Vulnerabilities in n/a

161,014 results
CVE-2007-0356—The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attackers to cause a denialEPSS 17.6%CVE-2021-44207HIGHAcclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.EPSS 17.6%KEVCVE-2011-1993—Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code EPSS 17.6%CVE-2012-4787CRITICALUse-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web sitEPSS 17.6%CVE-2009-4009—Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute EPSS 17.6%CVE-2024-34218LOWTOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost functioEPSS 17.6%CVE-2016-7252—Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectorsEPSS 17.6%CVE-2011-2960—Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers to cause a denial of EPSS 17.6%CVE-2024-47855MEDIUMutil/JSONTokener.java in JSON-lib before 3.1.0 mishandles an unbalanced comment string.EPSS 17.6%CVE-2015-3897—Directory traversal vulnerability in Bonita BPM Portal before 6.5.3 allows remote attackers to read arbitrary files via a .. (dot dot) in thEPSS 17.6%CVE-2015-1605—Multiple SQL injection vulnerabilities in Dell ScriptLogic Asset Manager (aka Quest Workspace Asset Manager) before 9.5 allow remote attackeEPSS 17.6%CVE-2015-1728—Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "EPSS 17.6%CVE-2021-45420—Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgiEPSS 17.5%CVE-2022-31267—Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as anEPSS 17.5%CVE-1999-0469—Internet Explorer 5.0 allows window spoofing, allowing a remote attacker to spoof a legitimate web site and capture information from the cliEPSS 17.5%CVE-2019-6446—An issue was discovered in NumPy before 1.16.3. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrarEPSS 17.5%CVE-2018-18065—_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attEPSS 17.5%CVE-1999-1033—Microsoft Outlook Express before 4.72.3612.1700 allows a malicious user to send a message that contains a .., which can inadvertently cause EPSS 17.5%CVE-2014-0293—Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web sEPSS 17.5%CVE-2001-0719—Buffer overflow in Microsoft Windows Media Player 6.4 allows remote attackers to execute arbitrary code via a malformed Advanced Streaming FEPSS 17.5%