Vulnerabilities in n/a

160,988 results
CVE-2020-25111—An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header length. This leads to DEPSS 20.9%CVE-2020-10827CRITICALA stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieveEPSS 20.9%CVE-2013-0633—Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x bEPSS 20.9%CVE-2014-7859—Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-32EPSS 20.9%CVE-2020-10828CRITICALA stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieveEPSS 20.9%CVE-2016-0128—The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, WiEPSS 20.9%CVE-2007-1306—Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending a Session InitiationEPSS 20.9%CVE-2006-7065—Microsoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL styleEPSS 20.9%CVE-2013-1317—Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggerEPSS 20.9%CVE-2012-2521—Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code EPSS 20.9%CVE-2023-28130HIGHLocal user may lead to privilege escalation using Gaia Portal hostnames page.EPSS 20.9%CVE-2016-3271—The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, akEPSS 20.9%CVE-2023-0830MEDIUMEasyNAS backup.pl system os command injectionEPSS 20.9%CVE-2014-2908—Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x allows remote attacEPSS 20.9%CVE-2015-2408—Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) EPSS 20.9%CVE-2005-1250—SQL injection vulnerability in the logon screen of the web front end (NmConsole/Login.asp) for IpSwitch WhatsUp Professional 2005 SP1 allowsEPSS 20.9%CVE-2020-15893—An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 19EPSS 20.9%CVE-2003-0909—Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe EPSS 20.9%CVE-2004-0933—Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure EPSS 20.9%CVE-2011-2383—Microsoft Internet Explorer 9 and earlier does not properly restrict cross-zone drag-and-drop actions, which allows user-assisted remote attEPSS 20.8%