91,785 indexed
CVECVE vulnerabilities
91,785 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,701–1,734 of 1,734 in KEV · page 35 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2010-0738 | Red Hat JBoss Authentication Bypass Vulnerability KEVCVSS 5.3Red Hat | The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which al… |
| CVE-2010-0249 | Microsoft Internet Explorer Use-After-Free Vulnerability KEVMicrosoft | Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associa… |
| CVE-2010-0232 | Microsoft Windows Kernel Exception Handler Vulnerability KEVMicrosoft | The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which a… |
| CVE-2010-0188 | Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability KEVCVSS 7.8Adobe | Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code. |
| CVE-2009-4324 | Adobe Acrobat and Reader Use-After-Free Vulnerability KEVAdobe | Use-after-free vulnerability in Adobe Acrobat and Reader allows remote attackers to execute code via a crafted PDF file. |
| CVE-2009-3960 | Adobe BlazeDS Information Disclosure Vulnerability KEVCVSS 6.5Adobe | Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure. |
| CVE-2009-3953 | Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability KEVAdobe | Adobe Acrobat and Reader contains an array boundary issue in Universal 3D (U3D) support that could lead to remote code execution. |
| CVE-2009-3459 | Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability KEVAdobe | Adobe Acrobat and Reader contain a heap-based buffer overflow vulnerability which could allow remote attackers to execute arbitrary code via a crafted PDF file… |
| CVE-2009-3129 | Microsoft Excel Featheader Record Memory Corruption Vulnerability KEVMicrosoft | Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size elemen… |
| CVE-2009-2055 | Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability KEVCisco | Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). |
| CVE-2009-1862 | Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability KEVAdobe | Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS). |
| CVE-2009-1537 | Microsoft DirectX NULL Byte Overwrite Vulnerability KEVMicrosoft | Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attack… |
| CVE-2009-1151 | phpMyAdmin Remote Code Execution Vulnerability KEVphpMyAdmin | Setup script used to generate configuration can be fooled using a crafted POST request to include arbitrary PHP code in generated configuration file. |
| CVE-2009-1123 | Microsoft Windows Improper Input Validation Vulnerability KEVMicrosoft | The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted app… |
| CVE-2009-0927 | Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability KEVAdobe | Stack-based buffer overflow in Adobe Reader and Adobe Acrobat allows remote attackers to execute arbitrary code. |
| CVE-2009-0563 | Microsoft Office Buffer Overflow Vulnerability KEVMicrosoft | Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an inv… |
| CVE-2009-0557 | Microsoft Office Object Record Corruption Vulnerability KEVMicrosoft | Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed reco… |
| CVE-2009-0556 | Microsoft Office PowerPoint Code Injection Vulnerability KEVMicrosoft | Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an Outlin… |
| CVE-2009-0238 | Microsoft Office Remote Code Execution KEVMicrosoft | Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user ope… |
| CVE-2008-4250 | Microsoft Windows Buffer Overflow Vulnerability KEVMicrosoft | Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted R… |
| CVE-2008-4128 | Cisco IOS Cross-Site Request Forgery Vulnerability KEVCVSS 8.1Cisco | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privileg… |
| CVE-2008-3431 | Oracle VirtualBox Insufficient Input Validation Vulnerability KEVOracle | An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code. |
| CVE-2008-2992 | Adobe Reader and Acrobat Input Validation Vulnerability KEVAdobe | Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution. |
| CVE-2008-0655 | Adobe Acrobat and Reader Unspecified Vulnerability KEVAdobe | Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an… |
| CVE-2008-0015 | Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially… |
| CVE-2007-5659 | Adobe Acrobat and Reader Buffer Overflow Vulnerability KEVAdobe | Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified… |
| CVE-2007-3010 | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability KEVAlcatel | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server allows remote attackers to execute arbitrary commands. |
| CVE-2007-0671 | Microsoft Office Excel Remote Code Execution Vulnerability KEVMicrosoft | Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file … |
| CVE-2006-2492 | Microsoft Word Malformed Object Pointer Vulnerability KEVMicrosoft | Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code. |
| CVE-2006-1547 | Apache Struts 1 ActionForm Denial-of-Service Vulnerability KEVApache | ActionForm in Apache Struts versions before 1.2.9 with BeanUtils 1.7 contains a vulnerability that allows for denial-of-service (DoS). |
| CVE-2005-2773 | HP OpenView Network Node Manager Remote Code Execution Vulnerability KEVHewlett Packard (HP) | HP OpenView Network Node Manager could allow a remote attacker to execute arbitrary commands on the system. |
| CVE-2004-1464 | Cisco IOS Denial-of-Service Vulnerability KEVCisco | Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hyper… |
| CVE-2004-0210 | Microsoft Windows Privilege Escalation Vulnerability KEVMicrosoft | A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system. |
| CVE-2002-0367 | Microsoft Windows Privilege Escalation Vulnerability KEVMicrosoft | smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain admi… |