CWE-399 · 2 632 записей
Resource Management Errors
CVE этого класса
2 632 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2010-0806Готовый эксплойт | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote atmicrosoft · internet explorer · CWE-399 | Высокая8,8 | KEV | 82,2 % | 10 мар. 2010 г. |
68На этой неделе | CVE-2009-3103Готовый эксплойт | Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold amicrosoft · windows server 2008 · CWE-399 | Критическая10,0 | — | 92,3 % | 8 сент. 2009 г. |
63На этой неделе | CVE-2009-0075Готовый эксплойт | Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to emicrosoft · internet explorer · CWE-399 | Критическая9,3 | — | 85,3 % | 10 февр. 2009 г. |
63На этой неделе | CVE-2018-0156Готовый эксплойт | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackercisco · ios · CWE-399 | Высокая7,5 | KEV | 8,6 % | 28 мар. 2018 г. |
62На этой неделе | CVE-2011-0065Готовый эксплойт | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers mozilla · firefox · CWE-399 | Критическая10,0 | — | 73,8 % | 7 мая 2011 г. |
62На этой неделе | CVE-2018-0154Готовый эксплойт | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unacisco · ios · CWE-399 | Высокая7,5 | KEV | 7,1 % | 28 мар. 2018 г. |
62На этой неделе | CVE-2017-12231Готовый эксплойт | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unautcisco · ios · CWE-399 | Высокая7,5 | KEV | 7,1 % | 28 сент. 2017 г. |
62На этой неделе | CVE-2017-12237Готовый эксплойт | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 couldcisco · ios · CWE-399 | Высокая7,5 | KEV | 7,1 % | 28 сент. 2017 г. |
62На этой неделе | CVE-2017-6627Готовый эксплойт | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, recisco · ios · CWE-399 | Высокая7,5 | KEV | 6,2 % | 7 сент. 2017 г. |
61На этой неделе | CVE-2010-3971Готовый эксплойт | Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in microsoft · internet explorer · CWE-399 | Критическая9,3 | — | 81,7 % | 22 дек. 2010 г. |
57В плане | CVE-2008-4844Готовый эксплойт | Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 microsoft · internet explorer · CWE-399 | Критическая9,3 | — | 66,5 % | 11 дек. 2008 г. |
57В плане | CVE-2017-12232Готовый эксплойт | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.cisco · ios · CWE-399 | Средняя6,5 | KEV | 2,2 % | 28 сент. 2017 г. |
57В плане | CVE-2017-12238Готовый эксплойт | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could cisco · ios · CWE-399 | Средняя6,5 | KEV | 2,0 % | 28 сент. 2017 г. |
56В плане | CVE-2009-2526Proof of concept | Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remotmicrosoft · windows server 2008 · CWE-399 | Высокая7,8 | — | 81,9 % | 14 окт. 2009 г. |
56В плане | CVE-2015-1868Эксплойта нет | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Serverpowerdns · authoritative · CWE-399 | Высокая7,8 | — | 81,7 % | 18 мая 2015 г. |
56В плане | CVE-2018-0161Готовый эксплойт | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalystcisco · ios · CWE-399 | Средняя6,3 | KEV | 4,1 % | 28 мар. 2018 г. |
55В плане | CVE-2015-0015Эксплойта нет | Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of servimicrosoft · windows server 2003 · CWE-399 | Высокая7,8 | — | 78,7 % | 13 янв. 2015 г. |
55В плане | CVE-2010-0477Proof of concept | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which almicrosoft · windows 7 · CWE-399 | Критическая10,0 | — | 50,2 % | 14 апр. 2010 г. |
54В плане | CVE-2013-0025Готовый эксплойт | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that microsoft · internet explorer · CWE-399 | Критическая9,3 | — | 55,8 % | 13 февр. 2013 г. |
54В плане | CVE-2018-0179Готовый эксплойт | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackcisco · ios · CWE-399 | Средняя5,9 | KEV | 4,9 % | 28 мар. 2018 г. |
54В плане | CVE-2018-0180Готовый эксплойт | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackcisco · ios · CWE-399 | Средняя5,9 | KEV | 4,9 % | 28 мар. 2018 г. |
53В плане | CVE-2008-3013Proof of concept | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, microsoft · digital image suite · CWE-399 | Критическая9,3 | — | 52,1 % | 10 сент. 2008 г. |
52В плане | CVE-2008-3656Готовый эксплойт | Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick iruby-lang · ruby · CWE-399 | Высокая7,8 | — | 70,2 % | 12 авг. 2008 г. |
52В плане | CVE-2009-1138Эксплойта нет | The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows rmicrosoft · windows 2000 · CWE-399 | Критическая10,0 | — | 39,4 % | 10 июн. 2009 г. |
52В плане | CVE-2008-4023Эксплойта нет | Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote atmicrosoft · windows 2000 · CWE-399 | Критическая10,0 | — | 39,2 % | 14 окт. 2008 г. |
- CVE-2010-080690Срочно
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote at
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 82 %microsoft · internet explorer10 мар. 2010 г.
- CVE-2009-310368На этой неделе
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold a
КритическаяCVSS 10,0Готовый эксплойтEPSS 92 %microsoft · windows server 20088 сент. 2009 г.
- CVE-2009-007563На этой неделе
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to e
КритическаяCVSS 9,3Готовый эксплойтEPSS 85 %microsoft · internet explorer10 февр. 2009 г.
- CVE-2018-015663На этой неделе
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 9 %cisco · ios28 мар. 2018 г.
- CVE-2011-006562На этой неделе
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %mozilla · firefox7 мая 2011 г.
- CVE-2018-015462На этой неделе
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an una
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 7 %cisco · ios28 мар. 2018 г.
- CVE-2017-1223162На этой неделе
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unaut
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 7 %cisco · ios28 сент. 2017 г.
- CVE-2017-1223762На этой неделе
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 7 %cisco · ios28 сент. 2017 г.
- CVE-2017-662762На этой неделе
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, re
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 6 %cisco · ios7 сент. 2017 г.
- CVE-2010-397161На этой неделе
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in
КритическаяCVSS 9,3Готовый эксплойтEPSS 82 %microsoft · internet explorer22 дек. 2010 г.
- CVE-2008-484457В плане
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6
КритическаяCVSS 9,3Готовый эксплойтEPSS 67 %microsoft · internet explorer11 дек. 2008 г.
- CVE-2017-1223257В плане
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 2 %cisco · ios28 сент. 2017 г.
- CVE-2017-1223857В плане
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 2 %cisco · ios28 сент. 2017 г.
- CVE-2009-252656В плане
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remot
ВысокаяCVSS 7,8Proof of conceptEPSS 82 %microsoft · windows server 200814 окт. 2009 г.
- CVE-2015-186856В плане
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server
ВысокаяCVSS 7,8Эксплойта нетEPSS 82 %powerdns · authoritative18 мая 2015 г.
- CVE-2018-016156В плане
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst
СредняяCVSS 6,3KEVГотовый эксплойтEPSS 4 %cisco · ios28 мар. 2018 г.
- CVE-2015-001555В плане
Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of servi
ВысокаяCVSS 7,8Эксплойта нетEPSS 79 %microsoft · windows server 200313 янв. 2015 г.
- CVE-2010-047755В плане
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which al
КритическаяCVSS 10,0Proof of conceptEPSS 50 %microsoft · windows 714 апр. 2010 г.
- CVE-2013-002554В плане
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that
КритическаяCVSS 9,3Готовый эксплойтEPSS 56 %microsoft · internet explorer13 февр. 2013 г.
- CVE-2018-017954В плане
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attack
СредняяCVSS 5,9KEVГотовый эксплойтEPSS 5 %cisco · ios28 мар. 2018 г.
- CVE-2018-018054В плане
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attack
СредняяCVSS 5,9KEVГотовый эксплойтEPSS 5 %cisco · ios28 мар. 2018 г.
- CVE-2008-301353В плане
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008,
КритическаяCVSS 9,3Proof of conceptEPSS 52 %microsoft · digital image suite10 сент. 2008 г.
- CVE-2008-365652В плане
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i
ВысокаяCVSS 7,8Готовый эксплойтEPSS 70 %ruby-lang · ruby12 авг. 2008 г.
- CVE-2009-113852В плане
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows r
КритическаяCVSS 10,0Эксплойта нетEPSS 39 %microsoft · windows 200010 июн. 2009 г.
- CVE-2008-402352В плане
Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote at
КритическаяCVSS 10,0Эксплойта нетEPSS 39 %microsoft · windows 200014 окт. 2008 г.