CVE Database

Comprehensive vulnerability intelligence with advanced analytics

8.8

A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet Explorer Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0226.

Published: May 12, 2017
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 61.98%
View Details
8.8

Incorrect handling of complex species in V8 in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac and 57.0.2987.108 for Android allowed a remote attacker to execute arbitrary code via a crafted HTML page.

Published: Apr 24, 2017
Modified: Oct 22, 2025
Product: debian debian_linux
EPSS: 50.65%
View Details
7.4

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result…

Published: Apr 24, 2017
Modified: Oct 22, 2025
Product: oracle weblogic_server
EPSS: 94.39%
View Details
8.8

An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Internet Explorer Elevation of Privilege Vulnerability."

Published: Apr 12, 2017
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 36.44%
View Details
9.8

CVE-2016-8735

Critical KEV

Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that…

Published: Apr 06, 2017
Modified: Oct 22, 2025
Product: oracle transportation_management
EPSS: 93.97%
View Details
9.8

CVE-2014-3931

Critical KEV

fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.

Published: Mar 31, 2017
Modified: Oct 22, 2025
EPSS: 35.56%
View Details
8.8

Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those described in CVE-2017-0018 and CVE-2017-0037.

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 41.46%
View Details
8.1

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets,…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: siemens syngo_sc2000_firmware
EPSS: 94.07%
View Details
7.5

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: siemens syngo_sc2000_firmware
EPSS: 92.42%
View Details
8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets,…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: siemens syngo_sc2000_firmware
EPSS: 93.73%
View Details
8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets,…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: siemens syngo_sc2000_firmware
EPSS: 93.34%
View Details
8.8

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets,…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: siemens syngo_sc2000_firmware
EPSS: 94.02%
View Details
4.3

CVE-2017-0059

Medium KEV

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 86.14%
View Details
6.5

CVE-2017-0022

Medium KEV

Microsoft XML Core Services (MSXML) in Windows 10 Gold, 1511, and 1607; Windows 7 SP1; Windows 8.1; Windows RT 8.1; Windows Server 2008 SP2 and R2 SP1; Windows Server 2012 Gold and R2; Windows Server 2016; and Windows Vista SP2 improperly handles objects in memory, allowing attackers to test for…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: microsoft windows_server_2012
EPSS: 28.07%
View Details
7.8

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 8.68%
View Details
7.8

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows…

Published: Mar 17, 2017
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 25.43%
View Details
8.8

V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.

Published: Jan 19, 2017
Modified: Oct 22, 2025
Product: redhat enterprise_linux_server
EPSS: 77.91%
View Details
7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."

Published: Dec 20, 2016
Modified: Oct 22, 2025
Product: microsoft excel
EPSS: 87.09%
View Details
8.8

Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable use after free vulnerability in the TextField class. Successful exploitation could lead to arbitrary code execution.

Published: Dec 15, 2016
Modified: Oct 22, 2025
Product: adobe flash_player
EPSS: 23.26%
View Details
6.5

CVE-2016-9563

Medium KEV

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

Published: Nov 23, 2016
Modified: Oct 22, 2025
Product: sap netweaver_application_server_java
EPSS: 58.44%
View Details
7.5

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special conditions it was possible to write SNMP variables on port 161/udp which should be read-only and should only be configured with TIA-Portal. A write to these variables…

Published: Nov 18, 2016
Modified: Oct 22, 2025
EPSS: 14.58%
View Details
8.8

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via…

Published: Nov 10, 2016
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 59.04%
View Details
7.8

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka…

Published: Nov 10, 2016
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 89.36%
View Details
8.8

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

Published: Nov 01, 2016
Modified: Oct 22, 2025
Product: adobe flash_player
EPSS: 46.89%
View Details