Vulnerabilities in N/A
159,958 resultsCVE-2005-0068—The original design of ICMP does not require authentication for host-generated ICMP error messages, which makes it easier for attackers to fEPSS 54.4%CVE-2001-1217—Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitiveEPSS 54.4%CVE-2011-0027—Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2, and Windows Data Access Components (WDAC) 6.0, does not properly validate memory alEPSS 54.4%CVE-2007-1765—Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial ofEPSS 54.3%CVE-2020-29557CRITICALAn issue was discovered on D-Link DIR-825 R1 devices through 3.0.1 before 2020-11-20. A buffer overflow in the web interface allows attackerEPSS 54.3%KEVCVE-2013-1899—Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to caEPSS 54.3%CVE-2019-6453—mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify EPSS 54.3%CVE-1999-0661—A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers EPSS 54.2%CVE-2006-5229—OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attaEPSS 54.2%CVE-2018-5347—Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.pEPSS 54.2%CVE-2005-0771—VERITAS Backup Exec Server (beserver.exe) 9.0 through 10.0 for Windows allows remote unauthenticated attackers to modify the registry by calEPSS 54.2%CVE-2019-17382—An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and aEPSS 54.1%CVE-2001-0800—lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.EPSS 54.1%CVE-2006-0395—The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which aEPSS 54.1%CVE-2006-4948—Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary cEPSS 54.1%CVE-2019-19609—The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the AdmEPSS 54.1%CVE-2022-38130—The com.keysight.tentacle.config.ResourceManager.smsRestoreDatabaseZip() method is used to restore the HSQLDB database used in SMS. It takesEPSS 54.1%CVE-2022-25075—TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerabilityEPSS 54.1%CVE-2017-6398—An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user can execute a terminEPSS 54.1%CVE-2010-1663—The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same OrigEPSS 54.1%