CWE-19 · 232 kayıt
Data Processing Errors
Bu sınıftaki CVE’ler
232 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
62Bu hafta | CVE-2016-3236Silahlaştırılmış | The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SPmicrosoft · windows 10 · CWE-19 | Kritik9,8 | — | %76,8 | 15 Haz 2016 |
59Planlayın | CVE-2016-4977Kavram kanıtı | When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_tpivotal · spring security oauth · CWE-19 | Yüksek8,8 | — | %79,2 | 25 May 2017 |
59Planlayın | CVE-2012-5357Silahlaştırılmış | Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remotektron · ektron content management system · CWE-19 | Kritik9,8 | — | %67,8 | 30 Eki 2017 |
58Planlayın | CVE-2015-5477Silahlaştırılmış | named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion faisc · bind · CWE-19 | Yüksek7,8 | — | %91,3 | 29 Tem 2015 |
53Planlayın | CVE-2015-5374Silahlaştırılmış | A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mosiemens · siprotec firmware · CWE-19 | Yüksek7,8 | — | %74,5 | 18 Tem 2015 |
53Planlayın | CVE-2016-2510İstismar yok | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackbeanshell · beanshell · CWE-19 | Yüksek8,1 | — | %70,4 | 7 Nis 2016 |
51Planlayın | CVE-2015-2373İstismar yok | The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to emicrosoft · windows 7 · CWE-19 | Kritik10,0 | — | %38,1 | 14 Tem 2015 |
49Planlayın | CVE-2015-0097Kavram kanıtı | Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers microsoft · excel · CWE-19 | Kritik9,3 | — | %40,9 | 11 Mar 2015 |
48Planlayın | CVE-2014-7141İstismar yok | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reasquid-cache · squid · CWE-19 | Orta6,4 | — | %76,1 | 26 Kas 2014 |
48Planlayın | CVE-2016-7274Kavram kanıtı | Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Wmicrosoft · windows 10 · CWE-19 | Yüksek8,8 | — | %42,5 | 20 Ara 2016 |
47Planlayın | CVE-2016-7272İstismar yok | The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gmicrosoft · windows 10 · CWE-19 | Yüksek8,8 | — | %39,3 | 20 Ara 2016 |
46Planlayın | CVE-2015-2432Kavram kanıtı | ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windomicrosoft · windows 7 · CWE-19 | Kritik9,3 | — | %30,3 | 14 Ağu 2015 |
46Planlayın | CVE-2016-7117İstismar yok | Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execlinux · linux kernel · CWE-19 | Kritik9,8 | — | %23,6 | 10 Eki 2016 |
45Planlayın | CVE-2014-9034Kavram kanıtı | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackerswordpress · wordpress · CWE-19 | Orta5,0 | — | %82,7 | 25 Kas 2014 |
45Planlayın | CVE-2017-6920İstismar yok | Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects sdrupal · drupal · CWE-19 | Kritik9,8 | — | %20,5 | 6 Ağu 2018 |
44Planlayın | CVE-2015-0081Kavram kanıtı | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windmicrosoft · windows 7 · CWE-19 | Kritik9,3 | — | %23,8 | 11 Mar 2015 |
42Planlayın | CVE-2015-5621Kavram kanıtı | The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list itemnet-snmp · net-snmp · CWE-19 | Yüksek7,5 | — | %40,9 | 19 Ağu 2015 |
42Planlayın | CVE-2015-1759İstismar yok | Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offimicrosoft · office compatibility pack · CWE-19 | Kritik9,3 | — | %16,3 | 9 Haz 2015 |
42Planlayın | CVE-2015-1760İstismar yok | Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrarmicrosoft · office · CWE-19 | Kritik9,3 | — | %16,3 | 9 Haz 2015 |
42Planlayın | CVE-2019-13917İstismar yok | Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansionexim · exim · CWE-19 | Kritik9,8 | — | %8,6 | 25 Tem 2019 |
42Planlayın | CVE-1999-0226İstismar yok | Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.microsoft · windows nt · CWE-19 | Kritik10,0 | — | %5,9 | 1 Oca 1999 |
42Planlayın | CVE-2014-7247İstismar yok | Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro justsystems · ichitaro · CWE-19 | Kritik10,0 | — | %5,3 | 25 Kas 2014 |
41Planlayın | CVE-2016-7273İstismar yok | The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary codmicrosoft · windows 10 · CWE-19 | Yüksek8,8 | — | %19,0 | 20 Ara 2016 |
41Planlayın | CVE-2015-1687İstismar yok | Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) vmicrosoft · internet explorer · CWE-19 | Kritik9,3 | — | %12,9 | 9 Haz 2015 |
41Planlayın | CVE-2015-5344İstismar yok | The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via apache · camel · CWE-19 | Kritik9,8 | — | %7,1 | 3 Şub 2016 |
- CVE-2016-323662Bu hafta
The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP
KritikCVSS 9,8SilahlaştırılmışEPSS %77microsoft · windows 1015 Haz 2016
- CVE-2016-497759Planlayın
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_t
YüksekCVSS 8,8Kavram kanıtıEPSS %79pivotal · spring security oauth25 May 2017
- CVE-2012-535759Planlayın
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true, which allows remot
KritikCVSS 9,8SilahlaştırılmışEPSS %68ektron · ektron content management system30 Eki 2017
- CVE-2015-547758Planlayın
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion fa
YüksekCVSS 7,8SilahlaştırılmışEPSS %91isc · bind29 Tem 2015
- CVE-2015-537453Planlayın
A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Mo
YüksekCVSS 7,8SilahlaştırılmışEPSS %74siemens · siprotec firmware18 Tem 2015
- CVE-2016-251053Planlayın
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attack
YüksekCVSS 8,1İstismar yokEPSS %70beanshell · beanshell7 Nis 2016
- CVE-2015-237351Planlayın
The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to e
KritikCVSS 10,0İstismar yokEPSS %38microsoft · windows 714 Tem 2015
- CVE-2015-009749Planlayın
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 allow remote attackers
KritikCVSS 9,3Kavram kanıtıEPSS %41microsoft · excel11 Mar 2015
- CVE-2014-714148Planlayın
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea
OrtaCVSS 6,4İstismar yokEPSS %76squid-cache · squid26 Kas 2014
- CVE-2016-727448Planlayın
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W
YüksekCVSS 8,8Kavram kanıtıEPSS %42microsoft · windows 1020 Ara 2016
- CVE-2016-727247Planlayın
The Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 G
YüksekCVSS 8,8İstismar yokEPSS %39microsoft · windows 1020 Ara 2016
- CVE-2015-243246Planlayın
ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo
KritikCVSS 9,3Kavram kanıtıEPSS %30microsoft · windows 714 Ağu 2015
- CVE-2016-711746Planlayın
Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to exec
KritikCVSS 9,8İstismar yokEPSS %24linux · linux kernel10 Eki 2016
- CVE-2014-903445Planlayın
wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers
OrtaCVSS 5,0Kavram kanıtıEPSS %83wordpress · wordpress25 Kas 2014
- CVE-2017-692045Planlayın
Drupal core 8 before versions 8.3.4 allows remote attackers to execute arbitrary code due to the PECL YAML parser not handling PHP objects s
KritikCVSS 9,8İstismar yokEPSS %20drupal · drupal6 Ağu 2018
- CVE-2015-008144Planlayın
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wind
KritikCVSS 9,3Kavram kanıtıEPSS %24microsoft · windows 711 Mar 2015
- CVE-2015-562142Planlayın
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnmp_variable_list item
YüksekCVSS 7,5Kavram kanıtıEPSS %41net-snmp · net-snmp19 Ağu 2015
- CVE-2015-175942Planlayın
Microsoft Office Compatibility Pack SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Offi
KritikCVSS 9,3İstismar yokEPSS %16microsoft · office compatibility pack9 Haz 2015
- CVE-2015-176042Planlayın
Microsoft Office Compatibility Pack SP3, Office 2010 SP2, Office 2013 SP1, and Office 2013 RT SP1 allow remote attackers to execute arbitrar
KritikCVSS 9,3İstismar yokEPSS %16microsoft · office9 Haz 2015
- CVE-2019-1391742Planlayın
Exim 4.85 through 4.92 (fixed in 4.92.1) allows remote code execution as root in some unusual configurations that use the ${sort } expansion
KritikCVSS 9,8İstismar yokEPSS %9exim · exim25 Tem 2019
- CVE-1999-022642Planlayın
Windows NT TCP/IP processes fragmented IP packets improperly, causing a denial of service.
KritikCVSS 10,0İstismar yokEPSS %6microsoft · windows nt1 Oca 1999
- CVE-2014-724742Planlayın
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro
KritikCVSS 10,0İstismar yokEPSS %5justsystems · ichitaro25 Kas 2014
- CVE-2016-727341Planlayın
The Graphics component in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows remote attackers to execute arbitrary cod
YüksekCVSS 8,8İstismar yokEPSS %19microsoft · windows 1020 Ara 2016
- CVE-2015-168741Planlayın
Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) v
KritikCVSS 9,3İstismar yokEPSS %13microsoft · internet explorer9 Haz 2015
- CVE-2015-534441Planlayın
The camel-xstream component in Apache Camel before 2.15.5 and 2.16.x before 2.16.1 allow remote attackers to execute arbitrary commands via
KritikCVSS 9,8İstismar yokEPSS %7apache · camel3 Şub 2016