imPC@ndo IT

Microsoft vulnerabilities

15.420 CVE

CVE-2016-0132
Critical 9.8

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Security…

microsoft .net_framework
0.22EPSS
CVE-2004-0124
Low 2.6

The DCOM RPC interface for Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause network communications via an "alter context" call that contains additional data, aka the "Object Identity Vulnerability."

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.22EPSS
CVE-2002-0863
Medium 5.0

Remote Data Protocol (RDP) version 5.0 in Microsoft Windows 2000 and RDP 5.1 in Windows XP does not encrypt the checksums of plaintext session data, which could allow a remote attacker to determine the contents of encrypted sessions via sniffing, aka "Weak Enc…

microsoft .net_windows_server · microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_nt · and 1 more
0.22EPSS
CVE-2013-3846
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Expl…

microsoft internet_explorer
0.22EPSS
CVE-2001-0662
Medium 5.0

RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.

microsoft windows_nt
0.22EPSS
CVE-2008-3648
High 9.3

nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.

microsoft windows_xp
0.22EPSS
CVE-2019-0585
High 8.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 …

microsoft office · microsoft office_365_proplus · microsoft office_online_server · microsoft office_web_apps_server · and 4 more
0.22EPSS
CVE-2010-1118
High 10.0

Unspecified vulnerability in Internet Explorer 8 on Microsoft Windows 7 allows remote attackers to execute arbitrary code via unknown vectors, possibly related to a use-after-free issue, as demonstrated by Peter Vreugdenhil during a Pwn2Own competition at CanS…

microsoft internet_explorer
0.22EPSS
CVE-2009-4311
High 9.3

Unspecified vulnerability in the Indeo codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via crafted media content, as reported to Microsoft by Paul Byrne of NGS Software. NOTE: this mig…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.22EPSS
CVE-2002-0078
High 7.5

The zone determination function in Microsoft Internet Explorer 5.5 and 6.0 allows remote attackers to run scripts in the Local Computer zone by embedding the script in a cookie, aka the "Cookie-based Script Execution" vulnerability.

microsoft internet_explorer
0.22EPSS
CVE-2003-0666
High 7.5

Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data offset and data size parameters in a Corel WordPerfect file.

microsoft wordperfect_converter
0.22EPSS
CVE-2002-2164
Medium 5.0

Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (crash) via a long <A HREF> link.

microsoft outlook_express
0.22EPSS
CVE-2013-3127
High 9.3

The Microsoft WMV video codec in wmv9vcm.dll, wmvdmod.dll in Windows Media Format Runtime 9 and 9.5, and wmvdecod.dll in Windows Media Format Runtime 11 and Windows Media Player 11 and 12 allows remote attackers to execute arbitrary code via a crafted media fi…

microsoft windows_media_format_runtime · microsoft windows_media_player
0.22EPSS
CVE-2013-1302
High 9.3

Microsoft Communicator 2007 R2, Lync 2010, Lync 2010 Attendee, and Lync Server 2013 do not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an invitation that triggers access to a deleted object, aka "Lync RCE Vuln…

microsoft lync · microsoft lync_server · microsoft office_communicator
0.22EPSS
CVE-2011-0094
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layouts Handling Memory Corruption Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2012-0162
High 9.3

Microsoft .NET Framework 4 does not properly allocate buffers, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP) or (2) a crafted .NET Framework application, aka ".NET Framework Buffer Allocation Vuln…

microsoft .net_framework
0.22EPSS
CVE-2012-0172
High 9.3

Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "VML Style Remote Code Execution Vulnerability."

microsoft internet_explorer
0.22EPSS
CVE-2012-0016
High 9.3

Untrusted search path vulnerability in Microsoft Expression Design; Expression Design SP1; and Expression Design 2, 3, and 4 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that cont…

microsoft expression_design
0.22EPSS
CVE-2024-43454
High 7.1

Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · and 2 more
0.22EPSS
CVE-2015-2435
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee…

microsoft .net_framework · microsoft live_meeting · microsoft lync · microsoft lync_basic · and 11 more
0.22EPSS
CVE-2016-3210
High 8.8

The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability…

microsoft internet_explorer
0.22EPSS
CVE-2004-0484
Low 2.6

mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a table containing a form that crosses multiple td elements, and whose "float: left" class is defined in a link to a CSS stylesheet after the en…

microsoft internet_explorer
0.22EPSS
CVE-2003-0907
Medium 5.1

Help and Support Center in Microsoft Windows XP SP1 does not properly validate HCP URLs, which allows remote attackers to execute arbitrary code via quotation marks in an hcp:// URL, which are not quoted when constructing the argument list to HelpCtr.exe.

microsoft windows_server_2003 · microsoft windows_xp
0.22EPSS
CVE-2014-0313
High 9.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-03…

microsoft internet_explorer
0.22EPSS
CVE-2016-7248
High 7.8

Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted file, aka "Microsoft Video Control Remote Code Execution Vul…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 1 more
0.22EPSS