CVE Database

Comprehensive vulnerability intelligence with advanced analytics

9.8

CVE-2014-8361

Critical KEV

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023.

Published: May 01, 2015
Modified: Oct 22, 2025
Product: aterm w1200ex-ms_firmware
EPSS: 93.99%
View Details
7.5

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N…

Published: Apr 22, 2015
Modified: Oct 22, 2025
Product: tp-link tl-wdr4300_\(1.0\)_firmware
EPSS: 92.86%
View Details
7.8

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in April 2015, aka "Win32k Elevation of Privilege Vulnerability."

Published: Apr 21, 2015
Modified: Oct 22, 2025
Product: microsoft windows_2003_server
EPSS: 89.86%
View Details
9.8

CVE-2015-3043

Critical KEV

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as exploited in the wild in April 2015, a different vulnerability than…

Published: Apr 14, 2015
Modified: Nov 17, 2025
Product: redhat enterprise_linux_server
EPSS: 82.65%
View Details
7.8

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allow remote attackers to…

Published: Apr 14, 2015
Modified: Oct 22, 2025
Product: microsoft word
EPSS: 93.62%
View Details
9.8

CVE-2015-1635

Critical KEV

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

Published: Apr 14, 2015
Modified: Oct 22, 2025
Product: microsoft windows_server_2012
EPSS: 94.31%
View Details
7.8

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via unspecified vectors.

Published: Apr 10, 2015
Modified: Oct 22, 2025
Product: apple mac_os_x
EPSS: 21.07%
View Details
7.5

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.

Published: Apr 03, 2015
Modified: Jan 12, 2026
Product: cisco prime_data_center_network_manager
EPSS: 53.13%
View Details
9.8

CVE-2015-2051

Critical KEV

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

Published: Feb 23, 2015
Modified: Oct 22, 2025
EPSS: 93.23%
View Details
9.8

CVE-2015-1427

Critical KEV

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

Published: Feb 17, 2015
Modified: Oct 22, 2025
Product: redhat fuse
EPSS: 92.33%
View Details
6.5

CVE-2015-0071

Medium KEV

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explorer ASLR Bypass Vulnerability."

Published: Feb 11, 2015
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 38.67%
View Details
9.8

CVE-2015-0313

Critical KEV

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

Published: Feb 02, 2015
Modified: Nov 17, 2025
Product: opensuse opensuse
EPSS: 93.27%
View Details
9.8

CVE-2015-0311

Critical KEV

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

Published: Jan 23, 2015
Modified: Nov 17, 2025
Product: microsoft internet_explorer
EPSS: 92.74%
View Details
7.8

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Windows, and have an unspecified impact on other platforms, via unknown…

Published: Jan 23, 2015
Modified: Nov 17, 2025
EPSS: 5.02%
View Details
7.8

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in…

Published: Jan 13, 2015
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 91.70%
View Details
8.8

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account or (2) enable remote management via a crafted configuration module to hedwig.cgi, (3) activate new configuration settings…

Published: Jan 13, 2015
Modified: Oct 22, 2025
EPSS: 35.43%
View Details
7.8

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

Published: Dec 10, 2014
Modified: Nov 17, 2025
EPSS: 3.63%
View Details
8.8

Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service…

Published: Nov 25, 2014
Modified: Oct 22, 2025
Product: adobe air_sdk
EPSS: 27.07%
View Details
8.8

The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote authenticated domain users to obtain domain administrator privileges via a forged signature…

Published: Nov 18, 2014
Modified: Oct 22, 2025
Product: microsoft windows_server_2012
EPSS: 89.01%
View Details
7.8

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Office 2007 SP3, when IMJPDCT.EXE (aka IME for Japanese) is installed, allow remote attackers to bypass a sandbox protection mechanism via a crafted PDF document, aka "Microsoft IME (Japanese) Elevation of…

Published: Nov 11, 2014
Modified: Oct 22, 2025
Product: microsoft office_2007_ime
EPSS: 36.75%
View Details
7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object, as exploited in the wild in October 2014…

Published: Oct 22, 2014
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 90.73%
View Details
8.8

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted…

Published: Oct 15, 2014
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 49.72%
View Details
8.8

Microsoft Internet Explorer 7 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability," as exploited in the wild in October 2014, a different vulnerability than CVE-2014-4124.

Published: Oct 15, 2014
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 52.88%
View Details
7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the…

Published: Oct 15, 2014
Modified: Oct 22, 2025
Product: microsoft windows_rt
EPSS: 92.31%
View Details