CSV
14,880 results for "vulnerability" Page 1
CVE-2014-6271 CRITICAL KEV Exploit

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

Sep 24, 2014 334 affected product(s) NVD
9.8
CVSS
94.2%
EPSS
⚡ 97.5
CVE-2009-1151 CRITICAL KEV Exploit

Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.

Mar 26, 2009 4 affected product(s) NVD
9.8
CVSS
93.3%
EPSS
⚡ 97.2
CVE-2015-5119 CRITICAL KEV Exploit

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

Jul 8, 2015 20 affected product(s) NVD
9.8
CVSS
93.2%
EPSS
⚡ 97.2
CVE-2011-3544 CRITICAL KEV Exploit

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting.

Oct 19, 2011 98 affected product(s) NVD
9.8
CVSS
92.5%
EPSS
⚡ 97
CVE-2015-0311 CRITICAL KEV Exploit

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

Jan 23, 2015 9 affected product(s) NVD
9.8
CVSS
92.6%
EPSS
⚡ 97
CVE-2015-0313 CRITICAL KEV Exploit

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Feb 2, 2015 12 affected product(s) NVD
9.8
CVSS
92.5%
EPSS
⚡ 97
CVE-2015-5122 CRITICAL KEV Exploit

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

Jul 14, 2015 19 affected product(s) NVD
9.8
CVSS
92.7%
EPSS
⚡ 97
CVE-2010-0840 CRITICAL KEV Exploit

Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, and 1.4.2_25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the March 2010 CPU. Oracle has not commented on claims from a reliable researcher that this is related to improper checks when executing privileged methods in the Java Runtime Environment (JRE), which allows attackers to execute arbitrary code via (1) an untrusted object that extends the trusted class but has not modified a certain method, or (2) "a similar trust issue with interfaces," aka "Trusted Methods Chaining Remote Code Execution Vulnerability."

Apr 1, 2010 10 affected product(s) NVD
9.8
CVSS
92.1%
EPSS
⚡ 96.8
CVE-2011-2462 CRITICAL KEV Exploit

Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, and Adobe Reader 9.x through 9.4.6 on UNIX, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unknown vectors, as exploited in the wild in December 2011.

Dec 7, 2011 3 affected product(s) NVD
9.8
CVSS
91.5%
EPSS
⚡ 96.7
CVE-2013-2729 CRITICAL KEV Exploit

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

May 16, 2013 15 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 96.1
CVE-2013-3346 CRITICAL KEV Exploit

Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.

Aug 30, 2013 6 affected product(s) NVD
9.8
CVSS
89.6%
EPSS
⚡ 96.1
CVE-2014-0780 CRITICAL KEV Exploit

Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests.

Apr 25, 2014 3 affected product(s) NVD
9.8
CVSS
89.2%
EPSS
⚡ 96
CVE-2014-7169 CRITICAL KEV Exploit

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271.

Sep 25, 2014 334 affected product(s) NVD
9.8
CVSS
89.1%
EPSS
⚡ 95.9
CVE-2011-1889 CRITICAL KEV Exploit

The NSPLookupServiceNext function in the client in Microsoft Forefront Threat Management Gateway (TMG) 2010 allows remote attackers to execute arbitrary code via vectors involving unspecified requests, aka "TMG Firewall Client Memory Corruption Vulnerability."

Jun 16, 2011 1 affected product(s) NVD
9.8
CVSS
88.1%
EPSS
⚡ 95.6
CVE-2015-3043 CRITICAL KEV Exploit

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than CVE-2015-0347, CVE-2015-0350, CVE-2015-0352, CVE-2015-0353, CVE-2015-0354, CVE-2015-0355, CVE-2015-0360, CVE-2015-3038, CVE-2015-3041, and CVE-2015-3042.

Apr 14, 2015 19 affected product(s) NVD
9.8
CVSS
87.4%
EPSS
⚡ 95.4
CVE-2012-3152 CRITICAL KEV Exploit

Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Report Server Component. NOTE: the previous information is from the October 2012 CPU. Oracle has not commented on claims from the original researcher that the URLPARAMETER functionality allows remote attackers to read and upload arbitrary files to reports/rwservlet, and that this issue occurs in earlier versions. NOTE: this can be leveraged with CVE-2012-3153 to execute arbitrary code by uploading a .jsp file.

Oct 16, 2012 3 affected product(s) NVD
9.1
CVSS
93.5%
EPSS
⚡ 94.5
CVE-2015-4068 CRITICAL KEV Exploit

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of service via a crafted file path to the (1) reportFileServlet or (2) exportServlet servlet.

May 29, 2015 2 affected product(s) NVD
9.1
CVSS
80.4%
EPSS
⚡ 90.5
CVE-2012-1710 CRITICAL KEV Exploit

Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Designer, a different vulnerability than CVE-2012-1709.

May 3, 2012 1 affected product(s) NVD
9.8
CVSS
40.8%
EPSS
⚡ 81.5
CVE-2014-2323 CRITICAL Exploit

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

Mar 14, 2014 9 affected product(s) NVD
9.8
CVSS
91.0%
EPSS
⚡ 76.5
CVE-2008-0081 CRITICAL Exploit

Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.

Jan 16, 2008 5 affected product(s) NVD
9.8
CVSS
81.8%
EPSS
⚡ 73.7
Page 1 of 744 Next →