Vulnerabilities in N/A
159,958 resultsCVE-2019-12583—Missing Access Control in the "Free Time" component of several Zyxel UAG, USG, and ZyWall devices allows a remote attacker to generate guestEPSS 43.9%CVE-2008-0016—Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote aEPSS 43.9%CVE-2005-4145—The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with a small search spaceEPSS 43.9%CVE-2020-13693—An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Registration is enabled.EPSS 43.9%CVE-2021-20235—There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator could have its sizeEPSS 43.9%CVE-2012-1775—Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code via a crafted MMS://EPSS 43.8%CVE-2014-0198—The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a bEPSS 43.8%CVE-2019-2215HIGHA use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exEPSS 43.8%KEVCVE-2014-8687—Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root privileges by leveraEPSS 43.8%CVE-2014-0231—The mod_cgid module in the Apache HTTP Server before 2.4.10 does not have a timeout mechanism, which allows remote attackers to cause a deniEPSS 43.8%CVE-2019-9618—The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.EPSS 43.8%CVE-2005-2122—Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shEPSS 43.8%CVE-2014-2815—Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executaEPSS 43.8%CVE-2001-0877—Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP aEPSS 43.8%CVE-2008-0105—Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arEPSS 43.8%CVE-2006-3637—Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted rEPSS 43.8%CVE-2006-4602—Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP codEPSS 43.7%CVE-2006-4704—Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in MicrosEPSS 43.7%CVE-2018-6317—The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability, allEPSS 43.7%CVE-2021-31642—A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, anEPSS 43.7%