Tue, Nov 20 · 07:29 PM CSTCVE-2018-18861
9.8/10 · Must read/watchNVDvuln
Summary
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
CVECVE-2018-18861
SeverityCRITICAL
TypeUPDATED
PublishedTue, Nov 20 · 07:29 PM CST
ModifiedWed, Aug 19 · 05:19 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-0901
9.8/10 · Must read/watchNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, a
CVECVE-2020-0901
SeverityCRITICAL
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 15 · 02:55 PM CDTCVE-2013-4730
10.0/10 · Must read/watchNVDvuln
Summary
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
CVECVE-2013-4730
SeverityHIGH
TypeUPDATED
PublishedThu, May 15 · 02:55 PM CDT
ModifiedWed, Aug 19 · 05:19 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1023
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. E
CVECVE-2020-1023
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1024
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. E
CVECVE-2020-1024
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1069
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in the security context of the SharePoint ap
CVECVE-2020-1069
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1102
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. E
CVECVE-2020-1102
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1117
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. An attacker who successfully exploited this vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accoun
CVECVE-2020-1117
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1126
8.8/10 · Worth your timeNVDvuln
Summary
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the
CVECVE-2020-1126
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1171
8.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in Visual Studio Code when the Python extension loads configuration files after opening a project. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user
CVECVE-2020-1171
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1118
8.6/10 · Worth your timeNVDvuln
Summary
A denial of service vulnerability exists in the Windows implementation of Transport Layer Security (TLS) when it improperly handles certain key exchanges. An attacker who successfully exploited the vulnerability could cause a target system to stop responding. To exploit this vulnerability, a remote unauthenticated atta
CVECVE-2020-1118
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1112
8.5/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) IIS module improperly handles uploaded content. An attacker who successfully exploited this vulnerability could upload restricted file types to an IIS-hosted folder. To exploit this vulnerability, an attacker
CVECVE-2020-1112
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Tue, Sep 29 · 07:59 PM CDTCVE-2015-7601
7.8/10 · Worth your timeNVDvuln
Summary
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.
CVECVE-2015-7601
SeverityHIGH
TypeUPDATED
PublishedTue, Sep 29 · 07:59 PM CDT
ModifiedWed, Aug 19 · 05:19 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1010
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the v
CVECVE-2020-1010
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1021
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vulnerability could gain greater access to sensitive informatio
CVECVE-2020-1021
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1028
7.8/10 · Worth your timeNVDvuln
Summary
A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user rights. There are multiple ways an attacker could exploit the
CVECVE-2020-1028
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1048
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or dele
CVECVE-2020-1048
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1051
7.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted
CVECVE-2020-1051
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1066
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The update addresses the vulnerability by correcting how .NET Framewo
CVECVE-2020-1066
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1067
7.8/10 · Worth your timeNVDvuln
Summary
A remote code execution vulnerability exists in the way that Windows handles objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with elevated permissions on a target system. To exploit the vulnerability, an attacker who has a domain user account could create a speci
CVECVE-2020-1067
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1068
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control o
CVECVE-2020-1068
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1070
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An attacker could then install programs; view, change, or dele
CVECVE-2020-1070
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1077
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerability by running a specially crafted application on the victim s
CVECVE-2020-1077
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1078
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations. To exploit the vulnerability, an attacker would require unprivileged execution on the victim system. After successfully exploiting the vulnerability, an attacker could run arbi
CVECVE-2020-1078
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT
Thu, May 21 · 11:15 PM CDTCVE-2020-1079
7.8/10 · Worth your timeNVDvuln
Summary
An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. To exploit
CVECVE-2020-1079
SeverityHIGH
TypeUPDATED
PublishedThu, May 21 · 11:15 PM CDT
ModifiedWed, Aug 19 · 05:17 PM CDT