11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2008-4734
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.4%
2008 2 PoCs

Cross-site request forgery (CSRF) vulnerability in the wpcr_do_options_page function in WP Comment Remix plugin before 1.4.4 for WordPress allows remote attackers to perform unauthorized actions as administrators via a request that sets the wpcr_hidden_form_input parameter.

CVE-2008-0063
Software Genérico Windows
N/A
UNKNOWN
EPSS
4.9%
2008 2 PoCs

The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."

CVE-2007-6543
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.5%
2007 1 PoC

SQL injection vulnerability in suggest-link.php in eSyndiCat Link Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2007-0069
Software Genérico Windows
N/A
UNKNOWN
EPSS
67.7%
2007 1 PoC

Unspecified vulnerability in the kernel in Microsoft Windows XP SP2, Server 2003, and Vista allows remote attackers to cause a denial of service (CPU consumption) and possibly execute arbitrary code via crafted (1) IGMPv3 and (2) MLDv2 packets that trigger memory corruption, aka "Windows Kernel TCP/IP/IGMPv3 and MLDv2 Vulnerability."

CVE-2007-0933
Software Genérico Windows
N/A
UNKNOWN
EPSS
38.0%
2007 1 PoC

Buffer overflow in the wireless driver 6.0.0.18 for D-Link DWL-G650+ (Rev. A1) on Windows XP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a beacon frame with a long TIM Information Element.

CVE-2014-4561
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2014 0 PoCs

The ultimate-weather plugin 1.0 for WordPress has XSS

CVE-2015-8433
Software Genérico Windows
N/A
UNKNOWN
EPSS
12.9%
2015 3 PoCs

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler before 20.0.0.204 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-8048, CVE-2015-8049, CVE-2015-8050, CVE-2015-8055, CVE-2015-8056, CVE-2015-8057, CVE-2015-8058, CVE-2015-8059, CVE-2015-8061, CVE-2015-8062, CVE-2015-8063, CVE-2015-8064, CVE-2015-8065, CVE-2015-8066, CVE-2015-8067, CVE-2015

CVE-2023-2256
Product Addons & Fields for WooCommerce Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
21.2%
2023 1 PoC

The Product Addons & Fields for WooCommerce WordPress plugin before 32.0.7 does not sanitize and escape some URL parameters, leading to Reflected Cross-Site Scripting.

CVE-2008-4278
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2008 1 PoC

VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.

CVE-2008-3009
Software Genérico Windows
N/A
UNKNOWN
EPSS
52.3%
2008 1 PoC

Microsoft Windows Media Player 6.4, Windows Media Format Runtime 7.1 through 11, and Windows Media Services 4.1, 9, and 2008 do not properly use the Service Principal Name (SPN) identifier when validating replies to authentication requests, which allows remote servers to execute arbitrary code via vectors that employ NTLM credential reflection, aka "SPN Vulnerability."

CVE-2008-1402
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.8%
2008 1 PoC

MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (exception and crash) via a UDP packet to the SNMP Trap Service (MgWTrap3.exe) or (2) denial of service (device freeze or memory consumption) via a malformed request to the Net Inspector Server (niengine).

CVE-2008-0490
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.8%
2008 1 PoC

SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2008-1280
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.4%
2008 1 PoC

Acronis True Image Windows Agent 1.0.0.54 and earlier, included in Acronis True Image Enterprise Server 9.5.0.8072 and the other True Image packages, allows remote attackers to cause a denial of service (crash) via a malformed packet to port 9876, which triggers a NULL pointer dereference.

CVE-2008-6938
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
73.7%
2008 1 PoC

Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi3, allows remote attackers to cause a denial of service (crash or hang) and obtain the full pathname of the server via a request to a file in the ISAPI directory that is not an executable DLL, which triggers the crash when the DLL load fails, as demonstrated using Isapi\users.txt.

CVE-2008-2894
Software Genérico Windows
N/A
UNKNOWN
EPSS
3.2%
2008 1 PoC

Directory traversal vulnerability in the FTP client in NCH Software Classic FTP 1.02 for Windows allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.

CVE-2008-1337
Software Genérico Windows
N/A
UNKNOWN
EPSS
1.2%
2008 3 PoCs

The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message.

CVE-2015-5541
Software Genérico Windows
N/A
UNKNOWN
EPSS
9.5%
2015 3 PoCs

Heap-based buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-5129.

CVE-2023-2605
wpbrutalai Web Windows
N/A
UNKNOWN
EPSS
0.2%
2023 2 PoCs

The wpbrutalai WordPress plugin before 2.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a logged in high privilege users such as admin.

CVE-2008-0107
Software Genérico Database Windows
N/A
UNKNOWN
EPSS
57.3%
2008 3 PoCs

Integer underflow in SQL Server 7.0 SP4, 2000 SP4, 2005 SP1 and SP2, 2000 Desktop Engine (MSDE 2000) SP4, 2005 Express Edition SP1 and SP2, and 2000 Desktop Engine (WMSDE); Microsoft Data Engine (MSDE) 1.0 SP4; and Internal Database (WYukon) SP2 allows remote authenticated users to execute arbitrary code via a (1) SMB or (2) WebDAV pathname for an on-disk file (aka stored backup file) with a crafted record size value, which triggers a heap-based buffer overflow, aka "SQL Server Memory Corruption Vulnerability."

CVE-2008-1118
Software Genérico Windows
N/A
UNKNOWN
EPSS
10.8%
2008 2 PoCs

Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.