CWE-399 · 2.632 kayıt
Resource Management Errors
Bu sınıftaki CVE’ler
2.632 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2010-0806Silahlaştırılmış | Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote atmicrosoft · internet explorer · CWE-399 | Yüksek8,8 | KEV | %82,2 | 10 Mar 2010 |
68Bu hafta | CVE-2009-3103Silahlaştırılmış | Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold amicrosoft · windows server 2008 · CWE-399 | Kritik10,0 | — | %92,3 | 8 Eyl 2009 |
63Bu hafta | CVE-2009-0075Silahlaştırılmış | Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to emicrosoft · internet explorer · CWE-399 | Kritik9,3 | — | %85,3 | 10 Şub 2009 |
63Bu hafta | CVE-2018-0156Silahlaştırılmış | A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attackercisco · ios · CWE-399 | Yüksek7,5 | KEV | %8,6 | 28 Mar 2018 |
62Bu hafta | CVE-2011-0065Silahlaştırılmış | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers mozilla · firefox · CWE-399 | Kritik10,0 | — | %73,8 | 7 May 2011 |
62Bu hafta | CVE-2018-0154Silahlaştırılmış | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unacisco · ios · CWE-399 | Yüksek7,5 | KEV | %7,1 | 28 Mar 2018 |
62Bu hafta | CVE-2017-12231Silahlaştırılmış | A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unautcisco · ios · CWE-399 | Yüksek7,5 | KEV | %7,1 | 28 Eyl 2017 |
62Bu hafta | CVE-2017-12237Silahlaştırılmış | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 couldcisco · ios · CWE-399 | Yüksek7,5 | KEV | %7,1 | 28 Eyl 2017 |
62Bu hafta | CVE-2017-6627Silahlaştırılmış | A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, recisco · ios · CWE-399 | Yüksek7,5 | KEV | %6,2 | 7 Eyl 2017 |
61Bu hafta | CVE-2010-3971Silahlaştırılmış | Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in microsoft · internet explorer · CWE-399 | Kritik9,3 | — | %81,7 | 22 Ara 2010 |
57Planlayın | CVE-2008-4844Silahlaştırılmış | Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 microsoft · internet explorer · CWE-399 | Kritik9,3 | — | %66,5 | 11 Ara 2008 |
57Planlayın | CVE-2017-12232Silahlaştırılmış | A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.cisco · ios · CWE-399 | Orta6,5 | KEV | %2,2 | 28 Eyl 2017 |
57Planlayın | CVE-2017-12238Silahlaştırılmış | A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could cisco · ios · CWE-399 | Orta6,5 | KEV | %2,0 | 28 Eyl 2017 |
56Planlayın | CVE-2009-2526Kavram kanıtı | Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remotmicrosoft · windows server 2008 · CWE-399 | Yüksek7,8 | — | %81,9 | 14 Eki 2009 |
56Planlayın | CVE-2015-1868İstismar yok | The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Serverpowerdns · authoritative · CWE-399 | Yüksek7,8 | — | %81,7 | 18 May 2015 |
56Planlayın | CVE-2018-0161Silahlaştırılmış | A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalystcisco · ios · CWE-399 | Orta6,3 | KEV | %4,1 | 28 Mar 2018 |
55Planlayın | CVE-2015-0015İstismar yok | Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of servimicrosoft · windows server 2003 · CWE-399 | Yüksek7,8 | — | %78,7 | 13 Oca 2015 |
55Planlayın | CVE-2010-0477Kavram kanıtı | The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which almicrosoft · windows 7 · CWE-399 | Kritik10,0 | — | %50,2 | 14 Nis 2010 |
54Planlayın | CVE-2013-0025Silahlaştırılmış | Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that microsoft · internet explorer · CWE-399 | Kritik9,3 | — | %55,8 | 13 Şub 2013 |
54Planlayın | CVE-2018-0179Silahlaştırılmış | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackcisco · ios · CWE-399 | Orta5,9 | KEV | %4,9 | 28 Mar 2018 |
54Planlayın | CVE-2018-0180Silahlaştırılmış | Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attackcisco · ios · CWE-399 | Orta5,9 | KEV | %4,9 | 28 Mar 2018 |
53Planlayın | CVE-2008-3013Kavram kanıtı | gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, microsoft · digital image suite · CWE-399 | Kritik9,3 | — | %52,1 | 10 Eyl 2008 |
52Planlayın | CVE-2008-3656Silahlaştırılmış | Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick iruby-lang · ruby · CWE-399 | Yüksek7,8 | — | %70,2 | 12 Ağu 2008 |
52Planlayın | CVE-2009-1138İstismar yok | The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows rmicrosoft · windows 2000 · CWE-399 | Kritik10,0 | — | %39,4 | 10 Haz 2009 |
52Planlayın | CVE-2008-4023İstismar yok | Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote atmicrosoft · windows 2000 · CWE-399 | Kritik10,0 | — | %39,2 | 14 Eki 2008 |
- CVE-2010-080690Hemen
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, and 7 allows remote at
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %82microsoft · internet explorer10 Mar 2010
- CVE-2009-310368Bu hafta
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold a
KritikCVSS 10,0SilahlaştırılmışEPSS %92microsoft · windows server 20088 Eyl 2009
- CVE-2009-007563Bu hafta
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to e
KritikCVSS 9,3SilahlaştırılmışEPSS %85microsoft · internet explorer10 Şub 2009
- CVE-2018-015663Bu hafta
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %9cisco · ios28 Mar 2018
- CVE-2011-006562Bu hafta
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers
KritikCVSS 10,0SilahlaştırılmışEPSS %74mozilla · firefox7 May 2011
- CVE-2018-015462Bu hafta
A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an una
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %7cisco · ios28 Mar 2018
- CVE-2017-1223162Bu hafta
A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unaut
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %7cisco · ios28 Eyl 2017
- CVE-2017-1223762Bu hafta
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %7cisco · ios28 Eyl 2017
- CVE-2017-662762Bu hafta
A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, re
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %6cisco · ios7 Eyl 2017
- CVE-2010-397161Bu hafta
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in mshtml.dll, as used in
KritikCVSS 9,3SilahlaştırılmışEPSS %82microsoft · internet explorer22 Ara 2010
- CVE-2008-484457Planlayın
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6
KritikCVSS 9,3SilahlaştırılmışEPSS %67microsoft · internet explorer11 Ara 2008
- CVE-2017-1223257Planlayın
A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %2cisco · ios28 Eyl 2017
- CVE-2017-1223857Planlayın
A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %2cisco · ios28 Eyl 2017
- CVE-2009-252656Planlayın
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remot
YüksekCVSS 7,8Kavram kanıtıEPSS %82microsoft · windows server 200814 Eki 2009
- CVE-2015-186856Planlayın
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server
YüksekCVSS 7,8İstismar yokEPSS %82powerdns · authoritative18 May 2015
- CVE-2018-016156Planlayın
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst
OrtaCVSS 6,3KEVSilahlaştırılmışEPSS %4cisco · ios28 Mar 2018
- CVE-2015-001555Planlayın
Microsoft Windows Server 2003 SP2, Server 2008 SP2 and R2 SP1, and Server 2012 Gold and R2 allow remote attackers to cause a denial of servi
YüksekCVSS 7,8İstismar yokEPSS %79microsoft · windows server 200313 Oca 2015
- CVE-2010-047755Planlayın
The SMB client in Microsoft Windows Server 2008 R2 and Windows 7 does not properly handle (1) SMBv1 and (2) SMBv2 response packets, which al
KritikCVSS 10,0Kavram kanıtıEPSS %50microsoft · windows 714 Nis 2010
- CVE-2013-002554Planlayın
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that
KritikCVSS 9,3SilahlaştırılmışEPSS %56microsoft · internet explorer13 Şub 2013
- CVE-2018-017954Planlayın
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attack
OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %5cisco · ios28 Mar 2018
- CVE-2018-018054Planlayın
Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attack
OrtaCVSS 5,9KEVSilahlaştırılmışEPSS %5cisco · ios28 Mar 2018
- CVE-2008-301353Planlayın
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008,
KritikCVSS 9,3Kavram kanıtıEPSS %52microsoft · digital image suite10 Eyl 2008
- CVE-2008-365652Planlayın
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick i
YüksekCVSS 7,8SilahlaştırılmışEPSS %70ruby-lang · ruby12 Ağu 2008
- CVE-2009-113852Planlayın
The LDAP service in Active Directory on Microsoft Windows 2000 SP4 does not properly free memory for LDAP and LDAPS requests, which allows r
KritikCVSS 10,0İstismar yokEPSS %39microsoft · windows 200010 Haz 2009
- CVE-2008-402352Planlayın
Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote at
KritikCVSS 10,0İstismar yokEPSS %39microsoft · windows 200014 Eki 2008