11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2009-3563
Software Genérico Windows
N/A
UNKNOWN
EPSS
81.1%
2009 1 PoC

ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

CVE-2023-3139
Protect WP Admin Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.4%
2023 1 PoC

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

CVE-2009-4748
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2009 1 PoC

SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.

CVE-2008-1440
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.6%
2008 1 PoC

Microsoft Windows XP SP2 and SP3, and Server 2003 SP1 and SP2, does not properly validate the option length field in Pragmatic General Multicast (PGM) packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted PGM packet, aka the "PGM Invalid Length Vulnerability."

CVE-2014-4535
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

CVE-2015-9481
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.5%
2015 1 PoC

The ThemeMakers Diplomat | Political theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.

CVE-2008-3274
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.7%
2008 1 PoC

The default configuration of Red Hat Enterprise IPA 1.0.0 and FreeIPA before 1.1.1 places ldap:///anyone on the read ACL for the krbMKey attribute, which allows remote attackers to obtain the Kerberos master key via an anonymous LDAP query.

CVE-2008-3851
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
7.4%
2008 2 PoCs

Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute arbitrary local files via a ..\ (dot dot backslash) in the (1) blogpost, (2) cat, and (3) file parameters to data/inc/themes/predefined_variables.php, as reachable through index.php; and the (4) blogpost and (5) cat parameters to data/inc/blog_include_react.php, as reachable through index.php. NOTE: the issue involving vectors 1 through 3 reportedly exists because of an incomplete fix for CVE-2008-3194.

CVE-2008-5715
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
8.5%
2008 2 PoCs

Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via JavaScript code with a long string value for the hash property (aka location.hash). NOTE: it was later reported that earlier versions are also affected, and that the impact is CPU consumption and application hang in unspecified circumstances perhaps involving other platforms.

CVE-2008-4844
Software Genérico Windows
N/A
UNKNOWN
EPSS
82.8%
2008 6 PoCs

Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.

CVE-2008-0087
Software Genérico Windows
N/A
UNKNOWN
EPSS
55.7%
2008 2 PoCs

The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.

CVE-2008-4616
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
4.0%
2008 1 PoC

The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a shared key.

CVE-2008-2747
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2008 1 PoC

No-IP Dynamic Update Client (DUC) 2.2.1 on Windows uses weak permissions for the HKLM\SOFTWARE\Vitalwerks\DUC registry key, which allows local users to obtain obfuscated passwords and other sensitive information by reading the (1) TrayPassword, (2) Username, (3) Password, and (4) Hosts registry values.

CVE-2008-3679
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.2%
2008 2 PoCs

Multiple cross-site scripting (XSS) vulnerabilities in index.php in IDevSpot PhpLinkExchange 1.01 allow remote attackers to inject arbitrary web script or HTML via the catid parameter in a (1) user_add, (2) recip, (3) tellafriend, or (4) contact action, or (5) in a request without an action; or (6) the id parameter in a tellafriend action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2015-9418
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The Watu Pro plugin before 4.9.0.8 for WordPress has CSRF that allows an attacker to delete quizzes.

CVE-2008-1801
Software Genérico Windows
N/A
UNKNOWN
EPSS
36.7%
2008 1 PoC

Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a Remote Desktop Protocol (RDP) request with a small length field.

CVE-2008-3008
Software Genérico Windows
N/A
UNKNOWN
EPSS
81.1%
2008 2 PoCs

Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9 Series allows remote attackers to execute arbitrary code via a long first argument to the GetDetailsString method, aka "Windows Media Encoder Buffer Overrun Vulnerability."

CVE-2008-3703
Software Genérico Windows
N/A
UNKNOWN
EPSS
24.5%
2008 1 PoC

The management console in the Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage Foundation for Windows (SFW) 5.0, 5.0 RP1a, and 5.1 accepts NULL NTLMSSP authentication, which allows remote attackers to execute arbitrary code via requests to the service socket that create "snapshots schedules" registry values specifying future command execution. NOTE: this issue exists because of an incomplete fix for CVE-2007-2279.

CVE-2008-6903
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.2%
2008 1 PoC

Sophos Anti-Virus for Windows before 7.6.3, Anti-Virus for Windows NT/9x before 4.7.18, Anti-Virus for OS X before 4.9.18, Anti-Virus for Linux before 6.4.5, Anti-Virus for UNIX before 7.0.5, Anti-Virus for Unix and Netware before 4.37.0, Sophos EM Library, and Sophos small business solutions, when CAB archive scanning is enabled, allows remote attackers to cause a denial of service (segmentation fault) via a "fuzzed" CAB archive file, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats.

CVE-2008-6101
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
1.0%
2008 3 PoCs

SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary SQL commands via the targetid parameter.