91,785 indexed

CVECVE vulnerabilities

91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 1,601–1,650 of 1,734 in KEV · page 33 of 35

IDTitleSummary
CVE-2014-1776Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code in the context of the current user.
CVE-2014-1761Microsoft Word Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
CVE-2014-100005D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability
KEVD-Link
D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existi…
CVE-2014-0780InduSoft Web Studio NTWebServer Directory Traversal Vulnerability
KEVInduSoft
InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read administrative passwords in APP files, allowi…
CVE-2014-0546Adobe Reader and Acrobat Sandbox Bypass Vulnerability
KEVAdobe
Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently execute native code in a privileged context.
CVE-2014-0502Adobe Flash Player Double Free Vulnerablity
KEVAdobe
Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2014-0497Adobe Flash Player Integer Underflow Vulnerablity
KEVAdobe
Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2014-0496Adobe Reader and Acrobat Use-After-Free Vulnerability
KEVAdobe
Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
CVE-2014-0322Microsoft Internet Explorer Use-After-Free Vulnerability
KEVMicrosoft
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
CVE-2014-0196Linux Kernel Race Condition Vulnerability
KEVLinux
Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privile…
CVE-2014-0160OpenSSL Information Disclosure Vulnerability
KEVOpenSSL
The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information.
CVE-2014-0130Ruby on Rails Directory Traversal Vulnerability
KEVRails
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails allows remote attackers …
CVE-2013-7331Microsoft Internet Explorer Information Disclosure Vulnerability
KEVMicrosoft
An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be queried. This vulnerability could allow an …
CVE-2013-6282Linux Kernel Improper Input Validation Vulnerability
KEVLinux
The get_user and put_user API functions of the Linux kernel fail to validate the target address when being used on ARM v6k/v7 platforms. This allows an applica…
CVE-2013-5223D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability
KEVD-Link
A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated users to inject arbitrary web script or HTML.
CVE-2013-5065Microsoft Windows Kernel Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a local attacker to escalate privileges.
CVE-2013-4810HP Multiple Products Remote Code Execution Vulnerability
KEVHewlett Packard (HP)
HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote attackers to execute arbitrary code via a mar…
CVE-2013-3993IBM InfoSphere BigInsights Invalid Input Vulnerability
KEVIBM
Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read, write, modify, or delete data.
CVE-2013-3918Microsoft Windows Out-of-Bounds Write Vulnerability
KEVMicrosoft
Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploi…
CVE-2013-3906Microsoft Graphics Component Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
CVE-2013-3900CVE-2013-3900
KEVCVSS 5.5microsoft
Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to infor…
CVE-2013-3897Microsoft Internet Explorer Use-After-Free Vulnerability
KEVMicrosoft
A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker to remotely execute arbitrary code.
CVE-2013-3896Microsoft Silverlight Information Disclosure Vulnerability
KEVMicrosoft
Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information …
CVE-2013-3893Microsoft Internet Explorer Resource Management Errors Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) …
CVE-2013-3660Microsoft Win32k Privilege Escalation Vulnerability
KEVMicrosoft
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a cert…
CVE-2013-3346Adobe Reader and Acrobat Memory Corruption Vulnerability
KEVAdobe
Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary code or cause a denial of service.
CVE-2013-3163Microsoft Internet Explorer Memory Corruption Vulnerability
KEVMicrosoft
Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted …
CVE-2013-2729Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability
KEVAdobe
Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
CVE-2013-2597Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability
KEVCode Aurora
The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability that allows for privilege escalation. Code …
CVE-2013-2596Linux Kernel Integer Overflow Vulnerability
KEVLinux
Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for privilege escalation.
CVE-2013-2551Microsoft Internet Explorer Use-After-Free Vulnerability
KEVMicrosoft
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a del…
CVE-2013-2465Oracle Java SE Unspecified Vulnerability
KEVOracle
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and a…
CVE-2013-2423Oracle JRE Unspecified Vulnerability
KEVOracle
Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
CVE-2013-2251Apache Struts Improper Input Validation Vulnerability
KEVApache
Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
CVE-2013-2094Linux Kernel Privilege Escalation Vulnerability
KEVLinux
Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perf_swevent_enabled array in sw_perf_eve…
CVE-2013-1690Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability
KEVMozilla
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a d…
CVE-2013-1675Mozilla Firefox Information Disclosure Vulnerability
KEVMozilla
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows…
CVE-2013-1347Microsoft Internet Explorer Remote Code Execution Vulnerability
KEVMicrosoft
This vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explor…
CVE-2013-1331Microsoft Office Buffer Overflow Vulnerability
KEVMicrosoft
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
CVE-2013-0648Adobe Flash Player Code Execution Vulnerability
KEVAdobe
Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary…
CVE-2013-0643Adobe Flash Player Incorrect Default Permissions Vulnerability
KEVAdobe
Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via c…
CVE-2013-0641Adobe Reader Buffer Overflow Vulnerability
KEVAdobe
A buffer overflow vulnerability exists in Adobe Reader which allows an attacker to perform remote code execution.
CVE-2013-0640Adobe Reader and Acrobat Memory Corruption Vulnerability
KEVAdobe
An memory corruption vulnerability exists in the acroform.dll in Adobe Reader that allows an attacker to perform remote code execution.
CVE-2013-0632Adobe ColdFusion Authentication Bypass Vulnerability
KEVAdobe
An authentication bypass vulnerability exists in Adobe ColdFusion which could result in an unauthorized user gaining administrative access.
CVE-2013-0631Adobe ColdFusion Information Disclosure Vulnerability
KEVAdobe
Adobe Coldfusion contains an unspecified vulnerability, which could result in information disclosure from a compromised server.
CVE-2013-0629Adobe ColdFusion Directory Traversal Vulnerability
KEVAdobe
Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.
CVE-2013-0625Adobe ColdFusion Authentication Bypass Vulnerability
KEVAdobe
Adobe Coldfusion contains an authentication bypass vulnerability, which could result in an unauthorized user gaining administrative access.
CVE-2013-0431Oracle JRE Sandbox Bypass Vulnerability
KEVCVSS 3.7Oracle
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
CVE-2013-0422Oracle JRE Remote Code Execution Vulnerability
KEVOracle
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
CVE-2013-0074Microsoft Silverlight Double Dereference Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.