Vulnerabilidades em n/a

160.988 resultados
CVE-2021-28113MEDIUMA command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (wiEPSS 22.3%CVE-2015-0032—vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 8 through 11 and other products, allows remote attackers EPSS 22.3%CVE-2011-4971—Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin_update, and (4) proEPSS 22.3%CVE-2016-1019HIGHAdobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitEPSS 22.3%KEVCVE-2017-14980—Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /loginEPSS 22.3%CVE-2016-3987—The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/opeEPSS 22.3%CVE-2014-2782—Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) EPSS 22.3%CVE-2011-0347—Microsoft Internet Explorer on Windows XP allows remote attackers to trigger an incorrect GUI display and have unspecified other impact via EPSS 22.3%CVE-2018-19365—The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specificalEPSS 22.3%CVE-2005-2371—Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", EPSS 22.3%CVE-2010-1717—Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attackers to read arbitraryEPSS 22.3%CVE-2020-13777—GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentEPSS 22.3%CVE-2012-0004—Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows EPSS 22.3%CVE-2019-16097—core/api/user.go in Harbor 1.7.0 through 1.8.2 allows non-admin users to create admin accounts via the POST /api/users API, when Harbor is sEPSS 22.3%CVE-2015-0019—Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via EPSS 22.3%CVE-2017-3077—Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image parser. Successful eEPSS 22.3%CVE-2001-1055—The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed ARP requEPSS 22.3%CVE-2002-1831—Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contEPSS 22.3%CVE-2014-6308—Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parEPSS 22.3%CVE-2010-3330MEDIUMMicrosoft Internet Explorer 6 through 8 does not properly restrict script access to content from a different (1) domain or (2) zone, which aEPSS 22.3%