VulDB Updates Updates
- CVE-2021-38646 | Microsoft Office 365 Apps for Enterprise/2013 SP1/2016/2019 Access Connectivity Engine Remote Code Executionby vuldb.com on April 25, 2024 at 5:53 am
A vulnerability was found in Microsoft Office 2013 SP1/2016/2019/365 Apps for Enterprise. It has been classified as critical. This affects an unknown part of the component Access Connectivity Engine. The manipulation leads to Remote Code Execution. This vulnerability is uniquely identified as CVE-2021-38646. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2021-34486 | Microsoft Windows up to Server 2019 Event Tracing Privilege Escalationby vuldb.com on April 25, 2024 at 5:43 am
A vulnerability was found in Microsoft Windows up to Server 2019. It has been rated as very critical. This issue affects some unknown processing of the component Event Tracing. The manipulation leads to Privilege Escalation. The identification of this vulnerability is CVE-2021-34486. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2021-26085 | Atlassian Confluence Server up to 7.4.9/7.12.2 /s/ information disclosureby vuldb.com on April 25, 2024 at 5:43 am
A vulnerability classified as problematic has been found in Atlassian Confluence Server up to 7.4.9/7.12.2. Affected is an unknown function of the file /s/. The manipulation leads to information disclosure. This vulnerability is traded as CVE-2021-26085. It is possible to launch the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2021-20028 | SonicWALL Secure Remote Access up to 9.0.0.9-26sv cross site scripting (SNWLID-2021-0017)by vuldb.com on April 25, 2024 at 5:40 am
A vulnerability has been found in SonicWALL Secure Remote Access up to 9.0.0.9-26sv and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. This vulnerability is known as CVE-2021-20028. The attack can be launched remotely. Furthermore, there is an exploit available.
- CVE-2022-1096 | Google Chrome prior 99.0.4844.84 v8 type confusionby vuldb.com on April 25, 2024 at 5:29 am
A vulnerability has been found in Google Chrome and classified as critical. Affected by this vulnerability is an unknown functionality of the component v8. The manipulation leads to type confusion. This vulnerability is known as CVE-2022-1096. The attack can be launched remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2022-0543 | Redis on Debian Lua sandboxby vuldb.com on April 25, 2024 at 5:28 am
A vulnerability, which was classified as critical, has been found in Redis on Debian. Affected by this issue is some unknown functionality of the component Lua. The manipulation leads to sandbox issue. This vulnerability is handled as CVE-2022-0543. The attack may be launched remotely. Furthermore, there is an exploit available.
- CVE-2019-7483 | SonicWALL SMA100 CGI Script handleWAFRedirect path traversalby vuldb.com on April 25, 2024 at 5:22 am
A vulnerability classified as problematic has been found in SonicWALL SMA100. This affects an unknown part of the file handleWAFRedirect of the component CGI Script. The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2019-7483. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
- CVE-2018-8440 | Microsoft Windows up to Server 2016 ALPC access control (Nessus ID 117415 / BID-105153)by vuldb.com on April 25, 2024 at 5:08 am
A vulnerability, which was classified as critical, has been found in Microsoft Windows. This issue affects some unknown processing of the component ALPC. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2018-8440. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2018-8406 | Microsoft Windows up to Server 2016 DirectX Graphics access control (Nessus ID 111685 / BID-105012)by vuldb.com on April 25, 2024 at 5:04 am
A vulnerability classified as critical has been found in Microsoft Windows up to Server 2016. Affected is an unknown function of the component DirectX Graphics. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2018-8406. It is possible to launch the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2018-8405 | Microsoft Windows up to Server 2016 DirectX Graphics access control (Nessus ID 111685 / ID 91465)by vuldb.com on April 25, 2024 at 4:55 am
A vulnerability was found in Microsoft Windows up to Server 2016. It has been rated as critical. This issue affects some unknown processing of the component DirectX Graphics. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2018-8405. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2017-0213 | Microsoft Windows up to Server 2016 COM Aggregate Marshaler access control (KB4019215 / EDB-42020)by vuldb.com on April 25, 2024 at 4:49 am
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component COM Aggregate Marshaler. The manipulation leads to improper access controls. This vulnerability is handled as CVE-2017-0213. It is possible to launch the attack on the local host. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2017-0059 | Microsoft Internet Explorer 9/10/11 information disclosure (MS17-006 / EDB-41661)by vuldb.com on April 25, 2024 at 4:43 am
A vulnerability was found in Microsoft Internet Explorer 9/10/11 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to information disclosure. This vulnerability is handled as CVE-2017-0059. The attack may be launched remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2017-0037 | Microsoft Edge type conversion (MS17-007 / EDB-41454)by vuldb.com on April 25, 2024 at 4:29 am
A vulnerability, which was classified as critical, has been found in Microsoft Edge. This issue affects some unknown processing. The manipulation leads to incorrect type conversion. The identification of this vulnerability is CVE-2017-0037. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2017-0037 | Microsoft Internet Explorer 10/11 type conversion (MS17-006 / EDB-41454)by vuldb.com on April 25, 2024 at 4:14 am
A vulnerability, which was classified as critical, has been found in Microsoft Internet Explorer 10/11. This issue affects some unknown processing. The manipulation leads to incorrect type conversion. The identification of this vulnerability is CVE-2017-0037. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2020-28871 | Monitorr 1.7.6m upload.php unrestricted upload (EDB-48980 / Duplicate CVE-2024-0713)by vuldb.com on April 25, 2024 at 4:09 am
A vulnerability has been found in Monitorr 1.7.6m and classified as critical. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation leads to unrestricted upload. This vulnerability is known as CVE-2020-28871. The attack can be launched remotely. Furthermore, there is an exploit available. During the analysis of our data team we suspected a duplicate CVE assignment as CVE-2024-0713.
- CVE-2017-0037 | Microsoft Internet Explorer 11 CSS mshtml.dll HandleColumnBreakOnColumnSpanningElement th type conversion (EDB-41454 / Nessus ID 97729)by vuldb.com on April 25, 2024 at 4:00 am
A vulnerability, which was classified as critical, has been found in Microsoft Internet Explorer 11. This issue affects the function Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement in the library mshtml.dll of the component CSS Handler. The manipulation of the argument th leads to incorrect type conversion. The identification of this vulnerability is CVE-2017-0037. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2016-7201 | Microsoft Edge Scripting Engine chakra.dll memory corruption (MS16-129 / EDB-40990)by vuldb.com on April 25, 2024 at 3:56 am
A vulnerability was found in Microsoft Edge and classified as critical. This issue affects some unknown processing in the library chakra.dll of the component Scripting Engine. The manipulation leads to memory corruption. The identification of this vulnerability is CVE-2016-7201. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2016-7200 | Microsoft Edge Scripting Engine chakra.dll memory corruption (MS16-129 / EDB-40990)by vuldb.com on April 25, 2024 at 3:46 am
A vulnerability has been found in Microsoft Edge and classified as critical. This vulnerability affects unknown code in the library chakra.dll of the component Scripting Engine. The manipulation leads to memory corruption. This vulnerability was named CVE-2016-7200. The attack can be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2016-0189 | Microsoft Windows Server 2008/Vista SP2 JScript/VBScript memory corruption (MS16-053 / EDB-40118)by vuldb.com on April 25, 2024 at 3:39 am
A vulnerability was found in Microsoft Windows Server 2008/Vista SP2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component JScript/VBScript. The manipulation leads to memory corruption. This vulnerability is known as CVE-2016-0189. The attack can be launched remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2016-0189 | Microsoft Internet Explorer 9/10/11 Scripting Engine memory corruption (MS16-051 / EDB-40118)by vuldb.com on April 25, 2024 at 3:34 am
A vulnerability was found in Microsoft Internet Explorer 9/10/11. It has been rated as critical. This issue affects some unknown processing of the component Scripting Engine. The manipulation leads to memory corruption. The identification of this vulnerability is CVE-2016-0189. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2016-0151 | Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2 CSRSS access control (MS16-048 / EDB-39740)by vuldb.com on April 25, 2024 at 3:33 am
A vulnerability, which was classified as critical, has been found in Microsoft Windows 8.1/10/RT 8.1/Server 2012/Server 2012 R2. This issue affects some unknown processing of the component CSRSS. The manipulation leads to improper access controls. The identification of this vulnerability is CVE-2016-0151. The attack needs to be approached locally. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2016-0040 | Microsoft Windows 7/Server 2008/Vista SP2 access control (MS16-014 / EDB-44586)by vuldb.com on April 25, 2024 at 3:25 am
A vulnerability was found in Microsoft Windows 7/Server 2008/Vista SP2. It has been classified as critical. Affected is an unknown function. The manipulation leads to improper access controls. This vulnerability is traded as CVE-2016-0040. Local access is required to approach this attack. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2015-2426 | Microsoft Windows Vista SP2 up to Server 2012 R2 Adobe Type Manager Library atmfd.dll memory corruption (MS15-078 / EDB-38222)by vuldb.com on April 25, 2024 at 3:16 am
A vulnerability has been found in Microsoft Windows Vista SP2 up to Server 2012 R2 and classified as critical. This vulnerability affects unknown code in the library atmfd.dll of the component Adobe Type Manager Library. The manipulation leads to memory corruption. This vulnerability was named CVE-2015-2426. The attack can be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2015-2419 | Microsoft Internet Explorer 10/11 JScript 9 memory corruption (MS15-065 / Nessus ID 84761)by vuldb.com on April 25, 2024 at 3:15 am
A vulnerability, which was classified as critical, was found in Microsoft Internet Explorer 10/11. Affected is an unknown function of the component JScript 9. The manipulation leads to memory corruption. This vulnerability is traded as CVE-2015-2419. It is possible to launch the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2015-1770 | Microsoft Office 2013 SP1 Office Document data processing (MS15-059 / Nessus ID 84055)by vuldb.com on April 25, 2024 at 3:13 am
A vulnerability, which was classified as critical, has been found in Microsoft Office 2013 SP1. This issue affects some unknown processing of the component Office Document Handler. The manipulation leads to data processing error. The identification of this vulnerability is CVE-2015-1770. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2013-3660 | Microsoft Windows EPATHOBJ::pprFlattenRec memory corruption (XFDB-84391 / EDB-25611)by vuldb.com on April 24, 2024 at 5:14 pm
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects the function EPATHOBJ::pprFlattenRec. The manipulation leads to memory corruption. This vulnerability was named CVE-2013-3660. An attack has to be approached locally. Furthermore, there is an exploit available.
- CVE-2013-2729 | Adobe Acrobat Reader up to 11.0.2 numeric error (APSB13-15 / XFDB-84224)by vuldb.com on April 24, 2024 at 5:06 pm
A vulnerability was found in Adobe Acrobat Reader up to 11.0.2. It has been classified as critical. This affects an unknown part. The manipulation leads to numeric error. This vulnerability is uniquely identified as CVE-2013-2729. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.
- CVE-2013-2551 | Microsoft Internet Explorer 6/7/8/9/10 memory corruption (MS13-037 / XFDB-82777)by vuldb.com on April 24, 2024 at 4:57 pm
A vulnerability classified as critical has been found in Microsoft Internet Explorer 6/7/8/9/10. This affects an unknown part. The manipulation leads to memory corruption. This vulnerability is uniquely identified as CVE-2013-2551. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2013-2551 | Microsoft Internet Explorer 6/7/8/9/10 Sandbox use after free (MS13-037 / EDB-26175)by vuldb.com on April 24, 2024 at 4:51 pm
A vulnerability was found in Microsoft Internet Explorer 6/7/8/9/10 and classified as critical. This issue affects some unknown processing of the component Sandbox. The manipulation leads to use after free. The identification of this vulnerability is CVE-2013-2551. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to apply a patch to fix this issue.
- CVE-2013-2465 | Oracle Java up to 5.0 Update 45/6 Update 45/7 Update 21 2D integer coercion (EDB-27705 / Nessus ID 69762)by vuldb.com on April 24, 2024 at 4:42 pm
A vulnerability was found in Oracle Java up to 5.0 Update 45/6 Update 45/7 Update 21. It has been rated as very critical. This issue affects some unknown processing of the component 2D. The manipulation leads to integer coercion error. The identification of this vulnerability is CVE-2013-2465. The attack may be initiated remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected component.