CWE-19 · 232 записей
Data Processing Errors
CVE этого класса
232 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
62На этой неделе | CVE-2016-3236Готовый эксплойт | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SPmicrosoft · windows 10 · CWE-19 | Критическая9,8 | — | 76,8 % | 15 июн. 2016 г. |
59В плане | CVE-2016-4977Proof of concept | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_tpivotal · spring security oauth · CWE-19 | Высокая8,8 | — | 79,2 % | 25 мая 2017 г. |
59В плане | CVE-2012-5357Готовый эксплойт | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remotektron · ektron content management system · CWE-19 | Критическая9,8 | — | 67,8 % | 30 окт. 2017 г. |
58В плане | CVE-2015-5477Готовый эксплойт | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Высокая7,8 | — | 91,3 % | 29 июл. 2015 г. |
53В плане | CVE-2015-5374Готовый эксплойт | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mosiemens · siprotec firmware · CWE-19 | Высокая7,8 | — | 74,5 % | 18 июл. 2015 г. |
53В плане | CVE-2016-2510Эксплойта нет | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackbeanshell · beanshell · CWE-19 | Высокая8,1 | — | 70,4 % | 7 апр. 2016 г. |
51В плане | CVE-2015-2373Эксплойта нет | The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to emicrosoft · windows 7 · CWE-19 | Критическая10,0 | — | 38,1 % | 14 июл. 2015 г. |
49В плане | CVE-2015-0097Proof of concept | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers microsoft · excel · CWE-19 | Критическая9,3 | — | 40,9 % | 11 мар. 2015 г. |
48В плане | CVE-2014-7141Эксплойта нет | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reasquid-cache · squid · CWE-19 | Средняя6,4 | — | 76,1 % | 26 нояб. 2014 г. |
48В плане | CVE-2016-7274Proof of concept | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Wmicrosoft · windows 10 · CWE-19 | Высокая8,8 | — | 42,5 % | 20 дек. 2016 г. |
47В плане | CVE-2016-7272Эксплойта нет | The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gmicrosoft · windows 10 · CWE-19 | Высокая8,8 | — | 39,3 % | 20 дек. 2016 г. |
46В плане | CVE-2015-2432Proof of concept | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windomicrosoft · windows 7 · CWE-19 | Критическая9,3 | — | 30,3 % | 14 авг. 2015 г. |
46В плане | CVE-2016-7117Эксплойта нет | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execlinux · linux kernel · CWE-19 | Критическая9,8 | — | 23,6 % | 10 окт. 2016 г. |
45В плане | CVE-2014-9034Proof of concept | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Средняя5,0 | — | 82,7 % | 25 нояб. 2014 г. |
45В плане | CVE-2017-6920Эксплойта нет | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Критическая9,8 | — | 20,5 % | 6 авг. 2018 г. |
44В плане | CVE-2015-0081Proof of concept | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windmicrosoft · windows 7 · CWE-19 | Критическая9,3 | — | 23,8 % | 11 мар. 2015 г. |
42В плане | CVE-2015-5621Proof of concept | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list itemnet-snmp · net-snmp · CWE-19 | Высокая7,5 | — | 40,9 % | 19 авг. 2015 г. |
42В плане | CVE-2015-1759Эксплойта нет | Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offimicrosoft · office compatibility pack · CWE-19 | Критическая9,3 | — | 16,3 % | 9 июн. 2015 г. |
42В плане | CVE-2015-1760Эксплойта нет | Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrarmicrosoft · office · CWE-19 | Критическая9,3 | — | 16,3 % | 9 июн. 2015 г. |
42В плане | CVE-2019-13917Эксплойта нет | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Критическая9,8 | — | 8,6 % | 25 июл. 2019 г. |
42В плане | CVE-1999-0226Эксплойта нет | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.microsoft · windows nt · CWE-19 | Критическая10,0 | — | 5,9 % | 1 янв. 1999 г. |
42В плане | CVE-2014-7247Эксплойта нет | Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro justsystems · ichitaro · CWE-19 | Критическая10,0 | — | 5,3 % | 25 нояб. 2014 г. |
41В плане | CVE-2016-7273Эксплойта нет | The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary codmicrosoft · windows 10 · CWE-19 | Высокая8,8 | — | 19,0 % | 20 дек. 2016 г. |
41В плане | CVE-2015-1687Эксплойта нет | Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vmicrosoft · internet explorer · CWE-19 | Критическая9,3 | — | 12,9 % | 9 июн. 2015 г. |
41В плане | CVE-2015-5344Эксплойта нет | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via apache · camel · CWE-19 | Критическая9,8 | — | 7,1 % | 3 февр. 2016 г. |
- CVE-2016-323662На этой неделе
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP
КритическаяCVSS 9,8Готовый эксплойтEPSS 77 %microsoft · windows 1015 июн. 2016 г.
- CVE-2016-497759В плане
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_t
ВысокаяCVSS 8,8Proof of conceptEPSS 79 %pivotal · spring security oauth25 мая 2017 г.
- CVE-2012-535759В плане
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remot
КритическаяCVSS 9,8Готовый эксплойтEPSS 68 %ektron · ektron content management system30 окт. 2017 г.
- CVE-2015-547758В плане
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
ВысокаяCVSS 7,8Готовый эксплойтEPSS 91 %isc · bind29 июл. 2015 г.
- CVE-2015-537453В плане
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mo
ВысокаяCVSS 7,8Готовый эксплойтEPSS 74 %siemens · siprotec firmware18 июл. 2015 г.
- CVE-2016-251053В плане
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attack
ВысокаяCVSS 8,1Эксплойта нетEPSS 70 %beanshell · beanshell7 апр. 2016 г.
- CVE-2015-237351В плане
The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to e
КритическаяCVSS 10,0Эксплойта нетEPSS 38 %microsoft · windows 714 июл. 2015 г.
- CVE-2015-009749В плане
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers
КритическаяCVSS 9,3Proof of conceptEPSS 41 %microsoft · excel11 мар. 2015 г.
- CVE-2014-714148В плане
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea
СредняяCVSS 6,4Эксплойта нетEPSS 76 %squid-cache · squid26 нояб. 2014 г.
- CVE-2016-727448В плане
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W
ВысокаяCVSS 8,8Proof of conceptEPSS 42 %microsoft · windows 1020 дек. 2016 г.
- CVE-2016-727247В плане
The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 G
ВысокаяCVSS 8,8Эксплойта нетEPSS 39 %microsoft · windows 1020 дек. 2016 г.
- CVE-2015-243246В плане
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
КритическаяCVSS 9,3Proof of conceptEPSS 30 %microsoft · windows 714 авг. 2015 г.
- CVE-2016-711746В плане
Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to exec
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %linux · linux kernel10 окт. 2016 г.
- CVE-2014-903445В плане
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
СредняяCVSS 5,0Proof of conceptEPSS 83 %wordpress · wordpress25 нояб. 2014 г.
- CVE-2017-692045В плане
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %drupal · drupal6 авг. 2018 г.
- CVE-2015-008144В плане
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind
КритическаяCVSS 9,3Proof of conceptEPSS 24 %microsoft · windows 711 мар. 2015 г.
- CVE-2015-562142В плане
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item
ВысокаяCVSS 7,5Proof of conceptEPSS 41 %net-snmp · net-snmp19 авг. 2015 г.
- CVE-2015-175942В плане
Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offi
КритическаяCVSS 9,3Эксплойта нетEPSS 16 %microsoft · office compatibility pack9 июн. 2015 г.
- CVE-2015-176042В плане
Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrar
КритическаяCVSS 9,3Эксплойта нетEPSS 16 %microsoft · office9 июн. 2015 г.
- CVE-2019-1391742В плане
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %exim · exim25 июл. 2019 г.
- CVE-1999-022642В плане
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %microsoft · windows nt1 янв. 1999 г.
- CVE-2014-724742В плане
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %justsystems · ichitaro25 нояб. 2014 г.
- CVE-2016-727341В плане
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary cod
ВысокаяCVSS 8,8Эксплойта нетEPSS 19 %microsoft · windows 1020 дек. 2016 г.
- CVE-2015-168741В плане
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v
КритическаяCVSS 9,3Эксплойта нетEPSS 13 %microsoft · internet explorer9 июн. 2015 г.
- CVE-2015-534441В плане
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %apache · camel3 февр. 2016 г.