91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,551–1,600 of 1,734 in KEV · page 32 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2015-2590 | Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability KEVOracle | An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote code execution. |
| CVE-2015-2546 | Microsoft Win32k Memory Corruption Vulnerability KEVCVSS 8.2Microsoft | The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application. |
| CVE-2015-2545 | Microsoft Office Malformed EPS File Vulnerability KEVMicrosoft | Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image. |
| CVE-2015-2502 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or cause a denial-of-service (DoS). |
| CVE-2015-2426 | Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles specially crafted OpenType fon… |
| CVE-2015-2425 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2015-2424 | Microsoft PowerPoint Memory Corruption Vulnerability KEVMicrosoft | Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document. |
| CVE-2015-2419 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. |
| CVE-2015-2387 | Microsoft ATM Font Driver Privilege Escalation Vulnerability KEVMicrosoft | ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges via a crafted application. |
| CVE-2015-2360 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause denial-of-service (DoS). |
| CVE-2015-2291 | Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability KEVCVSS 7.8Intel | Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS). |
| CVE-2015-2051 | D-Link DIR-645 Router Remote Code Execution Vulnerability KEVD-Link | D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface. |
| CVE-2015-1770 | Microsoft Office Uninitialized Memory Use Vulnerability KEVMicrosoft | Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document. |
| CVE-2015-1769 | Microsoft Windows Mount Manager Privilege Escalation Vulnerability KEVMicrosoft | A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links. |
| CVE-2015-1701 | Microsoft Win32k Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code wit… |
| CVE-2015-1671 | Microsoft Windows Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and Silverlight fail to properly handle TrueType fonts. |
| CVE-2015-1642 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code via a crafted document. |
| CVE-2015-1641 | Microsoft Office Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows … |
| CVE-2015-1635 | Microsoft HTTP.sys Remote Code Execution Vulnerability KEVMicrosoft | Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution. |
| CVE-2015-1427 | Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability KEVElastic | The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands. |
| CVE-2015-1187 | D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability KEVD-Link and TRENDnet | The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution. |
| CVE-2015-1130 | Apple OS X Authentication Bypass Vulnerability KEVApple | The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges. |
| CVE-2015-0666 | Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability KEVCisco | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. |
| CVE-2015-0313 | Adobe Flash Player Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code. |
| CVE-2015-0311 | Adobe Flash Player Remote Code Execution Vulnerability KEVAdobe | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code. |
| CVE-2015-0310 | Adobe Flash Player ASLR Bypass Vulnerability KEVAdobe | Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) pro… |
| CVE-2015-0071 | Microsoft Internet Explorer ASLR Bypass Vulnerability KEVMicrosoft | Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR) protection mechanism via a crafted web site. |
| CVE-2015-0016 | Microsoft Windows TS WebProxy Directory Traversal Vulnerability KEVMicrosoft | Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges. |
| CVE-2014-9163 | Adobe Flash Player Stack-Based Buffer Overflow Vulnerability KEVAdobe | Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely. |
| CVE-2014-8439 | Adobe Flash Player Dereferenced Pointer Vulnerability KEVAdobe | Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code execution. |
| CVE-2014-8361 | Realtek SDK Improper Input Validation Vulnerability KEVRealtek | Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote attackers to execute malicious code via a crafte… |
| CVE-2014-7169 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability KEVGNU | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute cod… |
| CVE-2014-6352 | Microsoft Windows Code Injection Vulnerability KEVMicrosoft | Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object. |
| CVE-2014-6332 | Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability KEVMicrosoft | OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site. |
| CVE-2014-6324 | Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability KEVMicrosoft | The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain administrator privileges. |
| CVE-2014-6287 | Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability KEVRejetto | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote attackers to execute arbitrary programs. |
| CVE-2014-6278 | GNU Bash OS Command Injection Vulnerability KEVGNU | GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. |
| CVE-2014-6271 | GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability KEVGNU | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute cod… |
| CVE-2014-4404 | Apple OS X Heap-Based Buffer Overflow Vulnerability KEVApple | Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows attackers to execute arbitrary code in a pri… |
| CVE-2014-4148 | Microsoft Windows Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts. |
| CVE-2014-4123 | Microsoft Internet Explorer Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. |
| CVE-2014-4114 | Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability KEVMicrosoft | A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user opens a file that contains a specially craf… |
| CVE-2014-4113 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2014-4077 | Microsoft IME Japanese Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with t… |
| CVE-2014-3931 | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability KEVLooking Glass | Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corr… |
| CVE-2014-3153 | Linux Kernel Privilege Escalation Vulnerability KEVLinux | The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex addresses, which allows local users to gain pr… |
| CVE-2014-3120 | Elasticsearch Remote Code Execution Vulnerability KEVElastic | Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code. |
| CVE-2014-2817 | Microsoft Internet Explorer Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via a crafted web site. |
| CVE-2014-2120 | Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability KEVCisco | Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attacker… |
| CVE-2014-1812 | Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy… |