Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2009-1151
Known exploited
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
CVSS Score
9.8
EPSS Score
0.93
Published
2009-03-26
CVE-2009-0927
Known exploited
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows remote attackers to execute arbitrary code via a crafted argument to the getIcon method of a Collab object, a different vulnerability than CVE-2009-0658.
CVSS Score
8.8
EPSS Score
0.937
Published
2009-03-19
CVE-2008-2992
Known exploited
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a PDF file that calls the util.printf JavaScript function with a crafted format string argument, a related issue to CVE-2008-1104.
CVSS Score
7.8
EPSS Score
0.934
Published
2008-11-04
CVE-2008-3431
Known exploited
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.
CVSS Score
8.8
EPSS Score
0.046
Published
2008-08-05
CVE-2007-5659
Known exploited
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code via a PDF file with long arguments to unspecified JavaScript methods. NOTE: this issue might be subsumed by CVE-2008-0655.
CVSS Score
7.8
EPSS Score
0.933
Published
2008-02-12
CVE-2008-0655
Known exploited
Multiple unspecified vulnerabilities in Adobe Reader and Acrobat before 8.1.2 have unknown impact and attack vectors.
CVSS Score
9.8
EPSS Score
0.7
Published
2008-02-07
CVE-2007-3010
Known exploited
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
CVSS Score
9.8
EPSS Score
0.94
Published
2007-09-18
CVE-2007-0671
Known exploited
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
CVSS Score
8.8
EPSS Score
0.681
Published
2007-02-03
CVE-2006-2492
Known exploited
Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.
CVSS Score
8.8
EPSS Score
0.753
Published
2006-05-20
CVE-2006-1547
Known exploited
ActionForm in Apache Software Foundation (ASF) Struts before 1.2.9 with BeanUtils 1.7 allows remote attackers to cause a denial of service via a multipart/form-data encoded form with a parameter name that references the public getMultipartRequestHandler method, which provides further access to elements in the CommonsMultipartRequestHandler implementation and BeanUtils.
CVSS Score
7.5
EPSS Score
0.137
Published
2006-03-30


Contact Us

Shodan ® - All rights reserved