXPFIX rhel rocky sles 6y ago JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in …
CVE-2016-10033 high 10.0 KEVEXPFIX arch archdebian debian 6y ago PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attac…
CVE-2018-7602 critical 10.0 KEVEXPFIX arch arch 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site.
CVE-2018-7600 critical 10.0 KEVEXPFIX arch arch 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise.
CVE-2010-0806 high 8.8 10.0 KEVEXP windows windows microsoft 17y ago Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion …
CVE-2010-0249 high 8.8 10.0 KEVEXP windows windows microsoft 17y ago Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted …
CVE-2009-3459 high 8.8 10.0 KEVEXP adobe 17y ago Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption.
CVE-2009-1537 high 8.8 10.0 KEV windows windows microsoft 17y ago Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a craf…
CVE-2008-4250 critical 9.8 10.0 KEVEXP windows windows 18y ago Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow dur…