Vulnerabilities in N/A
159,958 resultsCVE-2009-3867—Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before EPSS 73.4%CVE-2013-0758—Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before EPSS 73.4%CVE-2008-0621—Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to execute arbitrary cEPSS 73.4%CVE-2023-34260—Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed EPSS 73.4%CVE-2011-3026—Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly haEPSS 73.3%CVE-2004-0362—Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various ReEPSS 73.3%CVE-2015-3183—The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remotEPSS 73.3%CVE-2011-3389—The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, OpEPSS 73.3%CVE-2014-7868—Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remoEPSS 73.3%CVE-2019-12169—ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathname in a ZIP archive tEPSS 73.3%CVE-2024-37383MEDIUMRoundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 allows XSS via SVG animate attributes.EPSS 73.3%KEVCVE-2016-7202—The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cauEPSS 73.3%CVE-2022-34265—An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL inEPSS 73.3%CVE-2020-24881—SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.EPSS 73.3%CVE-2007-5067—Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long If-Modified-Since heEPSS 73.2%CVE-2018-1000130—A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java cEPSS 73.2%CVE-2006-3838—Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) SideEPSS 73.1%CVE-2021-25281—An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus,EPSS 73.1%CVE-2021-28958—Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing the password.EPSS 73.1%CVE-2017-11467—OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackeEPSS 73.1%