Search

Found 1,516 results in 471ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2016-1010 unknown 1.5 KEV 4y ago Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
CVE-2016-0984 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
CVE-2016-0034 unknown 1.5 KEV 4y ago Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
CVE-2015-8651 unknown 1.5 KEV 4y ago Integer overflow in Adobe Flash Player allows attackers to execute code.
CVE-2015-6175 unknown 1.5 KEV 4y ago The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted application.
CVE-2015-4495 unknown 2.5 KEVEXPFIX debian debian 4y ago Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
CVE-2015-2425 unknown 1.5 KEV 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2015-2360 unknown 1.5 KEV 4y ago Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
CVE-2015-1769 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
CVE-2015-1671 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
CVE-2015-0310 unknown 1.5 KEV 4y ago Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.
CVE-2015-0071 unknown 1.5 KEV 4y ago Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
CVE-2015-0016 unknown 2.5 KEVEXP 4y ago Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2014-8439 unknown 1.5 KEV 4y ago Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
CVE-2014-4148 unknown 1.5 KEV 4y ago A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
CVE-2014-4123 unknown 1.5 KEV 4y ago Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
CVE-2014-4077 unknown 1.5 KEV 4y ago Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanes…
CVE-2014-3153 unknown 2.5 KEVEXPFIX debian debian 4y ago The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain privileges.
CVE-2014-2817 unknown 1.5 KEV 4y ago Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
CVE-2014-0546 unknown 1.5 KEV 4y ago Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
CVE-2013-7331 unknown 2.5 KEVEXP 4y ago An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an attacker to detect anti-malware applicat…
CVE-2013-3993 unknown 1.5 KEV 4y ago Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
CVE-2013-3896 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application.
CVE-2013-2423 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
CVE-2013-0431 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2013-0422 unknown 2.5 KEVEXP 4y ago A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
CVE-2013-0074 unknown 2.5 KEVEXP 4y ago Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
CVE-2012-1710 unknown 1.5 KEV 4y ago Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown ve…
CVE-2010-1428 unknown 2.5 KEVEXP 4y ago Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs…
CVE-2010-0840 unknown 2.5 KEVEXP 4y ago Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
CVE-2010-0738 unknown 2.5 KEVEXP 4y ago The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests t…
CVE-2020-16846 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt allows an unauthenticated user with network access to the Salt API to use shell injections to run code on the Salt API using the SSH client. This vulnerability affects any users runnin…
CVE-2020-1147 critical 10.0 KEVEXP rhel 4y ago Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploi…
CVE-2020-11651 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains an authentication bypass vulnerability in the salt-master process ClearFuncs due to improperly validating method calls. The vulnerability allows a remote user to access some m…
CVE-2020-11652 unknown 2.5 KEVEXP sles 4y ago SaltStack Salt contains a path traversal vulnerability in the salt-master process ClearFuncs which allows directory access to authenticated users. Salt users who follow fundamental internet security …
CVE-2020-7961 unknown 2.5 KEVEXP 4y ago Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.
CVE-2018-8611 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory.
CVE-2018-19953 unknown 1.5 KEV 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2018-19949 unknown 1.5 KEV 4y ago A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.
CVE-2018-19943 unknown 1.5 KEV 4y ago A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.
CVE-2017-8543 unknown 1.5 KEV 4y ago Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.
CVE-2017-18362 unknown 1.5 KEV 4y ago ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.
CVE-2017-0210 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.
CVE-2017-0149 unknown 1.5 KEV 4y ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.
CVE-2017-0147 unknown 2.5 KEVEXP 4y ago The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2017-0022 unknown 1.5 KEV 4y ago Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
CVE-2017-0005 unknown 1.5 KEV 4y ago The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2016-6367 unknown 2.5 KEVEXP 4y ago A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.
CVE-2016-6366 unknown 2.5 KEVEXP 4y ago A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute cod…
CVE-2016-4657 unknown 2.5 KEVEXP 4y ago Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTM…
CVE-2016-4656 unknown 2.5 KEVEXP 4y ago A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.
CVE-2016-4655 unknown 2.5 KEVEXP 4y ago The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2016-3351 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific f…
CVE-2016-3298 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow th…
CVE-2016-0162 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.
CVE-2022-20821 unknown 1.5 KEV 4y ago Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running …
CVE-2021-30883 unknown 1.5 KEV 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.
CVE-2021-1048 unknown 1.5 KEVFIX slesdebian debian 4y ago Android kernel contains a use-after-free vulnerability that allows for privilege escalation.
CVE-2020-1027 unknown 1.5 KEV 4y ago An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated …
CVE-2020-0638 unknown 1.5 KEV 4y ago Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-8720 medium 7.0 KEVFIX sles rockydebian debian 4y ago WebKitGTK contains a memory corruption vulnerability which can allow an attacker to perform remote code execution.
CVE-2019-7287 unknown 1.5 KEV 4y ago Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.
CVE-2019-7286 unknown 2.5 KEVEXP 4y ago Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.
CVE-2019-18426 unknown 2.5 KEVEXP 4y ago A vulnerability in WhatsApp Desktop when paired with WhatsApp for iPhone allows cross-site scripting and local file reading.
CVE-2019-1385 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
CVE-2019-13720 critical 10.0 KEVEXPFIX arch archdebian debian 4y ago Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2019-11707 critical 10.0 KEVEXPFIX arch arch slesdebian debian 4y ago Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.
CVE-2019-1130 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
CVE-2019-0880 unknown 1.5 KEV 4y ago A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system …
CVE-2019-0703 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.
CVE-2019-0676 unknown 1.5 KEV 4y ago An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of fi…
CVE-2018-8589 unknown 1.5 KEV 4y ago A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security contex…
CVE-2018-5002 unknown 1.5 KEV 4y ago Adobe Flash Player have a stack-based buffer overflow vulnerability that could lead to remote code execution.
CVE-2014-3120 unknown 2.5 KEVEXP 4y ago Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2022-30525 unknown 2.5 KEVEXP 4y ago A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVE-2015-1427 unknown 2.5 KEVEXP 4y ago The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2016-4437 unknown 2.5 KEVEXPFIX debian debian 4y ago Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parameter when a cipher key has not been confi…
CVE-2016-7201 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-7200 unknown 2.5 KEVEXP 4y ago The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2016-3088 unknown 2.5 KEVEXPFIX debian debian 4y ago The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request
CVE-2017-12617 unknown 2.5 KEVEXP sles 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv…
CVE-2018-15133 unknown 2.5 KEVEXPFIX debian debian 4y ago Laravel Framework contains a deserialization of untrusted data vulnerability, allowing for remote command execution. This vulnerability may only be exploited if a malicious user has accessed the appl…
CVE-2015-5317 unknown 1.5 KEV 4y ago Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of jobs and builds otherwise inaccessible to them on the "Fingerprints" pages.
CVE-2017-9791 unknown 2.5 KEVEXP 4y ago The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
CVE-2018-8298 unknown 2.5 KEVEXP 4y ago The ChakraCore scripting engine contains a type confusion vulnerability which can allow for remote code execution.
CVE-2018-14667 unknown 1.5 KEV 4y ago Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute…
CVE-2016-8735 unknown 1.5 KEVFIX slesdebian debian 4y ago Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java Management Extension (JMX) ports. This C…
CVE-2019-1003030 unknown 2.5 KEVEXP 4y ago Jenkins Matrix Project plugin contains a vulnerability which can allow users to escape the sandbox, opening opportunity to perform remote code execution.
CVE-2013-2251 unknown 2.5 KEVEXP 4y ago Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2017-1000353 unknown 2.5 KEVEXP 4y ago Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would…
CVE-2018-1000861 unknown 2.5 KEVEXP 4y ago A code execution vulnerability exists in the Stapler web framework used by Jenkins
CVE-2019-1003029 unknown 2.5 KEVEXP 4y ago Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.
CVE-2022-1388 unknown 2.5 KEVEXP 4y ago F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code execution, creation or deletion of files, or disabling services.
CVE-2012-0391 unknown 2.5 KEVEXP 4y ago The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution.
CVE-2021-1789 medium 7.0 KEVFIX arch arch sles rocky 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2019-8506 low 5.0 KEVEXPFIX rockydebian debian rhel 4y ago A type confusion issue affecting multiple Apple products allows processing of maliciously crafted web content, leading to arbitrary code execution.
CVE-2014-4113 unknown 2.5 KEVEXP 4y ago Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2014-0322 unknown 2.5 KEVEXP 4y ago Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
CVE-2014-0160 unknown 2.5 KEVEXPFIX debian debian 4y ago The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2006-1547 unknown 1.5 KEV 4y ago ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS).