CWE-19 · 232 records
Data Processing Errors
CVEs in this class
232 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
62This week | CVE-2016-3236Weaponized | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SPmicrosoft · windows 10 · CWE-19 | Critical9.8 | — | 76.8% | Jun 15, 2016 |
59Plan | CVE-2016-4977Proof of concept | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_tpivotal · spring security oauth · CWE-19 | High8.8 | — | 79.2% | May 25, 2017 |
59Plan | CVE-2012-5357Weaponized | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remotektron · ektron content management system · CWE-19 | Critical9.8 | — | 67.8% | Oct 30, 2017 |
58Plan | CVE-2015-5477Weaponized | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | High7.8 | — | 91.3% | Jul 29, 2015 |
53Plan | CVE-2015-5374Weaponized | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mosiemens · siprotec firmware · CWE-19 | High7.8 | — | 74.5% | Jul 18, 2015 |
53Plan | CVE-2016-2510No exploit | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackbeanshell · beanshell · CWE-19 | High8.1 | — | 70.4% | Apr 7, 2016 |
51Plan | CVE-2015-2373No exploit | The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to emicrosoft · windows 7 · CWE-19 | Critical10.0 | — | 38.1% | Jul 14, 2015 |
49Plan | CVE-2015-0097Proof of concept | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers microsoft · excel · CWE-19 | Critical9.3 | — | 40.9% | Mar 11, 2015 |
48Plan | CVE-2014-7141No exploit | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reasquid-cache · squid · CWE-19 | Medium6.4 | — | 76.1% | Nov 26, 2014 |
48Plan | CVE-2016-7274Proof of concept | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Wmicrosoft · windows 10 · CWE-19 | High8.8 | — | 42.5% | Dec 20, 2016 |
47Plan | CVE-2016-7272No exploit | The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gmicrosoft · windows 10 · CWE-19 | High8.8 | — | 39.3% | Dec 20, 2016 |
46Plan | CVE-2015-2432Proof of concept | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windomicrosoft · windows 7 · CWE-19 | Critical9.3 | — | 30.3% | Aug 14, 2015 |
46Plan | CVE-2016-7117No exploit | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execlinux · linux kernel · CWE-19 | Critical9.8 | — | 23.6% | Oct 10, 2016 |
45Plan | CVE-2014-9034Proof of concept | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Medium5.0 | — | 82.7% | Nov 25, 2014 |
45Plan | CVE-2017-6920No exploit | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Critical9.8 | — | 20.5% | Aug 6, 2018 |
44Plan | CVE-2015-0081Proof of concept | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windmicrosoft · windows 7 · CWE-19 | Critical9.3 | — | 23.8% | Mar 11, 2015 |
42Plan | CVE-2015-5621Proof of concept | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list itemnet-snmp · net-snmp · CWE-19 | High7.5 | — | 40.9% | Aug 19, 2015 |
42Plan | CVE-2015-1759No exploit | Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offimicrosoft · office compatibility pack · CWE-19 | Critical9.3 | — | 16.3% | Jun 9, 2015 |
42Plan | CVE-2015-1760No exploit | Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrarmicrosoft · office · CWE-19 | Critical9.3 | — | 16.3% | Jun 9, 2015 |
42Plan | CVE-2019-13917No exploit | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Critical9.8 | — | 8.6% | Jul 25, 2019 |
42Plan | CVE-1999-0226No exploit | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.microsoft · windows nt · CWE-19 | Critical10.0 | — | 5.9% | Jan 1, 1999 |
42Plan | CVE-2014-7247No exploit | Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro justsystems · ichitaro · CWE-19 | Critical10.0 | — | 5.3% | Nov 25, 2014 |
41Plan | CVE-2016-7273No exploit | The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary codmicrosoft · windows 10 · CWE-19 | High8.8 | — | 19.0% | Dec 20, 2016 |
41Plan | CVE-2015-1687No exploit | Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vmicrosoft · internet explorer · CWE-19 | Critical9.3 | — | 12.9% | Jun 9, 2015 |
41Plan | CVE-2015-5344No exploit | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via apache · camel · CWE-19 | Critical9.8 | — | 7.1% | Feb 3, 2016 |
- CVE-2016-323662This week
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP
CriticalCVSS 9.8WeaponizedEPSS 77%microsoft · windows 10Jun 15, 2016
- CVE-2016-497759Plan
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_t
HighCVSS 8.8Proof of conceptEPSS 79%pivotal · spring security oauthMay 25, 2017
- CVE-2012-535759Plan
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remot
CriticalCVSS 9.8WeaponizedEPSS 68%ektron · ektron content management systemOct 30, 2017
- CVE-2015-547758Plan
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
HighCVSS 7.8WeaponizedEPSS 91%isc · bindJul 29, 2015
- CVE-2015-537453Plan
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mo
HighCVSS 7.8WeaponizedEPSS 74%siemens · siprotec firmwareJul 18, 2015
- CVE-2016-251053Plan
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attack
HighCVSS 8.1No exploitEPSS 70%beanshell · beanshellApr 7, 2016
- CVE-2015-237351Plan
The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to e
CriticalCVSS 10.0No exploitEPSS 38%microsoft · windows 7Jul 14, 2015
- CVE-2015-009749Plan
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers
CriticalCVSS 9.3Proof of conceptEPSS 41%microsoft · excelMar 11, 2015
- CVE-2014-714148Plan
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea
MediumCVSS 6.4No exploitEPSS 76%squid-cache · squidNov 26, 2014
- CVE-2016-727448Plan
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W
HighCVSS 8.8Proof of conceptEPSS 42%microsoft · windows 10Dec 20, 2016
- CVE-2016-727247Plan
The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 G
HighCVSS 8.8No exploitEPSS 39%microsoft · windows 10Dec 20, 2016
- CVE-2015-243246Plan
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
CriticalCVSS 9.3Proof of conceptEPSS 30%microsoft · windows 7Aug 14, 2015
- CVE-2016-711746Plan
Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to exec
CriticalCVSS 9.8No exploitEPSS 24%linux · linux kernelOct 10, 2016
- CVE-2014-903445Plan
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
MediumCVSS 5.0Proof of conceptEPSS 83%wordpress · wordpressNov 25, 2014
- CVE-2017-692045Plan
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
CriticalCVSS 9.8No exploitEPSS 20%drupal · drupalAug 6, 2018
- CVE-2015-008144Plan
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind
CriticalCVSS 9.3Proof of conceptEPSS 24%microsoft · windows 7Mar 11, 2015
- CVE-2015-562142Plan
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item
HighCVSS 7.5Proof of conceptEPSS 41%net-snmp · net-snmpAug 19, 2015
- CVE-2015-175942Plan
Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offi
CriticalCVSS 9.3No exploitEPSS 16%microsoft · office compatibility packJun 9, 2015
- CVE-2015-176042Plan
Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrar
CriticalCVSS 9.3No exploitEPSS 16%microsoft · officeJun 9, 2015
- CVE-2019-1391742Plan
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
CriticalCVSS 9.8No exploitEPSS 9%exim · eximJul 25, 2019
- CVE-1999-022642Plan
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
CriticalCVSS 10.0No exploitEPSS 6%microsoft · windows ntJan 1, 1999
- CVE-2014-724742Plan
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro
CriticalCVSS 10.0No exploitEPSS 5%justsystems · ichitaroNov 25, 2014
- CVE-2016-727341Plan
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary cod
HighCVSS 8.8No exploitEPSS 19%microsoft · windows 10Dec 20, 2016
- CVE-2015-168741Plan
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v
CriticalCVSS 9.3No exploitEPSS 13%microsoft · internet explorerJun 9, 2015
- CVE-2015-534441Plan
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via
CriticalCVSS 9.8No exploitEPSS 7%apache · camelFeb 3, 2016