Show filters
1,987 Total Results
Displaying 21-30 of 1,987
Sort by:
Attacker Value
Unknown

CVE-2015-0311

Disclosure Date: January 23, 2015 (last updated July 03, 2024)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
Attacker Value
Very High

CVE-2014-6271

Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
Attacker Value
Moderate

CVE-2024-30055

Disclosure Date: May 14, 2024 (last updated January 18, 2025)
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1
Attacker Value
Unknown

CVE-2021-34506

Disclosure Date: July 01, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2021-34475

Disclosure Date: July 01, 2023 (last updated October 08, 2023)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
Moderate

CVE-2021-22947

Disclosure Date: September 29, 2021 (last updated March 28, 2024)
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
Attacker Value
Unknown

CVE-2021-30617

Disclosure Date: September 03, 2021 (last updated November 08, 2023)
Chromium: CVE-2021-30617 Policy bypass in Blink
Attacker Value
Unknown

CVE-2016-3351

Disclosure Date: September 14, 2016 (last updated July 03, 2024)
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Attacker Value
Unknown

CVE-2024-21388

Disclosure Date: January 30, 2024 (last updated January 12, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-6345

Disclosure Date: November 29, 2023 (last updated December 16, 2023)
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)