Vulnerabilities in N/A
159,958 resultsCVE-2023-50868HIGHThe Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denEPSS 81.7%CVE-2012-2763—Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, alloEPSS 81.7%CVE-2012-4969HIGHUse-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 allows remote attackerEPSS 81.7%KEVCVE-2018-6789CRITICALAn issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overfEPSS 81.7%KEVCVE-2014-8516—Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a fiEPSS 81.7%CVE-2010-3971—Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in EPSS 81.7%CVE-2014-4114HIGHMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, andEPSS 81.6%KEVCVE-2021-42125—An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to EPSS 81.6%CVE-2010-0094—Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18 and 5.0 Update 23 alEPSS 81.6%CVE-2019-9513HIGHSome HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceEPSS 81.6%CVE-2023-31099HIGHZoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.EPSS 81.6%CVE-2019-17602—An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injectiEPSS 81.5%CVE-2009-1185—udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senEPSS 81.5%CVE-2007-0774—Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web ServEPSS 81.5%CVE-2017-17090—An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified AsEPSS 81.5%CVE-2019-10092—In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could EPSS 81.5%CVE-2016-2098—Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary RubEPSS 81.4%CVE-2016-5734—phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the pEPSS 81.4%CVE-2003-0344—Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) charactersEPSS 81.3%CVE-2003-0822—Buffer overflow in the debug functionality in fp30reg.dll of Microsoft FrontPage Server Extensions (FPSE) 2000 and 2002 allows remote attackEPSS 81.3%