Vulnerabilities in N/A
159,958 resultsCVE-2007-3901—Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for Microsoft DirectX 7.EPSS 45.9%CVE-2007-2141—Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary PHP code into shoutEPSS 45.8%CVE-2000-1039—Various TCP/IP stacks and network applications allow remote attackers to cause a denial of service by flooding a target host with TCP connecEPSS 45.8%CVE-2015-5563—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before EPSS 45.8%CVE-2011-5171—Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to execute arbitrary codEPSS 45.8%CVE-2022-37190—CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/apEPSS 45.8%CVE-2008-4834—Buffer overflow in SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackEPSS 45.8%CVE-2005-2373—Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directory name to (1) LIST,EPSS 45.7%CVE-2020-8165—A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal userEPSS 45.7%CVE-2008-4696—Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary web script or HTML viEPSS 45.7%CVE-2019-6444—An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read because attacker-contrEPSS 45.7%CVE-2007-4814—Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.2004.00 in Microsoft SQEPSS 45.7%CVE-2021-28143—/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (under System Tools).EPSS 45.7%CVE-2019-3993—ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's EPSS 45.7%CVE-2007-2093—Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote attackers to inject arEPSS 45.7%CVE-2017-6079—The HTTP web-management application on Edgewater Networks Edgemarc appliances has a hidden page that allows for user-defined commands such aEPSS 45.7%CVE-2005-1989—Unknown vulnerability in Internet Explorer 5.0, 5.5, and 6.0 allows remote attackers to obtain information and possibly execute code when brEPSS 45.7%CVE-2025-29306CRITICALAn issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.EPSS 45.7%CVE-2000-0126—Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.EPSS 45.7%CVE-2019-16891—Liferay Portal CE 6.2.5 allows remote command execution because of deserialization of a JSON payload.EPSS 45.7%