Vulnerabilities in N/A
160,154 resultsCVE-2008-4687—manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort parameter containing PHP EPSS 67.5%CVE-1999-0612—A version of finger is running that exposes valid user information to any entity on the network.EPSS 67.4%CVE-2016-1909—Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.EPSS 67.4%CVE-2006-1652—Multiple buffer overflows in (a) UltraVNC (aka Ultr@VNC) 1.0.1 and earlier and (b) tabbed_viewer 1.29 (1) allow user-assisted remote attackeEPSS 67.4%CVE-2020-26124—openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.EPSS 67.4%CVE-2012-2953—The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted inputEPSS 67.4%CVE-2004-1626—Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR commaEPSS 67.4%CVE-2017-8895—In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerEPSS 67.4%CVE-2006-6251—Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file,EPSS 67.3%CVE-2006-2086—Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE deEPSS 67.3%CVE-2010-1681—Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary codeEPSS 67.3%CVE-2012-1451—The CAB file parser in Emsisoft Anti-Malware 5.1.0.1 and Ikarus Virus Utilities T3 Command Line Scanner 1.1.97.0 allows remote attackers to EPSS 67.3%CVE-2015-7765—ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser account, which allowsEPSS 67.3%CVE-2015-0802—Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, whicEPSS 67.3%CVE-2007-5208—hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent attackers to execute EPSS 67.3%CVE-2012-0694—SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitraryEPSS 67.3%CVE-2016-7237—Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, WindowEPSS 67.3%CVE-2014-6593—Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4 allowEPSS 67.2%CVE-2007-5003—Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.5 alEPSS 67.2%CVE-2011-1473—OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, wEPSS 67.2%