CSV
14,880 results for "vulnerability" Page 2
CVE-2014-6271 CRITICAL KEV Exploit

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Sep 24, 2014 334 affected product(s) NVD
9.8
CVSS
94.2%
EPSS
⚡ 97.5
CVE-2015-5119 CRITICAL KEV Exploit

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Jul 8, 2015 20 affected product(s) NVD
9.8
CVSS
93.2%
EPSS
⚡ 97.2
CVE-2015-0311 CRITICAL KEV Exploit

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

Jan 23, 2015 9 affected product(s) NVD
9.8
CVSS
92.6%
EPSS
⚡ 97
CVE-2015-0313 CRITICAL KEV Exploit

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Feb 2, 2015 12 affected product(s) NVD
9.8
CVSS
92.5%
EPSS
⚡ 97
CVE-2015-5122 CRITICAL KEV Exploit

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

Jul 14, 2015 19 affected product(s) NVD
9.8
CVSS
92.7%
EPSS
⚡ 97
CVE-2013-2729 CRITICAL KEV Exploit

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

May 16, 2013 15 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 96.1
CVE-2013-3346 CRITICAL KEV Exploit

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

Aug 30, 2013 6 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 96.1
CVE-2014-0780 CRITICAL KEV Exploit

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

Apr 25, 2014 3 affected product(s) NVD
9.8
CVSS
89.2%
EPSS
⚡ 96
CVE-2014-7169 CRITICAL KEV Exploit

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Sep 25, 2014 334 affected product(s) NVD
9.8
CVSS
89.1%
EPSS
⚡ 95.9
CVE-2015-3043 CRITICAL KEV Exploit

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

Apr 14, 2015 19 affected product(s) NVD
9.8
CVSS
87.4%
EPSS
⚡ 95.4
CVE-2012-3152 CRITICAL KEV Exploit

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.

Oct 16, 2012 3 affected product(s) NVD
9.1
CVSS
93.5%
EPSS
⚡ 94.5
CVE-2015-4068 CRITICAL KEV Exploit

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

May 29, 2015 2 affected product(s) NVD
9.1
CVSS
80.4%
EPSS
⚡ 90.5
CVE-2015-2590 CRITICAL KEV Exploit

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Jul 16, 2015 71 affected product(s) NVD
9.8
CVSS
66.6%
EPSS
⚡ 89.2
CVE-2012-1710 CRITICAL KEV Exploit

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.

May 3, 2012 1 affected product(s) NVD
9.8
CVSS
40.8%
EPSS
⚡ 81.5
CVE-2015-5123 CRITICAL KEV Exploit

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Jul 14, 2015 16 affected product(s) NVD
9.8
CVSS
41.0%
EPSS
⚡ 81.5
CVE-2014-2323 CRITICAL Exploit

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

Mar 14, 2014 9 affected product(s) NVD
9.8
CVSS
91.0%
EPSS
⚡ 76.5
CVE-2016-0854 CRITICAL Exploit

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

Jan 15, 2016 1 affected product(s) NVD
9.8
CVSS
72.2%
EPSS
⚡ 70.8
CVE-2015-8617 CRITICAL

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.

Jan 19, 2016 1 affected product(s) NVD
9.8
CVSS
21.9%
EPSS
⚡ 45.8
CVE-2015-6792 CRITICAL

The MIDI subsystem in Google Chrome before 47.0.2526.106 does not properly handle the sending of data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, related to midi_manager.cc, midi_manager_alsa.cc, and midi_manager_mac.cc, a different vulnerability than CVE-2015-8664.

Dec 24, 2015 1 affected product(s) NVD
9.8
CVSS
19.7%
EPSS
⚡ 45.1
CVE-2013-5613 CRITICAL

Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.

Dec 11, 2013 28 affected product(s) NVD
9.8
CVSS
11.1%
EPSS
⚡ 42.5