11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2007-6332
Software Genérico Windows
N/A
UNKNOWN
EPSS
18.1%
2007 1 PoC

The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 in HP Quick Launch Button (QLBCTRL.exe, aka QLB) 6.3 and earlier, on Microsoft Windows before Vista allows remote attackers to create or modify arbitrary registry values via the arguments to the SetRegValue method.

CVE-2007-0040
Software Genérico Windows
N/A
UNKNOWN
EPSS
61.3%
2007 1 PoC

The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted LDAP request with an unspecified number of "convertible attributes."

CVE-2014-4932
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the val parameter to whois.php.

CVE-2015-6522
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
79.8%
2015 2 PoCs

SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the size parameter to get_album_item.php.

CVE-2017-13784
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
21.4%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-17740
Software Genérico Windows
N/A
UNKNOWN
EPSS
6.1%
2017 2 PoCs

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

CVE-2017-7805
Firefox Windows
N/A
UNKNOWN
EPSS
3.2%
2017 1 PoC

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVE-2017-12544
System Management Homepage for Windows and Linux Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
59.9%
2017 1 PoC

A cross-site scripting vulnerability in HPE System Management Homepage for Windows and Linux version prior to v7.6.1 was found.

CVE-2017-18530
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
0.1%
2017 0 PoCs

The rating-bws plugin before 0.2 for WordPress has multiple XSS issues.

CVE-2017-8682
Windows graphics Windows
N/A
UNKNOWN
EPSS
66.0%
2017 1 PoC

Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, Windows Server 2016, Microsoft Office Word Viewer, Microsoft Office 2007 Service Pack 3 , and Microsoft Office 2010 Service Pack 2 allows an attacker to execute remote code by the way it handles embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8683.

CVE-2017-18499
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The simple-membership plugin before 3.5.7 for WordPress has XSS.

CVE-2015-6678
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.8%
2015 3 PoCs

Buffer overflow in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-6676.

CVE-2017-18559
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The cforms2 plugin before 14.13.3 for WordPress has multiple XSS issues.

CVE-2017-6883
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2017 1 PoC

The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vulnerability could lead to information disclosure; an attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVE-2017-7043
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
3.5%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-13798
Software Genérico Cloud Windows
N/A
UNKNOWN
EPSS
12.5%
2017 1 PoC

An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud before 7.1 on Windows is affected. iTunes before 12.7.1 on Windows is affected. tvOS before 11.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2017-8471
Microsoft Windows Windows
N/A
UNKNOWN
EPSS
7.7%
2017 1 PoC

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an authenticated attacker to run a specially crafted application when the Windows kernel improperly initializes objects in memory, aka "Win32k Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8470, CVE-2017-8472, CVE-2017-8473, CVE-2017-8475, CVE-2017-8477, and CVE-2017-8484.

CVE-2017-18608
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

The spotim-comments plugin before 4.0.4 for WordPress has multiple XSS issues.

CVE-2017-14722
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
30.5%
2017 1 PoC

Before version 4.8.2, WordPress allowed a Directory Traversal attack in the Customizer component via a crafted theme filename.

CVE-2017-0346
GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.0%
2017 1 PoC

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.