91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,551–1,600 of 1,734 in KEV · page 32 of 35

IDTitleSummary
CVE-2015-2590Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability
KEVOracle
An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution.
CVE-2015-2546Microsoft Win32k Memory Corruption Vulnerability
KEVCVSS 8.2Microsoft
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
CVE-2015-2545Microsoft Office Malformed EPS File Vulnerability
KEVMicrosoft
Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
CVE-2015-2502Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS).
CVE-2015-2426Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fon…
CVE-2015-2425Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS).
CVE-2015-2424Microsoft PowerPoint Memory Corruption Vulnerability
KEVMicrosoft
Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document.
CVE-2015-2419Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site.
CVE-2015-2387Microsoft ATM Font Driver Privilege Escalation Vulnerability
KEVMicrosoft
ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application.
CVE-2015-2360Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS).
CVE-2015-2291Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability
KEVCVSS 7.8Intel
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
CVE-2015-2051D-Link DIR-645 Router Remote Code Execution Vulnerability
KEVD-Link
D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
CVE-2015-1770Microsoft Office Uninitialized Memory Use Vulnerability
KEVMicrosoft
Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
CVE-2015-1769Microsoft Windows Mount Manager Privilege Escalation Vulnerability
KEVMicrosoft
A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
CVE-2015-1701Microsoft Win32k Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code wit…
CVE-2015-1671Microsoft Windows Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts.
CVE-2015-1642Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document.
CVE-2015-1641Microsoft Office Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows …
CVE-2015-1635Microsoft HTTP.sys Remote Code Execution Vulnerability
KEVMicrosoft
Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
CVE-2015-1427Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability
KEVElastic
The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands.
CVE-2015-1187D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability
KEVD-Link and TRENDnet
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
CVE-2015-1130Apple OS X Authentication Bypass Vulnerability
KEVApple
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges.
CVE-2015-0666Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
KEVCisco
Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
CVE-2015-0313Adobe Flash Player Use-After-Free Vulnerability
KEVAdobe
Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0311Adobe Flash Player Remote Code Execution Vulnerability
KEVAdobe
Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
CVE-2015-0310Adobe Flash Player ASLR Bypass Vulnerability
KEVAdobe
Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) pro…
CVE-2015-0071Microsoft Internet Explorer ASLR Bypass Vulnerability
KEVMicrosoft
Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site.
CVE-2015-0016Microsoft Windows TS WebProxy Directory Traversal Vulnerability
KEVMicrosoft
Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.
CVE-2014-9163Adobe Flash Player Stack-Based Buffer Overflow Vulnerability
KEVAdobe
Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
CVE-2014-8439Adobe Flash Player Dereferenced Pointer Vulnerability
KEVAdobe
Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution.
CVE-2014-8361Realtek SDK Improper Input Validation Vulnerability
KEVRealtek
Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafte…
CVE-2014-7169GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
KEVGNU
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute cod…
CVE-2014-6352Microsoft Windows Code Injection Vulnerability
KEVMicrosoft
Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
CVE-2014-6332Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
KEVMicrosoft
OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
CVE-2014-6324Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability
KEVMicrosoft
The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges.
CVE-2014-6287Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability
KEVRejetto
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs.
CVE-2014-6278GNU Bash OS Command Injection Vulnerability
KEVGNU
GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.
CVE-2014-6271GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability
KEVGNU
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute cod…
CVE-2014-4404Apple OS X Heap-Based Buffer Overflow Vulnerability
KEVApple
Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a pri…
CVE-2014-4148Microsoft Windows Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
CVE-2014-4123Microsoft Internet Explorer Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
CVE-2014-4114Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability
KEVMicrosoft
A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially craf…
CVE-2014-4113Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
CVE-2014-4077Microsoft IME Japanese Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with t…
CVE-2014-3931Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability
KEVLooking Glass
Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corr…
CVE-2014-3153Linux Kernel Privilege Escalation Vulnerability
KEVLinux
The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain pr…
CVE-2014-3120Elasticsearch Remote Code Execution Vulnerability
KEVElastic
Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
CVE-2014-2817Microsoft Internet Explorer Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site.
CVE-2014-2120Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability
KEVCisco
Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attacker…
CVE-2014-1812Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.