Skip to content
Noroxi

CWE-19 · 232 records

Data Processing Errors

CVEs in this class

232 records

  • CVE-2016-3236
    62This week

    The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP

    CriticalCVSS 9.8WeaponizedEPSS 77%

    microsoft · windows 10Jun 15, 2016

  • When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_t

    HighCVSS 8.8Proof of conceptEPSS 79%

    pivotal · spring security oauthMay 25, 2017

  • Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remot

    CriticalCVSS 9.8WeaponizedEPSS 68%

    ektron · ektron content management systemOct 30, 2017

  • named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa

    HighCVSS 7.8WeaponizedEPSS 91%

    isc · bindJul 29, 2015

  • A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mo

    HighCVSS 7.8WeaponizedEPSS 74%

    siemens · siprotec firmwareJul 18, 2015

  • BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attack

    HighCVSS 8.1No exploitEPSS 70%

    beanshell · beanshellApr 7, 2016

  • The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to e

    CriticalCVSS 10.0No exploitEPSS 38%

    microsoft · windows 7Jul 14, 2015

  • Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers

    CriticalCVSS 9.3Proof of conceptEPSS 41%

    microsoft · excelMar 11, 2015

  • The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea

    MediumCVSS 6.4No exploitEPSS 76%

    squid-cache · squidNov 26, 2014

  • Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W

    HighCVSS 8.8Proof of conceptEPSS 42%

    microsoft · windows 10Dec 20, 2016

  • The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 G

    HighCVSS 8.8No exploitEPSS 39%

    microsoft · windows 10Dec 20, 2016

  • ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo

    CriticalCVSS 9.3Proof of conceptEPSS 30%

    microsoft · windows 7Aug 14, 2015

  • Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to exec

    CriticalCVSS 9.8No exploitEPSS 24%

    linux · linux kernelOct 10, 2016

  • wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers

    MediumCVSS 5.0Proof of conceptEPSS 83%

    wordpress · wordpressNov 25, 2014

  • Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s

    CriticalCVSS 9.8No exploitEPSS 20%

    drupal · drupalAug 6, 2018

  • Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind

    CriticalCVSS 9.3Proof of conceptEPSS 24%

    microsoft · windows 7Mar 11, 2015

  • The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item

    HighCVSS 7.5Proof of conceptEPSS 41%

    net-snmp · net-snmpAug 19, 2015

  • Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offi

    CriticalCVSS 9.3No exploitEPSS 16%

    microsoft · office compatibility packJun 9, 2015

  • Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrar

    CriticalCVSS 9.3No exploitEPSS 16%

    microsoft · officeJun 9, 2015

  • Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion

    CriticalCVSS 9.8No exploitEPSS 9%

    exim · eximJul 25, 2019

  • Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.

    CriticalCVSS 10.0No exploitEPSS 6%

    microsoft · windows ntJan 1, 1999

  • Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro

    CriticalCVSS 10.0No exploitEPSS 5%

    justsystems · ichitaroNov 25, 2014

  • The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary cod

    HighCVSS 8.8No exploitEPSS 19%

    microsoft · windows 10Dec 20, 2016

  • Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v

    CriticalCVSS 9.3No exploitEPSS 13%

    microsoft · internet explorerJun 9, 2015

  • The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via

    CriticalCVSS 9.8No exploitEPSS 7%

    apache · camelFeb 3, 2016

All vulnerability classes