Vulnerabilities in N/A

159,958 results
CVE-2009-2496Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web ComponentEPSS 29.5%CVE-2016-8858HIGHThe kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consEPSS 29.5%CVE-2014-1201Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 serEPSS 29.5%CVE-2022-40881CRITICALSolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpEPSS 29.5%CVE-2016-7191The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recEPSS 29.4%CVE-2019-19492FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.EPSS 29.4%CVE-2009-0559Stack-based buffer overflow in Excel in Microsoft Office 2000 SP3 and Office XP SP3 allows remote attackers to execute arbitrary code via a EPSS 29.4%CVE-2004-0600Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute arbitrary code via anEPSS 29.4%CVE-2012-2175Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows EPSS 29.4%CVE-2001-1319Microsoft Exchange 5.5 2000 allows remote attackers to cause a denial of service (hang) via exceptional BER encodings for the LDAP filter tyEPSS 29.4%CVE-2021-37557A SQL injection vulnerability in image generation in Centreon before 20.04.14, 20.10.8, and 21.04.2 allows remote authenticated (but low-priEPSS 29.4%CVE-2006-1313Microsoft JScript 5.1, 5.5, and 5.6 on Windows 2000 SP4, and 5.6 on Windows XP, Server 2003, Windows 98 and Windows Me, will "release objectEPSS 29.4%CVE-2012-1891CRITICALHeap-based buffer overflow in Microsoft Data Access Components (MDAC) 2.8 SP1 and SP2 and Windows Data Access Components (WDAC) 6.0 allows rEPSS 29.4%CVE-2015-8043Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 EPSS 29.4%CVE-2018-14699System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackerEPSS 29.4%CVE-2012-4598An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary codeEPSS 29.4%CVE-2011-1002avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an emptyEPSS 29.4%CVE-2007-3670Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered,EPSS 29.4%CVE-2016-0198Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, OEPSS 29.4%CVE-2022-32209# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::SaniEPSS 29.4%