CVE Vulnerability Database

Search and browse 284 known security vulnerabilities. Filter by severity, vendor, product, and year.

284 vulnerabilities found
CVE-2010-0806
8.8 high

Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object, as exploited in the wild in March 2010, ak

Microsoft Internet Explorer Mar 10, 2010
CVE-2010-0386
8.1 high

The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.

Sun Java System Application Server Jan 25, 2010
CVE-2010-0249
8.8 high

Use-after-free vulnerability in Microsoft Internet Explorer 6, 6 SP1, 7, and 8 on Windows 2000 SP4; Windows XP SP2 and SP3; Windows Server 2003 SP2; Windows Vista Gold, SP1, and SP2; Windows Server 2008 Gold, SP2, and R2; and Windows 7 allows remote attackers to execute arbitrary code by accessing a

Microsoft Internet Explorer Jan 15, 2010
CVE-2009-3555
9.8 critical

The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple C

Apache Http Server Nov 9, 2009
CVE-2009-3459
8.8 high

Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attackers to execute arbitrary code via a crafted PDF file that triggers memory corruption, as exploited in the wild in October 2009. NOTE: some of these details are obtained f

Adobe Acrobat Oct 13, 2009
CVE-2009-2495
6.5 medium

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1 does not properly enforce string termination, which allows remote attackers to obtain sensitive information via a crafted HTML docum

Microsoft Visual C\+\+ Jul 29, 2009
CVE-2009-2493
8.8 high

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly re

Microsoft Visual C\+\+ Jul 29, 2009
CVE-2009-0901
8.8 high

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not prevent VariantClea

Microsoft Visual C\+\+ Jul 29, 2009
CVE-2009-1537
8.8 high

Unspecified vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow in Microsoft DirectX 7.0 through 9.0c on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2 allows remote attackers to execute arbitrary code via a crafted QuickTime media file, as exploited

Microsoft Directx May 29, 2009
CVE-2003-1567
7.5 high

The undocumented TRACK method in Microsoft Internet Information Services (IIS) 5.0 returns the content of the original request in the body of the response, which makes it easier for remote attackers to steal cookies and authentication credentials, or bypass the HttpOnly protection mechanism, by usin

Microsoft Internet Information Services Jan 15, 2009
CVE-2004-2761
9.8 critical

The MD5 Message-Digest Algorithm is not collision resistant, which makes it easier for context-dependent attackers to conduct spoofing attacks, as demonstrated by attacks on the use of MD5 in the signature algorithm of an X.509 certificate.

Ietf Md5 Jan 5, 2009
CVE-2008-5161
3.7 low

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; a

Openbsd Openssh Nov 19, 2008
CVE-2008-4309
7.5 high

Integer overflow in the netsnmp_create_subtree_cache function in agent/snmp_agent.c in net-snmp 5.4 before 5.4.2.1, 5.3 before 5.3.2.3, and 5.2 before 5.2.5.1 allows remote attackers to cause a denial of service (crash) via a crafted SNMP GETBULK request, which triggers a heap-based buffer overflow,

Net-Snmp Net-Snmp Oct 31, 2008
CVE-2008-4250
9.8 critical

The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by

Microsoft Windows 2000 Oct 23, 2008
CVE-2005-1794
6.4 medium

Microsoft Terminal Server using Remote Desktop Protocol (RDP) 5.2 stores an RSA private key in mstlsapi.dll and uses it to sign a certificate, which allows remote attackers to spoof public keys of legitimate servers and conduct man-in-the-middle attacks.

Microsoft Remote Desktop Connection Jun 1, 2005
CVE-2004-2320
5.3 medium

The default configuration of BEA WebLogic Server and Express 8.1 SP2 and earlier, 7.0 SP4 and earlier, 6.1 through SP6, and 5.1 through SP13 responds to the HTTP TRACE request, which can allow remote attackers to steal information using cross-site tracing (XST) attacks in applications that are vulne

Bea Weblogic Server Dec 31, 2004
CVE-1999-0632
7.3 high

The RPC portmapper service is running.

Jan 1, 1999
CVE-1999-0524
4.0 medium

ICMP information such as (1) netmask and (2) timestamp is allowed from arbitrary hosts.

Apple Mac Os X Aug 1, 1997
CVE-1999-0517
5.9 medium

An SNMP community name is the default (e.g. public), null, or missing.

Hp Hp-Ux Jan 1, 1997
CVE-1999-0511
9.1 critical

IP forwarding is enabled on a machine which is not a router or firewall.

Microsoft Windows 2000 Jan 1, 1997