91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,651–1,700 of 1,734 in KEV · page 34 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2012-5076 | Oracle Java SE Sandbox Bypass Vulnerability KEVOracle | The default Java security properties configuration did not restrict access to the com.sun.org.glassfish.external and com.sun.org.glassfish.gmbal packages. An u… |
| CVE-2012-5054 | Adobe Flash Player Integer Overflow Vulnerability KEVAdobe | Adobe Flash Player contains an integer overflow vulnerability that allows remote attackers to execute code via malformed arguments. |
| CVE-2012-4969 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site. |
| CVE-2012-4792 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that trigger… |
| CVE-2012-4681 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability KEVCVSS 9.8Oracle | The Java Runtime Environment (JRE) component in Oracle Java SE allow for remote code execution. |
| CVE-2012-3152 | Oracle Fusion Middleware Unspecified Vulnerability KEVOracle | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affect… |
| CVE-2012-2539 | Microsoft Word Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data. |
| CVE-2012-2034 | Adobe Flash Player Memory Corruption Vulnerability KEVAdobe | Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS). |
| CVE-2012-1889 | Microsoft XML Core Services Memory Corruption Vulnerability KEVMicrosoft | Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution. |
| CVE-2012-1856 | Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability KEVMicrosoft | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) doc… |
| CVE-2012-1854 | Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability KEVMicrosoft | Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. |
| CVE-2012-1823 | PHP-CGI Query String Parameter Vulnerability KEVPHP | sapi/cgi/cgi_main.c in PHP, when configured as a CGI script, does not properly handle query strings, which allows remote attackers to execute arbitrary code. |
| CVE-2012-1723 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability KEVCVSS 9.8Oracle | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers to affect confidentiality, integrity, and a… |
| CVE-2012-1710 | Oracle Fusion Middleware Unspecified Vulnerability KEVCVSS 9.8Oracle | Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, in… |
| CVE-2012-1535 | Adobe Flash Player Arbitrary Code Execution Vulnerability KEVAdobe | Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content. |
| CVE-2012-0767 | Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability KEVAdobe | Adobe Flash Player contains a XSS vulnerability that allows remote attackers to inject web script or HTML. |
| CVE-2012-0754 | Adobe Flash Player Memory Corruption Vulnerability KEVAdobe | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2012-0518 | Oracle Fusion Middleware Unspecified Vulnerability KEVOracle | Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via… |
| CVE-2012-0507 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability KEVCVSS 9.8Oracle | An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code. |
| CVE-2012-0391 | Apache Struts 2 Improper Input Validation Vulnerability KEVApache | The ExceptionDelegator component in Apache Struts 2 before 2.2.3.1 contains an improper input validation vulnerability that allows for remote code execution. |
| CVE-2012-0158 | Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability KEVMicrosoft | Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affecte… |
| CVE-2012-0151 | Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability KEVMicrosoft | The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (P… |
| CVE-2011-4723 | D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability KEVD-Link | The D-Link DIR-300 router stores cleartext passwords, which allows context-dependent attackers to obtain sensitive information. |
| CVE-2011-3544 | Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability KEVOracle | An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute … |
| CVE-2011-3402 | Microsoft Windows Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote … |
| CVE-2011-2462 | Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability KEVAdobe | The Universal 3D (U3D) component in Adobe Reader and Acrobat contains a memory corruption vulnerability which could allow remote attackers to execute code or c… |
| CVE-2011-2005 | Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability KEVMicrosoft | afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gai… |
| CVE-2011-1889 | Microsoft Forefront TMG Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution … |
| CVE-2011-1823 | Android OS Privilege Escalation Vulnerability KEVAndroid | The vold volume manager daemon in Android kernel trusts messages from a PF_NETLINK socket, which allows an attacker to execute code and gain root privileges. T… |
| CVE-2011-0611 | Adobe Flash Player Remote Code Execution Vulnerability KEVAdobe | Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted… |
| CVE-2011-0609 | Adobe Flash Player Unspecified Vulnerability KEVAdobe | Adobe Flash Player contains an unspecified vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2010-5330 | Ubiquiti AirOS Command Injection Vulnerability KEVUbiquiti | Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi. |
| CVE-2010-5326 | SAP NetWeaver Remote Code Execution Vulnerability KEVSAP | SAP NetWeaver Application Server Java Platforms Invoker Servlet does not require authentication, allowing for remote code execution via a HTTP or HTTPS request. |
| CVE-2010-4398 | Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability KEVMicrosoft | Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the Use… |
| CVE-2010-4345 | Exim Privilege Escalation Vulnerability KEVExim | Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that … |
| CVE-2010-4344 | Exim Heap-Based Buffer Overflow Vulnerability KEVExim | Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session. |
| CVE-2010-3962 | Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be… |
| CVE-2010-3904 | Linux Kernel Improper Input Validation Vulnerability KEVLinux | Linux Kernel contains an improper input validation vulnerability in the Reliable Datagram Sockets (RDS) protocol implementation that allows local users to gain… |
| CVE-2010-3765 | Mozilla Multiple Products Remote Code Execution Vulnerability KEVMozilla | Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary … |
| CVE-2010-3333 | Microsoft Office Stack-based Buffer Overflow Vulnerability KEVMicrosoft | A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code executi… |
| CVE-2010-3035 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability KEVCisco | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). |
| CVE-2010-2883 | Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability KEVAdobe | Adobe Acrobat and Reader contain a stack-based buffer overflow vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2010-2861 | Adobe ColdFusion Directory Traversal Vulnerability KEVCVSS 9.8Adobe | A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files. |
| CVE-2010-2572 | Microsoft PowerPoint Buffer Overflow Vulnerability KEVMicrosoft | Microsoft PowerPoint contains a buffer overflow vulnerability that alllows for remote code execution. |
| CVE-2010-2568 | Microsoft Windows Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious sho… |
| CVE-2010-1871 | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability KEVRed Hat | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This v… |
| CVE-2010-1428 | Red Hat JBoss Information Disclosure Vulnerability KEVCVSS 7.5Red Hat | Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, … |
| CVE-2010-1297 | Adobe Flash Player Memory Corruption Vulnerability KEVAdobe | Adobe Flash Player contains a memory corruption vulnerability that allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2010-0840 | Oracle JRE Unspecified Vulnerability KEVOracle | Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availabi… |
| CVE-2010-0806 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access t… |