Vulnerabilidades en n/a

160.832 resultados
CVE-2016-10372—The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP portEPSS 81.8%CVE-2015-7871—Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication.EPSS 81.8%CVE-2023-50868HIGHThe Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denEPSS 81.7%CVE-2015-1868—The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) ServerEPSS 81.7%CVE-2012-2763—Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, alloEPSS 81.7%CVE-2014-8516—Unrestricted file upload vulnerability in Visual Mining NetCharts Server allows remote attackers to execute arbitrary code by uploading a fiEPSS 81.7%CVE-2010-3971—Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in EPSS 81.7%CVE-2014-4114HIGHMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, andEPSS 81.6%KEVCVE-2021-42125—An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to EPSS 81.6%CVE-2024-46538CRITICALA cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadEPSS 81.6%CVE-2019-9513HIGHSome HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of serviceEPSS 81.6%CVE-2023-31099HIGHZoho ManageEngine OPManager through 126323 allows an authenticated user to achieve remote code execution via probe servers.EPSS 81.6%CVE-2019-17602—An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injectiEPSS 81.5%CVE-2009-1185—udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by senEPSS 81.5%CVE-2007-0774—Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web ServEPSS 81.5%CVE-2017-17090—An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and older, and Certified AsEPSS 81.5%CVE-2019-10092—In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could EPSS 81.5%CVE-2016-2098—Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary RubEPSS 81.4%CVE-2018-5955—An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attackerEPSS 81.4%CVE-2010-2883HIGHStack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allowsEPSS 81.4%KEV