Vulnerabilities in N/A

159,958 results
CVE-2014-9295Multiple stack-based buffer overflows in ntpd in NTP before 4.2.8 allow remote attackers to execute arbitrary code via a crafted packet, relEPSS 78.1%CVE-2010-1587The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a /EPSS 78.0%CVE-2007-2139Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Media Server, as used EPSS 78.0%CVE-2019-16113Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and thEPSS 78.0%CVE-2013-6221Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server iEPSS 77.9%CVE-2016-2108The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a deniaEPSS 77.9%CVE-2021-41951ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_sso/pages/index.php viEPSS 77.9%CVE-2013-1347HIGHMicrosoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessiEPSS 77.9%KEVCVE-2014-5005Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute arbitrarEPSS 77.8%CVE-2019-12840In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the datEPSS 77.8%CVE-2014-0113CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClaEPSS 77.8%CVE-2017-1000117A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL can result in any progEPSS 77.8%CVE-2020-13562CRITICALA cross-site scripting vulnerability exists in the template functionality of phpGACL 3.3.7. A specially crafted HTTP request can lead to arbEPSS 77.7%CVE-2019-15949HIGHNagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as tEPSS 77.7%KEVCVE-2008-3466Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attaEPSS 77.7%CVE-2020-36227A flaw was discovered in OpenLDAP before 2.4.57 leading to an infinite loop in slapd with the cancel_extop Cancel operation, resulting in deEPSS 77.7%CVE-2020-36222A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial EPSS 77.7%CVE-2012-1440The ELF file parser in Norman Antivirus 6.06.12, eSafe 7.0.17.0, CA eTrust Vet Antivirus 36.1.8511, Fortinet Antivirus 4.2.254.0, and Panda EPSS 77.7%CVE-2010-0842Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4.2_25, and 1.3.1_27 EPSS 77.7%CVE-2008-2639Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows remote attackers to exeEPSS 77.7%