Vulnerabilities (CVE)
1,704 pages, showing 201–300, ordered by identifier.
- CVE-2015-7755 — Juniper ScreenOS Improper Authentication Vulnerability Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote...
- CVE-2015-8651 — Adobe Flash Player Integer Overflow Vulnerability Integer overflow in Adobe Flash Player allows attackers to execute code.
- CVE-2016-0034 — Microsoft Silverlight Runtime Remote Code Execution Vulnerability Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or...
- CVE-2016-0040 — Microsoft Windows Kernel Privilege Escalation Vulnerability The kernel in Microsoft Windows allows local users to gain privileges via a crafted application.
- CVE-2016-0099 — Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to...
- CVE-2016-0151 — Microsoft Windows CSRSS Security Feature Bypass Vulnerability The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to...
- CVE-2016-0162 — Microsoft Internet Explorer Information Disclosure Vulnerability An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The...
- CVE-2016-0165 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2016-0167 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
- CVE-2016-0185 — Microsoft Windows Media Center Remote Code Execution Vulnerability Microsoft Windows Media Center contains a remote code execution vulnerability when Windows Media Center opens a...
- CVE-2016-0189 — Microsoft Internet Explorer Memory Corruption Vulnerability The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to...
- CVE-2016-0752 — Ruby on Rails Directory Traversal Vulnerability Directory traversal vulnerability in Action View in Ruby on Rails allows remote attackers to read arbitrary files.
- CVE-2016-0984 — Adobe Flash Player and AIR Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.
- CVE-2016-10033 — PHPMailer Command Injection Vulnerability PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically,...
- CVE-2016-1010 — Adobe Flash Player and AIR Integer Overflow Vulnerability Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.
- CVE-2016-10174 — NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability The NETGEAR WNR2000v5 router contains a buffer overflow which can be exploited to achieve remote code execution.
- CVE-2016-1019 — Adobe Flash Player Arbitrary Code Execution Vulnerability Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
- CVE-2016-11021 — D-Link DCS-930L Devices OS Command Injection Vulnerability setSystemCommand on D-Link DCS-930L devices allows a remote attacker to execute code via an OS command.
- CVE-2016-1555 — NETGEAR Multiple WAP Devices Command Injection Vulnerability Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the...
- CVE-2016-1646 — Google Chromium V8 Out-of-Bounds Read Vulnerability Google Chromium V8 Engine contains an out-of-bounds read vulnerability that allows a remote attacker to cause a...
- CVE-2016-20017 — D-Link DSL-2750B Devices Command Injection Vulnerability D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command...
- CVE-2016-2386 — SAP NetWeaver SQL Injection Vulnerability SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute...
- CVE-2016-2388 — SAP NetWeaver Information Disclosure Vulnerability The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user...
- CVE-2016-3088 — Apache ActiveMQ Improper Input Validation Vulnerability The Fileserver web application in Apache ActiveMQ allows remote attackers to upload and execute arbitrary files via...
- CVE-2016-3235 — Microsoft Office OLE DLL Side Loading Vulnerability Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability...
- CVE-2016-3298 — Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects...
- CVE-2016-3309 — Microsoft Windows Kernel Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An...
- CVE-2016-3351 — Microsoft Internet Explorer and Edge Information Disclosure Vulnerability An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge...
- CVE-2016-3393 — Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory....
- CVE-2016-3427 — Oracle Java SE and JRockit Unspecified Vulnerability Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect...
- CVE-2016-3643 — SolarWinds Virtualization Manager Privilege Escalation Vulnerability SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.
- CVE-2016-3714 — ImageMagick Improper Input Validation Vulnerability ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT,...
- CVE-2016-3715 — ImageMagick Arbitrary File Deletion Vulnerability ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's...
- CVE-2016-3718 — ImageMagick Server-Side Request Forgery (SSRF) Vulnerability ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery...
- CVE-2016-3976 — SAP NetWeaver Directory Traversal Vulnerability SAP NetWeaver Application Server Java Platforms contains a directory traversal vulnerability via a .. (dot dot...
- CVE-2016-4117 — Adobe Flash Player Arbitrary Code Execution Vulnerability An access of resource using incompatible type vulnerability exists within Adobe Flash Player that allows an attacker...
- CVE-2016-4171 — Adobe Flash Player Remote Code Execution Vulnerability Unspecified vulnerability in Adobe Flash Player allows for remote code execution.
- CVE-2016-4437 — Apache Shiro Code Execution Vulnerability Apache Shiro contains a vulnerability which may allow remote attackers to execute code or bypass intended access...
- CVE-2016-4523 — Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability The WAP interface in Trihedral VTScada (formerly VTS) allows remote attackers to cause a denial-of-service (DoS).
- CVE-2016-4655 — Apple iOS Information Disclosure Vulnerability The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.
- CVE-2016-4656 — Apple iOS Memory Corruption Vulnerability A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or...
- CVE-2016-4657 — Apple iOS Webkit Memory Corruption Vulnerability Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a...
- CVE-2016-5195 — Linux Kernel Race Condition Vulnerability Race condition in mm/gup.c in the Linux kernel allows local users to escalate privileges.
- CVE-2016-5198 — Google Chromium V8 Out-of-Bounds Memory Vulnerability Google Chromium V8 Engine contains an out-of-bounds memory access vulnerability that allows a remote attacker to...
- CVE-2016-6277 — NETGEAR Multiple Routers Remote Code Execution Vulnerability NETGEAR confirmed multiple routers allow unauthenticated web pages to pass form input directly to the command-line...
- CVE-2016-6366 — Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could...
- CVE-2016-6367 — Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local...
- CVE-2016-6415 — Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet...
- CVE-2016-7193 — Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability which can allow for remote code execution.
- CVE-2016-7200 — Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a...
- CVE-2016-7201 — Microsoft Edge Memory Corruption Vulnerability The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a...
- CVE-2016-7255 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege...
- CVE-2016-7256 — Microsoft Windows Open Type Font Remote Code Execution Vulnerability A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted...
- CVE-2016-7262 — Microsoft Office Security Feature Bypass Vulnerability A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who...
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in...
- CVE-2016-7855 — Adobe Flash Player Use-After-Free Vulnerability Use-after-free vulnerability in Adobe Flash Player Windows and OS and Linux allows remote attackers to execute...
- CVE-2016-7892 — Adobe Flash Player Use-After-Free Vulnerability Adobe Flash Player has an exploitable use-after-free vulnerability in the TextField class.
- CVE-2016-8562 — Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability An improper privilege management vulnerability exists within the Siemens SIMATIC Communication Processor (CP) that...
- CVE-2016-8735 — Apache Tomcat Remote Code Execution Vulnerability Apache Tomcat contains an unspecified vulnerability that allows for remote code execution if...
- CVE-2016-9079 — Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting...
- CVE-2016-9563 — SAP NetWeaver XML External Entity (XXE) Vulnerability SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows...
- CVE-2017-0001 — Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7...
- CVE-2017-0005 — Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.
- CVE-2017-0022 — Microsoft XML Core Services Information Disclosure Vulnerability Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on...
- CVE-2017-0037 — Microsoft Edge and Internet Explorer Type Confusion Vulnerability Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution.
- CVE-2017-0059 — Microsoft Internet Explorer Information Disclosure Vulnerability Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted...
- CVE-2017-0101 — Microsoft Windows Transaction Manager Privilege Escalation Vulnerability A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
- CVE-2017-0143 — Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code...
- CVE-2017-0144 — Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via...
- CVE-2017-0145 — Microsoft SMBv1 Remote Code Execution Vulnerability The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via...
- CVE-2017-0146 — Microsoft Windows SMB Remote Code Execution Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
- CVE-2017-0147 — Microsoft Windows SMBv1 Information Disclosure Vulnerability The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory...
- CVE-2017-0148 — Microsoft SMBv1 Server Remote Code Execution Vulnerability The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
- CVE-2017-0149 — Microsoft Internet Explorer Memory Corruption Vulnerability Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code...
- CVE-2017-0199 — Microsoft Office and WordPad Remote Code Execution Vulnerability Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially...
- CVE-2017-0210 — Microsoft Internet Explorer Privilege Escalation Vulnerability A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies,...
- CVE-2017-0213 — Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted...
- CVE-2017-0222 — Microsoft Internet Explorer Remote Code Execution Vulnerability A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory.
- CVE-2017-0261 — Microsoft Office Use-After-Free Vulnerability Microsoft Office contains a use-after-free vulnerability which can allow for remote code execution.
- CVE-2017-0262 — Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office.
- CVE-2017-0263 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to...
- CVE-2017-1000253 — Linux Kernel PIE Stack Buffer Corruption Vulnerability Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in loadelf...
- CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer...
- CVE-2017-1000486 — Primetek Primefaces Remote Code Execution Vulnerability Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution
- CVE-2017-10271 — Oracle Corporation WebLogic Server Remote Code Execution Vulnerability Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution.
- CVE-2017-11292 — Adobe Flash Player Type Confusion Vulnerability Adobe Flash Player contains a type confusion vulnerability which can allow for remote code execution.
- CVE-2017-11317 — Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or...
- CVE-2017-11357 — Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can...
- CVE-2017-11774 — Microsoft Office Outlook Security Feature Bypass Vulnerability Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in...
- CVE-2017-11826 — Microsoft Office Remote Code Execution Vulnerability A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle...
- CVE-2017-11882 — Microsoft Office Memory Corruption Vulnerability Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the...
- CVE-2017-12149 — Red Hat JBoss Application Server Remote Code Execution Vulnerability The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to...
- CVE-2017-12231 — Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an...
- CVE-2017-12232 — Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2)...
- CVE-2017-12233 — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could...
- CVE-2017-12234 — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could...
- CVE-2017-12235 — Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS...
- CVE-2017-12237 — Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an...
- CVE-2017-12238 — Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches...
- CVE-2017-12240 — Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.