91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,451–1,500 of 1,734 in KEV · page 30 of 35

IDTitleSummary
CVE-2017-1000486Primetek Primefaces Remote Code Execution Vulnerability
KEVPrimetek
Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
CVE-2017-1000353Jenkins Remote Code Execution Vulnerability
KEVJenkins
Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to th…
CVE-2017-1000253Linux Kernel PIE Stack Buffer Corruption Vulnerability
KEVLinux
Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escal…
CVE-2017-0263Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory.
CVE-2017-0262Microsoft Office Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in Microsoft Office.
CVE-2017-0261Microsoft Office Use-After-Free Vulnerability
KEVMicrosoft
Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
CVE-2017-0222Microsoft Internet Explorer Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
CVE-2017-0213Microsoft Windows Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
CVE-2017-0210Microsoft Internet Explorer Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access inf…
CVE-2017-0199Microsoft Office and WordPad Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows…
CVE-2017-0149Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a cr…
CVE-2017-0148Microsoft SMBv1 Server Remote Code Execution Vulnerability
KEVMicrosoft
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0147Microsoft Windows SMBv1 Information Disclosure Vulnerability
KEVMicrosoft
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
CVE-2017-0146Microsoft Windows SMB Remote Code Execution Vulnerability
KEVMicrosoft
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
CVE-2017-0145Microsoft SMBv1 Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0144Microsoft SMBv1 Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2017-0143Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
CVE-2017-0101Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
CVE-2017-0059Microsoft Internet Explorer Information Disclosure Vulnerability
KEVMicrosoft
Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site.
CVE-2017-0037Microsoft Edge and Internet Explorer Type Confusion Vulnerability
KEVMicrosoft
Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
CVE-2017-0022Microsoft XML Core Services Information Disclosure Vulnerability
KEVMicrosoft
Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.
CVE-2017-0005Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability
KEVMicrosoft
The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
CVE-2017-0001Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability
KEVMicrosoft
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an…
CVE-2016-9563SAP NetWeaver XML External Entity (XXE) Vulnerability
KEVSAP
SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML…
CVE-2016-9079Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability
KEVMozilla
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows.
CVE-2016-8735Apache Tomcat Remote Code Execution Vulnerability
KEVCVSS 9.8Apache
Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java …
CVE-2016-8562Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability
KEVSiemens
An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cau…
CVE-2016-7892Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
CVE-2016-7855Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code.
CVE-2016-7836SKYSEA Client View Improper Authentication Vulnerability
KEVSKYSEA
SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP conne…
CVE-2016-7262Microsoft Office Security Feature Bypass Vulnerability
KEVMicrosoft
A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could e…
CVE-2016-7256Microsoft Windows Open Type Font Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully ex…
CVE-2016-7255Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacke…
CVE-2016-7201Microsoft Edge Memory Corruption Vulnerability
KEVMicrosoft
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a …
CVE-2016-7200Microsoft Edge Memory Corruption Vulnerability
KEVMicrosoft
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a …
CVE-2016-7193Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
CVE-2016-6415Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
KEVCisco
Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negot…
CVE-2016-6367Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
KEVCisco
A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (Do…
CVE-2016-6366Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability
KEVCisco
A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the af…
CVE-2016-6277NETGEAR Multiple Routers Remote Code Execution Vulnerability
KEVNETGEAR
NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution.
CVE-2016-5198Google Chromium V8 Out-of-Bounds Memory Vulnerability
KEVGoogle
Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code…
CVE-2016-5195Linux Kernel Race Condition Vulnerability
KEVLinux
Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
CVE-2016-4657Apple iOS Webkit Memory Corruption Vulnerability
KEVApple
Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web s…
CVE-2016-4656Apple iOS Memory Corruption Vulnerability
KEVApple
A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted…
CVE-2016-4655Apple iOS Information Disclosure Vulnerability
KEVApple
The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
CVE-2016-4523Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability
KEVTrihedral
The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
CVE-2016-4437Apache Shiro Code Execution Vulnerability
KEVApache
Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parame…
CVE-2016-4171Adobe Flash Player Remote Code Execution Vulnerability
KEVAdobe
Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
CVE-2016-4117Adobe Flash Player Arbitrary Code Execution Vulnerability
KEVCVSS 9.8Adobe
An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution.
CVE-2016-3976SAP NetWeaver Directory Traversal Vulnerability
KEVSAP
SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFi…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.