Vulnerabilities (CVE)
1,704 pages, showing 101–200, ordered by identifier.
- CVE-2013-2251 — Apache Struts Improper Input Validation Vulnerability Apache Struts allows remote attackers to execute arbitrary Object-Graph Navigation Language (OGNL) expressions.
- CVE-2013-2423 — Oracle JRE Unspecified Vulnerability Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
- CVE-2013-2465 — Oracle Java SE Unspecified Vulnerability Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE allows remote attackers...
- CVE-2013-2551 — Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a...
- CVE-2013-2596 — Linux Kernel Integer Overflow Vulnerability Linux kernel fb_mmap function in drivers/video/fbmem.c contains an integer overflow vulnerability that allows for...
- CVE-2013-2597 — Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability The Code Aurora audio calibration database (acdb) audio driver contains a stack-based buffer overflow vulnerability...
- CVE-2013-2729 — Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Reader and Acrobat allows attackers to execute remote code.
- CVE-2013-3163 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code...
- CVE-2013-3346 — Adobe Reader and Acrobat Memory Corruption Vulnerability Adobe Reader and Acrobat contain a memory corruption vulnerability which can allow attackers to execute arbitrary...
- CVE-2013-3660 — Microsoft Win32k Privilege Escalation Vulnerability The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly...
- CVE-2013-3893 — Microsoft Internet Explorer Resource Management Errors Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The...
- CVE-2013-3896 — Microsoft Silverlight Information Disclosure Vulnerability Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote...
- CVE-2013-3897 — Microsoft Internet Explorer Use-After-Free Vulnerability A use-after-free vulnerability exists within CDisplayPointer in Microsoft Internet Explorer that allows an attacker...
- CVE-2013-3900 — Microsoft WinVerifyTrust function Remote Code Execution A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows...
- CVE-2013-3906 — Microsoft Graphics Component Memory Corruption Vulnerability Microsoft Graphics Component contains a memory corruption vulnerability which can allow for remote code execution.
- CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX...
- CVE-2013-3993 — IBM InfoSphere BigInsights Invalid Input Vulnerability Certain APIs within BigInsights can take invalid input that might allow attackers unauthorized access to read,...
- CVE-2013-4810 — HP Multiple Products Remote Code Execution Vulnerability HP ProCurve Manager (PCM), PCM+, Identity Driven Manager (IDM), and Application Lifecycle Management allow remote...
- CVE-2013-5065 — Microsoft Windows Kernel Privilege Escalation Vulnerability Microsoft Windows NDProxy.sys in the kernel contains an improper input validation vulnerability which can allow a...
- CVE-2013-5223 — D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability A cross-site scripting (XSS) vulnerability exists in the D-Link DSL-2760U gateway, allowing remote authenticated...
- CVE-2013-6282 — Linux Kernel Improper Input Validation Vulnerability The getuser and putuser API functions of the Linux kernel fail to validate the target address when being used on ARM...
- CVE-2013-7331 — Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists in Internet Explorer which allows resources loaded into memory to be...
- CVE-2014-0130 — Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render...
- CVE-2014-0160 — OpenSSL Information Disclosure Vulnerability The TLS and DTLS implementations in OpenSSL do not properly handle Heartbeat Extension packets, which allows remote...
- CVE-2014-0196 — Linux Kernel Race Condition Vulnerability Linux Kernel contains a race condition vulnerability within the nttywrite function that allows local users to cause...
- CVE-2014-0322 — Microsoft Internet Explorer Use-After-Free Vulnerability Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute code.
- CVE-2014-0496 — Adobe Reader and Acrobat Use-After-Free Vulnerability Adobe Reader and Acrobat contain a use-after-free vulnerability which can allow for code execution.
- CVE-2014-0497 — Adobe Flash Player Integer Underflow Vulnerablity Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.
- CVE-2014-0502 — Adobe Flash Player Double Free Vulnerablity Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.
- CVE-2014-0546 — Adobe Reader and Acrobat Sandbox Bypass Vulnerability Adobe Reader and Acrobat on Windows allow attackers to bypass a sandbox protection mechanism, and consequently...
- CVE-2014-0780 — InduSoft Web Studio NTWebServer Directory Traversal Vulnerability InduSoft Web Studio NTWebServer contains a directory traversal vulnerability that allows remote attackers to read...
- CVE-2014-100005 — D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change...
- CVE-2014-1761 — Microsoft Word Memory Corruption Vulnerability Microsoft Word contains a memory corruption vulnerability which when exploited could allow for remote code execution.
- CVE-2014-1776 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code...
- CVE-2014-1812 — Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes...
- CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login...
- CVE-2014-2817 — Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer cotains an unspecified vulnerability that allows remote attackers to gain privileges via...
- CVE-2014-3120 — Elasticsearch Remote Code Execution Vulnerability Elasticsearch enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code.
- CVE-2014-3153 — Linux Kernel Privilege Escalation Vulnerability The futex_requeue function in kernel/futex.c in Linux kernel does not ensure that calls have two different futex...
- CVE-2014-3931 — Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to...
- CVE-2014-4077 — Microsoft IME Japanese Privilege Escalation Vulnerability Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows...
- CVE-2014-4113 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2014-4114 — Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability A vulnerability exists in Windows Object Linking & Embedding (OLE) that could allow remote code execution if a user...
- CVE-2014-4123 — Microsoft Internet Explorer Privilege Escalation Vulnerability Microsoft Internet Explorer contains an unspecified vulnerability that allows remote attackers to gain privileges...
- CVE-2014-4148 — Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows kernel-mode driver improperly handles TrueType fonts.
- CVE-2014-4404 — Apple OS X Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow in IOHIDFamily in Apple OS X, which affects, iOS before 8 and Apple TV before 7, allows...
- CVE-2014-6271 — GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables,...
- CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands...
- CVE-2014-6287 — Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (HFS or HttpFileServer) allows remote...
- CVE-2014-6324 — Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability The Kerberos Key Distribution Center (KDC) in Microsoft allows remote authenticated domain users to obtain domain...
- CVE-2014-6332 — Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability OleAut32.dll in OLE in Microsoft Windows allows remote attackers to remotely execute code via a crafted web site.
- CVE-2014-6352 — Microsoft Windows Code Injection Vulnerability Microsoft Windows allow remote attackers to execute arbitrary code via a crafted OLE object.
- CVE-2014-7169 — GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables,...
- CVE-2014-8361 — Realtek SDK Improper Input Validation Vulnerability Realtek SDK contains an improper input validation vulnerability in the miniigd SOAP service that allows remote...
- CVE-2014-8439 — Adobe Flash Player Dereferenced Pointer Vulnerability Adobe Flash Player has a vulnerability in the way it handles a dereferenced memory pointer which could lead to code...
- CVE-2014-9163 — Adobe Flash Player Stack-Based Buffer Overflow Vulnerability Stack-based buffer overflow in Adobe Flash Player allows attackers to execute code remotely.
- CVE-2015-0016 — Microsoft Windows TS WebProxy Directory Traversal Vulnerability Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote...
- CVE-2015-0071 — Microsoft Internet Explorer ASLR Bypass Vulnerability Microsoft Internet Explorer allows remote attackers to bypass the address space layout randomization (ASLR)...
- CVE-2015-0310 — Adobe Flash Player ASLR Bypass Vulnerability Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the...
- CVE-2015-0311 — Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute code.
- CVE-2015-0313 — Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player allows remote attackers to execute code.
- CVE-2015-0666 — Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows...
- CVE-2015-1130 — Apple OS X Authentication Bypass Vulnerability The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication...
- CVE-2015-1187 — D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to perform remote code execution.
- CVE-2015-1427 — Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability The Groovy scripting engine in Elasticsearch allows remote attackers to bypass the sandbox protection mechanism and...
- CVE-2015-1635 — Microsoft HTTP.sys Remote Code Execution Vulnerability Microsoft HTTP protocol stack (HTTP.sys) contains a vulnerability that allows for remote code execution.
- CVE-2015-1641 — Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files...
- CVE-2015-1642 — Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote attackers to execute arbitrary code...
- CVE-2015-1671 — Microsoft Windows Remote Code Execution Vulnerability A remote code execution vulnerability exists when components of Windows, .NET Framework, Office, Lync, and...
- CVE-2015-1701 — Microsoft Win32k Privilege Escalation Vulnerability An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a...
- CVE-2015-1769 — Microsoft Windows Mount Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Mount Manager component improperly processes symbolic links.
- CVE-2015-1770 — Microsoft Office Uninitialized Memory Use Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted Office document.
- CVE-2015-2051 — D-Link DIR-645 Router Remote Code Execution Vulnerability D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings...
- CVE-2015-2291 — Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that...
- CVE-2015-2360 — Microsoft Win32k Privilege Escalation Vulnerability Win32k.sys in the kernel-mode drivers in Microsoft Windows allows local users to gain privileges or cause...
- CVE-2015-2387 — Microsoft ATM Font Driver Privilege Escalation Vulnerability ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server allows local users to gain privileges...
- CVE-2015-2419 — Microsoft Internet Explorer Memory Corruption Vulnerability JScript in Microsoft Internet Explorer allows remote attackers to execute remote code or cause a denial of service...
- CVE-2015-2424 — Microsoft PowerPoint Memory Corruption Vulnerability Microsoft PowerPoint allows remote attackers to execute arbitrary code or cause a denial of service (memory...
- CVE-2015-2425 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code...
- CVE-2015-2426 — Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library...
- CVE-2015-2502 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows an attacker to execute code or...
- CVE-2015-2545 — Microsoft Office Malformed EPS File Vulnerability Microsoft Office allows remote attackers to execute arbitrary code via a crafted EPS image.
- CVE-2015-2546 — Microsoft Win32k Memory Corruption Vulnerability The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
- CVE-2015-2590 — Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability An unspecified vulnerability exists within Oracle Java Runtime Environment that allows an attacker to perform remote...
- CVE-2015-3035 — TP-Link Multiple Archer Devices Directory Traversal Vulnerability Directory traversal vulnerability in multiple TP-Link Archer devices allows remote attackers to read arbitrary files...
- CVE-2015-3043 — Adobe Flash Player Memory Corruption Vulnerability A memory corruption vulnerability exists in Adobe Flash Player that allows an attacker to perform remote code execution.
- CVE-2015-3113 — Adobe Flash Player Heap-Based Buffer Overflow Vulnerability Heap-based buffer overflow vulnerability in Adobe Flash Player allows remote attackers to execute code.
- CVE-2015-3246 — Red Hat Libuser Race Condition Vulnerability Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the...
- CVE-2015-4068 — Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability Directory traversal vulnerability in Arcserve UDP allows remote attackers to obtain sensitive information or cause a...
- CVE-2015-4495 — Mozilla Firefox Security Feature Bypass Vulnerability Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.
- CVE-2015-4852 — Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can...
- CVE-2015-4902 — Oracle Java SE Integrity Check Vulnerability Unspecified vulnerability in Oracle Java SE allows remote attackers to affect integrity via Unknown vectors related...
- CVE-2015-5119 — Adobe Flash Player Use-After-Free Vulnerability A use-after-free vulnerability exists within the ActionScript 3 ByteArray class in Adobe Flash Player that allows an...
- CVE-2015-5122 — Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash...
- CVE-2015-5123 — Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash...
- CVE-2015-5287 — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local...
- CVE-2015-5317 — Jenkins User Interface (UI) Information Disclosure Vulnerability Jenkins User Interface (UI) contains an information disclosure vulnerability that allows users to see the names of...
- CVE-2015-6175 — Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows contains a vulnerability that allows local users to gain privileges via a crafted...
- CVE-2015-7450 — IBM WebSphere Application Server and Server Hypervisor Edition Code Injection. Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile...
- CVE-2015-7645 — Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.