91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,601–1,650 of 1,734 in KEV · page 33 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2014-1776 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user. |
| CVE-2014-1761 | Microsoft Word Memory Corruption Vulnerability KEVMicrosoft | Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution. |
| CVE-2014-100005 | D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability KEVD-Link | D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existi… |
| CVE-2014-0780 | InduSoft Web Studio NTWebServer Directory Traversal Vulnerability KEVInduSoft | InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowi… |
| CVE-2014-0546 | Adobe Reader and Acrobat Sandbox Bypass Vulnerability KEVAdobe | Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context. |
| CVE-2014-0502 | Adobe Flash Player Double Free Vulnerablity KEVAdobe | Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code. |
| CVE-2014-0497 | Adobe Flash Player Integer Underflow Vulnerablity KEVAdobe | Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code. |
| CVE-2014-0496 | Adobe Reader and Acrobat Use-After-Free Vulnerability KEVAdobe | Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution. |
| CVE-2014-0322 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code. |
| CVE-2014-0196 | Linux Kernel Race Condition Vulnerability KEVLinux | Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privile… |
| CVE-2014-0160 | OpenSSL Information Disclosure Vulnerability KEVOpenSSL | The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information. |
| CVE-2014-0130 | Ruby on Rails Directory Traversal Vulnerability KEVRails | Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers … |
| CVE-2013-7331 | Microsoft Internet Explorer Information Disclosure Vulnerability KEVMicrosoft | An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an … |
| CVE-2013-6282 | Linux Kernel Improper Input Validation Vulnerability KEVLinux | The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an applica… |
| CVE-2013-5223 | D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability KEVD-Link | A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML. |
| CVE-2013-5065 | Microsoft Windows Kernel Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges. |
| CVE-2013-4810 | HP Multiple Products Remote Code Execution Vulnerability KEVHewlett Packard (HP) | HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a mar… |
| CVE-2013-3993 | IBM InfoSphere BigInsights Invalid Input Vulnerability KEVIBM | Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data. |
| CVE-2013-3918 | Microsoft Windows Out-of-Bounds Write Vulnerability KEVMicrosoft | Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploi… |
| CVE-2013-3906 | Microsoft Graphics Component Memory Corruption Vulnerability KEVMicrosoft | Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution. |
| CVE-2013-3900 | CVE-2013-3900 KEVCVSS 5.5microsoft | Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to infor… |
| CVE-2013-3897 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code. |
| CVE-2013-3896 | Microsoft Silverlight Information Disclosure Vulnerability KEVMicrosoft | Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information … |
| CVE-2013-3893 | Microsoft Internet Explorer Resource Management Errors Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) … |
| CVE-2013-3660 | Microsoft Win32k Privilege Escalation Vulnerability KEVMicrosoft | The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a cert… |
| CVE-2013-3346 | Adobe Reader and Acrobat Memory Corruption Vulnerability KEVAdobe | Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service. |
| CVE-2013-3163 | Microsoft Internet Explorer Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted … |
| CVE-2013-2729 | Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability KEVAdobe | Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code. |
| CVE-2013-2597 | Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability KEVCode Aurora | The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code … |
| CVE-2013-2596 | Linux Kernel Integer Overflow Vulnerability KEVLinux | Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation. |
| CVE-2013-2551 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a del… |
| CVE-2013-2465 | Oracle Java SE Unspecified Vulnerability KEVOracle | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and a… |
| CVE-2013-2423 | Oracle JRE Unspecified Vulnerability KEVOracle | Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity. |
| CVE-2013-2251 | Apache Struts Improper Input Validation Vulnerability KEVApache | Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions. |
| CVE-2013-2094 | Linux Kernel Privilege Escalation Vulnerability KEVLinux | Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_eve… |
| CVE-2013-1690 | Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability KEVMozilla | Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a d… |
| CVE-2013-1675 | Mozilla Firefox Information Disclosure Vulnerability KEVMozilla | Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows… |
| CVE-2013-1347 | Microsoft Internet Explorer Remote Code Execution Vulnerability KEVMicrosoft | This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explor… |
| CVE-2013-1331 | Microsoft Office Buffer Overflow Vulnerability KEVMicrosoft | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document. |
| CVE-2013-0648 | Adobe Flash Player Code Execution Vulnerability KEVAdobe | Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary… |
| CVE-2013-0643 | Adobe Flash Player Incorrect Default Permissions Vulnerability KEVAdobe | Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via c… |
| CVE-2013-0641 | Adobe Reader Buffer Overflow Vulnerability KEVAdobe | A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution. |
| CVE-2013-0640 | Adobe Reader and Acrobat Memory Corruption Vulnerability KEVAdobe | An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution. |
| CVE-2013-0632 | Adobe ColdFusion Authentication Bypass Vulnerability KEVAdobe | An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access. |
| CVE-2013-0631 | Adobe ColdFusion Information Disclosure Vulnerability KEVAdobe | Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server. |
| CVE-2013-0629 | Adobe ColdFusion Directory Traversal Vulnerability KEVAdobe | Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories. |
| CVE-2013-0625 | Adobe ColdFusion Authentication Bypass Vulnerability KEVAdobe | Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access. |
| CVE-2013-0431 | Oracle JRE Sandbox Bypass Vulnerability KEVCVSS 3.7Oracle | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox. |
| CVE-2013-0422 | Oracle JRE Remote Code Execution Vulnerability KEVOracle | A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system. |
| CVE-2013-0074 | Microsoft Silverlight Double Dereference Vulnerability KEVCVSS 7.8Microsoft | Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight… |