Vulnerabilities in N/A
159,958 resultsCVE-2014-3513—Memory leak in d1_srtp.c in the DTLS SRTP extension in OpenSSL 1.0.1 before 1.0.1j allows remote attackers to cause a denial of service (memEPSS 37.1%CVE-2007-0034—Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers EPSS 37.1%CVE-2005-2117—Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML charactersEPSS 37.0%CVE-2009-0476—Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio componeEPSS 37.0%CVE-2020-13818—In Zoho ManageEngine OpManager before 125144, when <cachestart> is used, directory traversal validation can be bypassed.EPSS 37.0%CVE-2015-8351—PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allowsEPSS 37.0%CVE-2010-0255—Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows EPSS 37.0%CVE-2002-0023—Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which EPSS 37.0%CVE-2014-7883—HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive infoEPSS 37.0%CVE-2005-0582—Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code via a long filename inEPSS 37.0%CVE-2016-3115MEDIUMMultiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended sheEPSS 37.0%CVE-2018-7582—WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to TCP port 9991.EPSS 37.0%CVE-2011-5165—Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted remote attackers to exeEPSS 37.0%CVE-2015-6835—The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_unserialize calls, wEPSS 37.0%CVE-2016-3074—Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or EPSS 37.0%CVE-2007-1525—Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute arbitrary PHP code vEPSS 37.0%CVE-2015-4624—Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.EPSS 37.0%CVE-2017-6019—An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid EPSS 36.9%CVE-2006-6723—The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (memory consumption) vEPSS 36.9%CVE-2016-2118—The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCEPSS 36.9%