Vulnerabilities in N/A
159,958 resultsCVE-2023-24322MEDIUMA reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbEPSS 31.7%CVE-2008-3473—Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attEPSS 31.7%CVE-2014-0591—The query_findclosestnsec3 function in query.c in named in ISC BIND 9.6, 9.7, and 9.8 before 9.8.6-P2 and 9.9 before 9.9.4-P2, and 9.6-ESV bEPSS 31.7%CVE-2012-5613—MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the FILE privilege to uEPSS 31.7%CVE-2006-1305—Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interruptedEPSS 31.7%CVE-2013-3860—Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 does not properly parse a DTD during XML digital-signature validation, whiEPSS 31.6%CVE-2013-3120—Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafEPSS 31.6%CVE-2015-8410—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2EPSS 31.6%CVE-2015-8048—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2EPSS 31.6%CVE-2015-8412—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2EPSS 31.6%CVE-2015-8411—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2EPSS 31.6%CVE-2015-8413—Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2EPSS 31.6%CVE-2009-1137—Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a fEPSS 31.6%CVE-2009-0222—Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a fEPSS 31.6%CVE-2015-1896—Stack-based buffer overflow in the FastBackMount process in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.11.1 allows remote attackers EPSS 31.6%CVE-2008-4728—Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird DeploymEPSS 31.6%CVE-2001-0010—Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.EPSS 31.6%CVE-2006-1191—Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allEPSS 31.6%CVE-2001-0663—Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of invalid Remote DesktopEPSS 31.6%CVE-2009-2505—The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 ProtectedEPSS 31.6%