Vulnerabilities in N/A
159,958 resultsCVE-2019-9511HIGHSome HTTP/2 implementations are vulnerable to window size manipulation and stream prioritization manipulation, potentially leading to a denial of serviceEPSS 59.5%CVE-2013-7108—Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allowEPSS 59.5%CVE-2005-0768—Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remoEPSS 59.5%CVE-2006-4868—Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on WinEPSS 59.5%CVE-2013-5795—Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0EPSS 59.5%CVE-2006-6424—Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to EPSS 59.5%CVE-2021-42342—An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passed to CGI scripts witEPSS 59.5%CVE-2007-3813—PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitEPSS 59.4%CVE-2018-8770—Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.EPSS 59.4%CVE-2018-11218—Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 EPSS 59.4%CVE-2012-2576—SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, aEPSS 59.4%CVE-2012-0549—Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows remote attackers to affEPSS 59.4%CVE-2022-47075HIGHAn issue was discovered in Smart Office Web 20.28 and earlier allows attackers to download sensitive information via the action name parametEPSS 59.4%CVE-2017-16249—The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the seEPSS 59.4%CVE-2013-3138—Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, WindowsEPSS 59.4%CVE-2023-43261HIGHAn information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router componentsEPSS 59.3%CVE-2007-1868—The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-daEPSS 59.3%CVE-2004-1595—Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.EPSS 59.3%CVE-2015-0206—Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers tEPSS 59.3%CVE-2015-5603—The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecifieEPSS 59.3%