Show filters
5,934 Total Results
Displaying 21-30 of 5,934
Sort by:
Attacker Value
Unknown
CVE-2022-40674
Disclosure Date: September 14, 2022 (last updated February 24, 2025)
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
3
Attacker Value
Low
CVE-2021-33331
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.
2
Attacker Value
Low
CVE-2021-33326
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
2
Attacker Value
Very High
CVE-2020-3280 Cisco Unified CCX Preauth RCE
Disclosure Date: May 20, 2020 (last updated February 21, 2025)
A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerability by sending a malicious serialized Java object to a specific listener on an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user on an affected device.
1
Attacker Value
Moderate
CVE-2020-0674
Disclosure Date: February 11, 2020 (last updated February 21, 2025)
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
1
Attacker Value
High
Internet Explorer RCE through scripting engine memory corruption (IE 9, 10, 11)
Disclosure Date: November 12, 2019 (last updated July 26, 2024)
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1426, CVE-2019-1427, CVE-2019-1428.
1
Attacker Value
Unknown
CVE-2015-2425
Disclosure Date: July 14, 2015 (last updated June 29, 2024)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2383 and CVE-2015-2384.
2
Attacker Value
Unknown
CVE-2015-0071
Disclosure Date: February 11, 2015 (last updated July 03, 2024)
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."
2
Attacker Value
Unknown
CVE-2015-0313
Disclosure Date: February 02, 2015 (last updated July 03, 2024)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.
2
Attacker Value
Unknown
CVE-2015-0311
Disclosure Date: January 23, 2015 (last updated July 03, 2024)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
2