11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2015-1614
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption] parameter in an update action in the image_metadata_cruncher_title page to wp-admin/options.php or (3) custom image meta tag to the image metadata cruncher page.

CVE-2017-8751
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
54.0%
2017 1 PoC

Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.

CVE-2017-9419
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.

CVE-2018-5284
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.

CVE-2018-5366
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.

CVE-2019-1343
Windows Server Windows
N/A
UNKNOWN
EPSS
31.3%
2019 1 PoC

A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1346, CVE-2019-1347.

CVE-2018-14568
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

Suricata before 4.0.5 stops TCP stream inspection upon a TCP RST from a server. This allows detection bypass because Windows TCP clients proceed with normal processing of TCP data that arrives shortly after an RST (i.e., they act as if the RST had not yet been received).

CVE-2007-0221
Software Genérico Windows
N/A
UNKNOWN
EPSS
65.0%
2007 1 PoC

Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."

CVE-2004-1317
Software Genérico Windows
N/A
UNKNOWN
EPSS
77.8%
2004 3 PoCs

Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.

CVE-2004-0568
Software Genérico Windows
N/A
UNKNOWN
EPSS
26.9%
2004 1 PoC

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

CVE-2004-0123
Software Genérico Windows
N/A
UNKNOWN
EPSS
59.1%
2004 1 PoC

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVE-2004-1244
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.5%
2004 1 PoC

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

CVE-2004-0897
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.5%
2004 1 PoC

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVE-2014-8955
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.

CVE-2015-3088
Software Genérico Windows
N/A
UNKNOWN
EPSS
79.5%
2015 1 PoC

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2004-1361
Software Genérico Windows
N/A
UNKNOWN
EPSS
29.1%
2004 1 PoC

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

CVE-2004-0571
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.8%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.

CVE-2004-0201
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.7%
2004 1 PoC

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

CVE-2004-0211
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.9%
2004 2 PoCs

The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

CVE-2004-1305
Software Genérico Windows
N/A
UNKNOWN
EPSS
78.5%
2004 3 PoCs

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.