91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,451–1,500 of 1,734 in KEV · page 30 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2017-1000486 | Primetek Primefaces Remote Code Execution Vulnerability KEVPrimetek | Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution |
| CVE-2017-1000353 | Jenkins Remote Code Execution Vulnerability KEVJenkins | Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to th… |
| CVE-2017-1000253 | Linux Kernel PIE Stack Buffer Corruption Vulnerability KEVLinux | Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escal… |
| CVE-2017-0263 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. |
| CVE-2017-0262 | Microsoft Office Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in Microsoft Office. |
| CVE-2017-0261 | Microsoft Office Use-After-Free Vulnerability KEVMicrosoft | Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution. |
| CVE-2017-0222 | Microsoft Internet Explorer Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. |
| CVE-2017-0213 | Microsoft Windows Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. |
| CVE-2017-0210 | Microsoft Internet Explorer Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access inf… |
| CVE-2017-0199 | Microsoft Office and WordPad Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows… |
| CVE-2017-0149 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a cr… |
| CVE-2017-0148 | Microsoft SMBv1 Server Remote Code Execution Vulnerability KEVMicrosoft | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. |
| CVE-2017-0147 | Microsoft Windows SMBv1 Information Disclosure Vulnerability KEVMicrosoft | The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. |
| CVE-2017-0146 | Microsoft Windows SMB Remote Code Execution Vulnerability KEVMicrosoft | The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. |
| CVE-2017-0145 | Microsoft SMBv1 Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. |
| CVE-2017-0144 | Microsoft SMBv1 Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. |
| CVE-2017-0143 | Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. |
| CVE-2017-0101 | Microsoft Windows Transaction Manager Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. |
| CVE-2017-0059 | Microsoft Internet Explorer Information Disclosure Vulnerability KEVMicrosoft | Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. |
| CVE-2017-0037 | Microsoft Edge and Internet Explorer Type Confusion Vulnerability KEVMicrosoft | Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. |
| CVE-2017-0022 | Microsoft XML Core Services Information Disclosure Vulnerability KEVMicrosoft | Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site. |
| CVE-2017-0005 | Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability KEVMicrosoft | The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. |
| CVE-2017-0001 | Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability KEVMicrosoft | The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an… |
| CVE-2016-9563 | SAP NetWeaver XML External Entity (XXE) Vulnerability KEVSAP | SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML… |
| CVE-2016-9079 | Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability KEVMozilla | Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. |
| CVE-2016-8735 | Apache Tomcat Remote Code Execution Vulnerability KEVCVSS 9.8Apache | Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if JmxRemoteLifecycleListener is used and an attacker can reach Java … |
| CVE-2016-8562 | Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability KEVSiemens | An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that allows a privileged attacker to remotely cau… |
| CVE-2016-7892 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class. |
| CVE-2016-7855 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute arbitrary code. |
| CVE-2016-7836 | SKYSEA Client View Improper Authentication Vulnerability KEVSKYSEA | SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP conne… |
| CVE-2016-7262 | Microsoft Office Security Feature Bypass Vulnerability KEVMicrosoft | A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could e… |
| CVE-2016-7256 | Microsoft Windows Open Type Font Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully ex… |
| CVE-2016-7255 | Microsoft Win32k Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacke… |
| CVE-2016-7201 | Microsoft Edge Memory Corruption Vulnerability KEVMicrosoft | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a … |
| CVE-2016-7200 | Microsoft Edge Memory Corruption Vulnerability KEVMicrosoft | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a … |
| CVE-2016-7193 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution. |
| CVE-2016-6415 | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability KEVCisco | Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negot… |
| CVE-2016-6367 | Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability KEVCisco | A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (Do… |
| CVE-2016-6366 | Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability KEVCisco | A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the af… |
| CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability KEVNETGEAR | NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line interface, permitting remote code execution. |
| CVE-2016-5198 | Google Chromium V8 Out-of-Bounds Memory Vulnerability KEVGoogle | Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to perform read/write operations, leading to code… |
| CVE-2016-5195 | Linux Kernel Race Condition Vulnerability KEVLinux | Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges. |
| CVE-2016-4657 | Apple iOS Webkit Memory Corruption Vulnerability KEVApple | Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web s… |
| CVE-2016-4656 | Apple iOS Memory Corruption Vulnerability KEVApple | A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted… |
| CVE-2016-4655 | Apple iOS Information Disclosure Vulnerability KEVApple | The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application. |
| CVE-2016-4523 | Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability KEVTrihedral | The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS). |
| CVE-2016-4437 | Apache Shiro Code Execution Vulnerability KEVApache | Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access restrictions via an unspecified request parame… |
| CVE-2016-4171 | Adobe Flash Player Remote Code Execution Vulnerability KEVAdobe | Unspecified vulnerability in Adobe Flash Player allows for remote code execution. |
| CVE-2016-4117 | Adobe Flash Player Arbitrary Code Execution Vulnerability KEVCVSS 9.8Adobe | An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker to perform remote code execution. |
| CVE-2016-3976 | SAP NetWeaver Directory Traversal Vulnerability KEVSAP | SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a ..\ (dot dot backslash) in the fileName parameter to CrashFi… |