CSV
36,917 results for "vulnerability" Page 1
CVE-2009-0927 HIGH KEV Exploit

Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.

Mar 19, 2009 3 affected product(s) NVD
8.8
CVSS
93.8%
EPSS
⚡ 93.3
CVE-2009-3953 HIGH KEV Exploit

The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than CVE-2009-2994.

Jan 13, 2010 8 affected product(s) NVD
8.8
CVSS
90.5%
EPSS
⚡ 92.4
CVE-2010-0249 HIGH KEV Exploit

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object, related to incorrectly initialized memory and improper handling of objects in memory, as exploited in the wild in December 2009 and January 2010 during Operation Aurora, aka "HTML Object Memory Corruption Vulnerability."

Jan 15, 2010 5 affected product(s) NVD
8.8
CVSS
88.8%
EPSS
⚡ 91.8
CVE-2010-0188 HIGH KEV Exploit

Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

Feb 22, 2010 4 affected product(s) NVD
7.8
CVSS
93.6%
EPSS
⚡ 89.3
CVE-2009-4324 HIGH KEV Exploit

Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.

Dec 15, 2009 9 affected product(s) NVD
7.8
CVSS
92.9%
EPSS
⚡ 89.1
CVE-2009-3129 HIGH KEV Exploit

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset, aka "Excel Featheader Record Memory Corruption Vulnerability."

Nov 11, 2009 10 affected product(s) NVD
7.8
CVSS
91.2%
EPSS
⚡ 88.6
CVE-2009-0557 HIGH KEV Exploit

Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Object Record Corruption Vulnerability."

Jun 10, 2009 14 affected product(s) NVD
7.8
CVSS
86.4%
EPSS
⚡ 87.1
CVE-2009-0563 HIGH KEV Exploit

Stack-based buffer overflow in Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 2008; Open XML File Format Converter for Mac; Microsoft Office Word Viewer 2003 SP3; Microsoft Office Word Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a Word document with a crafted tag containing an invalid length field, aka "Word Buffer Overflow Vulnerability."

Jun 10, 2009 12 affected product(s) NVD
7.8
CVSS
79.9%
EPSS
⚡ 85.2
CVE-2010-0232 HIGH KEV Exploit

The kernel in Microsoft Windows NT 3.1 through Windows 7, including Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, and Windows Server 2008 Gold and SP2, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges by crafting a VDM_TIB data structure in the Thread Environment Block (TEB), and then calling the NtVdmControl function to start the Windows Virtual DOS Machine (aka NTVDM) subsystem, leading to improperly handled exceptions involving the #GP trap handler (nt!KiTrap0D), aka "Windows Kernel Exception Handler Vulnerability."

Jan 21, 2010 4 affected product(s) NVD
7.8
CVSS
75.5%
EPSS
⚡ 83.9
CVE-2009-1862 HIGH KEV Exploit

Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via (1) a crafted Flash application in a .pdf file or (2) a crafted .swf file, related to authplay.dll, as exploited in the wild in July 2009.

Jul 23, 2009 4 affected product(s) NVD
7.8
CVSS
58.6%
EPSS
⚡ 78.8
CVE-2009-1123 HIGH KEV Exploit

The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Desktop Vulnerability."

Jun 10, 2009 8 affected product(s) NVD
7.8
CVSS
5.2%
EPSS
⚡ 62.8
CVE-2010-0258 HIGH Exploit

Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code via a crafted spreadsheet that causes memory to be interpreted as a different object type than intended, aka "Microsoft Office Excel Sheet Object Type Confusion Vulnerability."

Mar 10, 2010 13 affected product(s) NVD
7.8
CVSS
71.4%
EPSS
⚡ 62.6
CVE-2009-0231 HIGH

The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data record that triggers an integer truncation and a heap-based buffer overflow, aka "Embedded OpenType Font Heap Overflow Vulnerability."

Jul 15, 2009 11 affected product(s) NVD
8.8
CVSS
65.0%
EPSS
⚡ 54.7
CVE-2008-0077 HIGH

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, aka "Property Memory Corruption Vulnerability."

Feb 12, 2008 3 affected product(s) NVD
8.8
CVSS
62.3%
EPSS
⚡ 53.9
CVE-2008-3475 HIGH

Microsoft Internet Explorer 6 does not properly handle errors related to using the componentFromPoint method on xml objects that have been (1) incorrectly initialized or (2) deleted, which allows remote attackers to execute arbitrary code via a crafted HTML document, aka "Uninitialized Memory Corruption Vulnerability."

Oct 15, 2008 4 affected product(s) NVD
8.8
CVSS
59.2%
EPSS
⚡ 53
CVE-2010-0050 HIGH

Use-after-free vulnerability in WebKit in Apple Safari before 4.0.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an HTML document with improperly nested tags.

Mar 15, 2010 10 affected product(s) NVD
8.8
CVSS
46.4%
EPSS
⚡ 49.1
CVE-2009-3658 HIGH

Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.

Oct 9, 2009 1 affected product(s) NVD
8.8
CVSS
22.0%
EPSS
⚡ 41.8
CVE-2003-1048 HIGH

Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.

Jul 27, 2004 18 affected product(s) NVD
7.8
CVSS
33.2%
EPSS
⚡ 41.2
CVE-2009-0244 HIGH

Directory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mobile 5.0 for Pocket PC and 5.0 for Pocket PC Phone Edition, allows remote authenticated users to list arbitrary directories, and create or read arbitrary files, via a .. (dot dot) in a pathname. NOTE: this can be leveraged for code execution by writing to a Startup folder.

Jan 21, 2009 6 affected product(s) NVD
8.8
CVSS
17.4%
EPSS
⚡ 40.4
CVE-2010-0378 HIGH

Use-after-free vulnerability in Adobe Flash Player 6.0.79, as distributed in Microsoft Windows XP SP2 and SP3, allows remote attackers to execute arbitrary code by unloading a Flash object that is currently being accessed by a script, leading to memory corruption, aka a "Movie Unloading Vulnerability."

Jan 21, 2010 1 affected product(s) NVD
8.8
CVSS
13.8%
EPSS
⚡ 39.3
Page 1 of 1846 Next →