CSV
14,719 results for "vulnerability" Page 3
CVE-2016-2386 CRITICAL KEV Exploit

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Feb 16, 2016 1 affected product(s) NVD
9.8
CVSS
71.1%
EPSS
⚡ 90.5
CVE-2015-2590 CRITICAL KEV Exploit

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.

Jul 16, 2015 71 affected product(s) NVD
9.8
CVSS
25.5%
EPSS
⚡ 76.8
CVE-2015-5123 CRITICAL KEV Exploit

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Jul 14, 2015 16 affected product(s) NVD
9.8
CVSS
18.5%
EPSS
⚡ 74.7
CVE-2016-0854 CRITICAL Exploit

Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vectors.

Jan 15, 2016 1 affected product(s) NVD
9.8
CVSS
77.0%
EPSS
⚡ 72.3
CVE-2016-2842 CRITICAL

The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.

Mar 3, 2016 32 affected product(s) NVD
9.8
CVSS
53.7%
EPSS
⚡ 55.3
CVE-2016-0003 CRITICAL

Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."

Jan 13, 2016 1 affected product(s) NVD
9.6
CVSS
38.0%
EPSS
⚡ 49.8
CVE-2016-0799 CRITICAL

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

Mar 3, 2016 35 affected product(s) NVD
9.8
CVSS
32.4%
EPSS
⚡ 48.9
CVE-2016-0705 CRITICAL

Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.

Mar 3, 2016 61 affected product(s) NVD
9.8
CVSS
26.3%
EPSS
⚡ 47.1
CVE-2015-8617 CRITICAL

Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allows remote attackers to execute arbitrary code via format string specifiers in a string that is misused as a class name, leading to incorrect error handling.

Jan 19, 2016 1 affected product(s) NVD
9.8
CVSS
22.8%
EPSS
⚡ 46
CVE-2016-0951 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-0952 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-0953 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-1988 CRITICAL

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.

Mar 15, 2016 5 affected product(s) NVD
9.8
CVSS
10.6%
EPSS
⚡ 42.4
CVE-2015-8459 CRITICAL

Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-8460, CVE-2015-8636, and CVE-2015-8645.

Dec 28, 2015 11 affected product(s) NVD
10.0
CVSS
6.1%
EPSS
⚡ 41.8
CVE-2016-0746 CRITICAL

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.

Feb 15, 2016 9 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2016-0933 CRITICAL

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0931, CVE-2016-0936, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, and CVE-2016-0946.

Jan 14, 2016 32 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-1007 CRITICAL

Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1009.

Mar 9, 2016 6 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-1009 CRITICAL

Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1007.

Mar 9, 2016 6 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-1962 CRITICAL

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.

Mar 13, 2016 18 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-0940 CRITICAL

Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-0932, CVE-2016-0934, CVE-2016-0937, and CVE-2016-0941.

Jan 14, 2016 32 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8