11328 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2004-0069
Software Genérico Windows
N/A
UNKNOWN
EPSS
8.3%
2004 2 PoCs

Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the username, which is processed by the wscanf function.

CVE-2004-2289
Software Genérico Windows
N/A
UNKNOWN
EPSS
12.1%
2004 2 PoCs

Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.

CVE-2018-6356
Software Genérico DevOps Windows
N/A
UNKNOWN
EPSS
31.6%
2018 1 PoC

Jenkins before 2.107 and Jenkins LTS before 2.89.4 did not properly prevent specifying relative paths that escape a base directory for URLs accessing plugin resource files. This allowed users with Overall/Read permission to download files from the Jenkins master they should not have access to. On Windows, any file accessible to the Jenkins master process could be downloaded. On other operating systems, any file within the Jenkins home directory accessible to the Jenkins master process could be downloaded.

CVE-2023-5610
Seraphinite Accelerator Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The Seraphinite Accelerator WordPress plugin before 2.2.29 does not validate the URL to redirect any authenticated user to, leading to an arbitrary redirect

CVE-2018-3285
MySQL Server Database Windows
N/A
UNKNOWN
EPSS
0.3%
2018 1 PoC

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Windows). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2014-8622
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-value parameter.

CVE-2004-0901
Software Genérico Windows
N/A
UNKNOWN
EPSS
36.2%
2004 1 PoC

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font Conversion Vulnerability," a different vulnerability than CVE-2004-0571.

CVE-2004-0727
Software Genérico Windows
N/A
UNKNOWN
EPSS
57.6%
2004 1 PoC

Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows remote web servers to bypass zone restrictions and execute arbitrary code in the local computer zone by redirecting a function to another function with the same name, as demonstrated by SimilarMethodNameRedir, aka the "Similar Method Name Redirection Cross Domain Vulnerability."

CVE-2023-4933
WP Job Openings Web Windows
N/A
UNKNOWN
EPSS
0.1%
2023 1 PoC

The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.

CVE-2004-0686
Software Genérico Windows
N/A
UNKNOWN
EPSS
11.6%
2004 1 PoC

Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.

CVE-2004-0569
Software Genérico Windows
N/A
UNKNOWN
EPSS
21.0%
2004 1 PoC

The RPC Runtime Library for Microsoft Windows NT 4.0 allows remote attackers to read active memory or cause a denial of service (system crash) via a malicious message, possibly related to improper length values.

CVE-2004-0899
Software Genérico Windows
N/A
UNKNOWN
EPSS
37.3%
2004 1 PoC

The DHCP Server service for Microsoft Windows NT 4.0 Server and Terminal Server Edition, with DHCP logging enabled, does not properly validate the length of certain messages, which allows remote attackers to cause a denial of service (application crash) via a malformed DHCP message, aka "Logging Vulnerability."

CVE-2004-0883
Software Genérico Windows
N/A
UNKNOWN
EPSS
15.4%
2004 2 PoCs

Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for

CVE-2007-3038
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
30.6%
2007 1 PoC

The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka "Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability."

CVE-2014-8087
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the post highlights plugin before 2.6.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the txt parameter in a headline action to ajax/ph_save.php.

CVE-2015-9388
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.1%
2015 1 PoC

The mtouch-quiz plugin before 3.1.3 for WordPress has wp-admin/edit.php CSRF with resultant XSS.

CVE-2004-0772
Software Genérico Windows
N/A
UNKNOWN
EPSS
5.0%
2004 1 PoC

Double free vulnerabilities in error handling code in krb524d for MIT Kerberos 5 (krb5) 1.2.8 and earlier may allow remote attackers to execute arbitrary code.

CVE-2004-1306
Software Genérico Windows
N/A
UNKNOWN
EPSS
48.0%
2004 1 PoC

Heap-based buffer overflow in winhlp32.exe in Windows NT, Windows 2000 through SP4, Windows XP through SP2, and Windows 2003 allows remote attackers to execute arbitrary code via a crafted .hlp file.

CVE-2004-1089
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.1%
2004 1 PoC

Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.

CVE-2004-0523
Software Genérico Windows
N/A
UNKNOWN
EPSS
25.9%
2004 1 PoC

Multiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as root.