Vulnerabilities in N/A
160,161 resultsCVE-2015-0816—Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes EPSS 66.9%CVE-2013-7260—Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow rEPSS 66.9%CVE-2018-18778—ACME mini_httpd before 1.30 lets remote users read arbitrary files.EPSS 66.9%CVE-2012-2962—SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenEPSS 66.8%CVE-2006-5112—Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.EPSS 66.8%CVE-2011-0609HIGHUnspecified vulnerability in Adobe Flash Player 10.2.154.13 and earlier on Windows, Mac OS X, Linux, and Solaris; 10.1.106.16 and earlier onEPSS 66.8%KEVCVE-2013-1571—Unspecified vulnerability in the Javadoc component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 andEPSS 66.8%CVE-2014-0239—The internal DNS server in Samba 4.x before 4.0.18 does not check the QR field in the header section of an incoming DNS message before sendiEPSS 66.8%CVE-2005-4267—Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP command that ends wiEPSS 66.8%CVE-2007-1404—tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not prEPSS 66.7%CVE-2006-1016—Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, EPSS 66.7%CVE-2015-2049—Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated users to execute arbitrEPSS 66.7%CVE-2023-28126MEDIUMAn authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploitinEPSS 66.7%CVE-2010-2551—The SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate an inEPSS 66.6%CVE-2017-18044—A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing functionEPSS 66.6%CVE-2024-57726CRITICALSimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with exceEPSS 66.6%KEVCVE-2002-1120—Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.EPSS 66.6%CVE-2013-3576—ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacteEPSS 66.6%CVE-2015-6133—Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library lEPSS 66.6%CVE-2006-5650—The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via tEPSS 66.6%