11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2015-1614
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

Multiple cross-site request forgery (CSRF) vulnerabilities in the Image Metadata Cruncher plugin for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) image_metadata_cruncher[alt] or (2) image_metadata_cruncher[caption] parameter in an update action in the image_metadata_cruncher_title page to wp-admin/options.php or (3) custom image meta tag to the image metadata cruncher page.

CVE-2017-8751
Microsoft Edge Windows
N/A
UNKNOWN
EPSS
54.0%
2017 1 PoC

Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8731, CVE-2017-8734, and CVE-2017-11766.

CVE-2017-9419
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2017 1 PoC

Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.

CVE-2013-2205
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.6%
2013 1 PoC

The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site.

CVE-2004-1317
Software Genérico Windows
N/A
UNKNOWN
EPSS
77.8%
2004 3 PoCs

Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attackers to execute arbitrary code via a long DNS command.

CVE-2018-8786
FreeRDP Windows
N/A
UNKNOWN
EPSS
9.6%
2018 CWE-680 2 PoCs

FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.

CVE-2004-0568
Software Genérico Windows
N/A
UNKNOWN
EPSS
26.9%
2004 1 PoC

HyperTerminal application for Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003 does not properly validate the length of a value that is saved in a session file, which allows remote attackers to execute arbitrary code via a malicious HyperTerminal session file (.ht), web site, or Telnet URL contained in an e-mail message, triggering a buffer overflow.

CVE-2004-0123
Software Genérico Windows
N/A
UNKNOWN
EPSS
59.1%
2004 1 PoC

Double free vulnerability in the ASN.1 library as used in Windows NT 4.0, Windows 2000, Windows XP, and Windows Server 2003, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

CVE-2004-1244
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.5%
2004 1 PoC

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

CVE-2004-0897
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.5%
2004 1 PoC

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

CVE-2014-8955
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.2%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in the Contact Form Clean and Simple (clean-and-simple-contact-form-by-meg-nicholas) plugin 4.4.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the cscf[name] parameter to contact-us/.

CVE-2015-3088
Software Genérico Windows
N/A
UNKNOWN
EPSS
79.5%
2015 1 PoC

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 17.0.0.172, Adobe AIR SDK before 17.0.0.172, and Adobe AIR SDK & Compiler before 17.0.0.172 allows attackers to execute arbitrary code via unspecified vectors.

CVE-2004-1361
Software Genérico Windows
N/A
UNKNOWN
EPSS
29.1%
2004 1 PoC

Integer underflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a malformed .hlp file, which leads to a heap-based buffer overflow.

CVE-2004-0571
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.8%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Table Conversion Vulnerability," a different vulnerability than CVE-2004-0901.

CVE-2004-0201
Software Genérico Windows
N/A
UNKNOWN
EPSS
50.7%
2004 1 PoC

Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.

CVE-2004-0211
Software Genérico Windows
N/A
UNKNOWN
EPSS
2.9%
2004 2 PoCs

The kernel for Microsoft Windows Server 2003 does not reset certain values in CPU data structures, which allows local users to cause a denial of service (system crash) via a malicious program.

CVE-2004-1305
Software Genérico Windows
N/A
UNKNOWN
EPSS
78.5%
2004 3 PoCs

The Windows Animated Cursor (ANI) capability in Windows NT, Windows 2000 through SP4, Windows XP through SP1, and Windows 2003 allow remote attackers to cause a denial of service via (1) the frame number set to zero, which causes an invalid memory address to be used and leads to a kernel crash, or (2) the rate number set to zero, which leads to resource exhaustion and hang.

CVE-2004-0117
Software Genérico Windows
N/A
UNKNOWN
EPSS
52.5%
2004 3 PoCs

Unknown vulnerability in the H.323 protocol implementation in Windows 98, Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code.

CVE-2004-0839
Software Genérico Windows
N/A
UNKNOWN
EPSS
42.0%
2004 2 PoCs

Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".

CVE-2015-9445
Software Genérico Web Database Windows
N/A
UNKNOWN
EPSS
0.3%
2015 2 PoCs

The unite-gallery-lite plugin before 1.5 for WordPress has CSRF and SQL injection via wp-admin/admin-ajax.php in a unitegallery_ajax_action operation.