Vulnerabilities in N/A
160,538 resultsCVE-2012-2333—Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC enEPSS 28.2%CVE-2006-0058—Signal handler race condition in Sendmail 8.13.x before 8.13.6 allows remote attackers to execute arbitrary code by triggering timeouts in aEPSS 28.1%CVE-2020-10931—Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to tryEPSS 28.1%CVE-2003-1566—Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sEPSS 28.1%CVE-2016-3109—The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.EPSS 28.1%CVE-2019-14529—OpenEMR before 5.0.2 allows SQL Injection in interface/forms/eye_mag/save.php.EPSS 28.1%CVE-1999-0737—The viewcode.asp sample file in IIS and Site Server allows remote attackers to read arbitrary files.EPSS 28.1%CVE-2013-0006HIGHMicrosoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbiEPSS 28.1%CVE-2011-1137—Integer overflow in the mod_sftp (aka SFTP) module in ProFTPD 1.3.3d and earlier allows remote attackers to cause a denial of service (memorEPSS 28.1%CVE-2001-0875—Internet Explorer 5.5 and 6.0 allows remote attackers to cause the File Download dialogue box to misrepresent the name of the file in the diEPSS 28.1%CVE-2000-0071—IIS 4.0 allows a remote attacker to obtain the real pathname of the document root by requesting non-existent files with .ida or .idq extensiEPSS 28.1%CVE-2009-0689—Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in EPSS 28.1%CVE-2020-35606—Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commEPSS 28.0%CVE-2021-43287—An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets kEPSS 28.0%CVE-2007-5347—Microsoft Internet Explorer 5.01 through 7 allows remote attackers to execute arbitrary code via "unexpected method calls to HTML objects," EPSS 28.0%CVE-2008-1456—Array index vulnerability in the Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, anEPSS 28.0%CVE-2008-3263—The IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.EPSS 28.0%CVE-2009-0223—Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via crafted sound data in a fEPSS 28.0%CVE-2009-0560—Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System EPSS 28.0%CVE-2008-3474MEDIUMMicrosoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attEPSS 28.0%