Vulnerabilities in N/A
159,958 resultsCVE-2007-0009—Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.1EPSS 50.4%CVE-2000-0665—GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.EPSS 50.3%CVE-2014-7285—The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS coEPSS 50.3%CVE-2017-16720—A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structurEPSS 50.3%CVE-2017-6465—Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP server it is connecting EPSS 50.3%CVE-2015-5130—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before EPSS 50.3%CVE-2015-5134—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before EPSS 50.3%CVE-2015-5127—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before EPSS 50.3%CVE-2012-3363CRITICALZend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows reEPSS 50.2%CVE-2018-9126—The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover databaEPSS 50.2%CVE-2021-3407HIGHA flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.EPSS 50.2%CVE-2011-3230—Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitraryEPSS 50.2%CVE-2021-40493—Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs via the pollingObjecEPSS 50.2%CVE-2010-0477—The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which alEPSS 50.2%CVE-2015-4024—Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, aEPSS 50.1%CVE-2018-14364—GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write acEPSS 50.1%CVE-2017-14535—trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.EPSS 50.1%CVE-2017-14098—In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, oEPSS 50.1%CVE-2012-4915—Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary filEPSS 50.0%CVE-2007-2386—Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termiEPSS 50.0%