Show filters
1,987 Total Results
Displaying 21-30 of 1,987
Sort by:
Attacker Value
Unknown
CVE-2015-0311
Disclosure Date: January 23, 2015 (last updated July 03, 2024)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
2
Attacker Value
Very High
CVE-2014-6271
Disclosure Date: September 24, 2014 (last updated July 25, 2024)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.
2
Attacker Value
Moderate
CVE-2024-30055
Disclosure Date: May 14, 2024 (last updated January 18, 2025)
Microsoft Edge (Chromium-based) Spoofing Vulnerability
1
Attacker Value
Unknown
CVE-2021-34506
Disclosure Date: July 01, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
1
Attacker Value
Unknown
CVE-2021-34475
Disclosure Date: July 01, 2023 (last updated October 08, 2023)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
1
Attacker Value
Moderate
CVE-2021-22947
Disclosure Date: September 29, 2021 (last updated March 28, 2024)
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *before* the TLS handshake as if they were authenticated.Using this flaw, it allows a Man-In-The-Middle attacker to first inject the fake responses, then pass-through the TLS traffic from the legitimate server and trick curl into sending data back to the user thinking the attacker's injected data comes from the TLS-protected server.
1
Attacker Value
Unknown
CVE-2021-30617
Disclosure Date: September 03, 2021 (last updated November 08, 2023)
Chromium: CVE-2021-30617 Policy bypass in Blink
1
Attacker Value
Unknown
CVE-2016-3351
Disclosure Date: September 14, 2016 (last updated July 03, 2024)
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
1
Attacker Value
Unknown
CVE-2024-21388
Disclosure Date: January 30, 2024 (last updated January 12, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
1
Attacker Value
Unknown
CVE-2023-6345
Disclosure Date: November 29, 2023 (last updated December 16, 2023)
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
1