Vulnerabilidades en n/a

160.915 resultados
CVE-2015-2995—The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote attackers to upload anEPSS 33.6%CVE-2017-7588—On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempEPSS 33.6%CVE-2015-0071MEDIUMMicrosoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "InternEPSS 33.6%KEVCVE-2010-5299—Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl file. NOTE: it has bEPSS 33.6%CVE-2021-31761—Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's running process featurEPSS 33.6%CVE-2016-3215—Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive inforEPSS 33.6%CVE-2015-2444—Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) EPSS 33.6%CVE-2009-0076—Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the zoom style directivEPSS 33.5%CVE-2013-3111—Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) EPSS 33.5%CVE-2000-0711—Netscape Communicator does not properly prevent a ServerSocket object from being created by untrusted entities, which allows remote attackerEPSS 33.5%CVE-2018-11690—The Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper valiEPSS 33.5%CVE-2022-48194HIGHTP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoSEPSS 33.5%CVE-2020-13921—**Resolved** Only when using H2/MySQL/TiDB as Apache SkyWalking storage, there is a SQL injection vulnerability in the wildcard query cases.EPSS 33.5%CVE-2016-0971—Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.2EPSS 33.5%CVE-2015-0050—Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via aEPSS 33.5%CVE-2022-38545—Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a EPSS 33.5%CVE-2017-16885—Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining information about Internet UsEPSS 33.5%CVE-2000-0673—The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sendiEPSS 33.4%CVE-2008-2069—Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in EPSS 33.4%CVE-2021-32607—An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHEPSS 33.4%