imPC@ndo IT

Microsoft vulnerabilities

15.441 CVE

CVE-2014-0297
High 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.22EPSS
CVE-2010-3338
High 7.2

The Windows Task Scheduler in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly determine the security context of scheduled tasks, which allows local users to gain privileges via a crafted application, …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.22EPSS
CVE-2006-3915
Medium 5.0

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.

microsoft internet_explorer
0.22EPSS
CVE-2006-3511
Medium 5.0

Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.

microsoft internet_explorer
0.22EPSS
CVE-2025-29793
High 7.2

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

microsoft sharepoint_enterprise_server · microsoft sharepoint_server
0.22EPSS
CVE-2010-3946
High 9.3

Integer overflow in the PICT image converter in the graphics filters in Microsoft Office XP SP3, Office 2003 SP3, and Office Converter Pack allows remote attackers to execute arbitrary code via a crafted PICT image in an Office document, aka "PICT Image Conver…

microsoft office · microsoft office_converter_pack
0.22EPSS
CVE-2006-7066
High 7.1

Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating an object inside an iframe, deleting the frame by setting its location.href to about:blank, then accessing a property of the object within …

microsoft internet_explorer
0.22EPSS
CVE-2012-0142
High 9.3

Microsoft Excel 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2008 for Mac; Excel Viewer; and Office Compatibility Pack SP2 and SP3 do not properly handle memory during the opening of files, which allows remote attackers to execute arbitrary code v…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.22EPSS
CVE-2011-1250
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Link Properties Handling Memory Cor…

microsoft internet_explorer
0.22EPSS
CVE-2014-0312
High 9.3

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.22EPSS
CVE-1999-0886
High 9.0

The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.

microsoft windows_nt
0.22EPSS
CVE-2002-0869
High 7.5

Unknown vulnerability in the hosting process (dllhost.exe) for Microsoft Internet Information Server (IIS) 4.0 through 5.1 allows remote attackers to gain privileges by executing an out of process application that acquires LocalSystem privileges, aka "Out of P…

microsoft internet_information_server · microsoft internet_information_services
0.22EPSS
CVE-2014-2776
High 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-1769, CVE…

microsoft internet_explorer
0.22EPSS
CVE-2016-7217
High 8.8

Media Foundation in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Media Foundation Memory Corrupti…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 1 more
0.22EPSS
CVE-2016-7205
High 8.8

Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.22EPSS
CVE-2023-36052
High 8.6

Azure CLI REST Command Information Disclosure Vulnerability

microsoft azure_command-line_interface
0.22EPSS
CVE-2018-8161
High 7.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft S…

microsoft office · microsoft office_web_apps · microsoft sharepoint_server · microsoft word
0.22EPSS
CVE-2013-3863
High 9.3

Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via a crafted OLE object in a file, aka "OLE Property Vulnerability."

microsoft windows_server_2003 · microsoft windows_xp
0.22EPSS
CVE-2017-8737
High 7.5

Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way th…

microsoft edge · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012
0.22EPSS
CVE-2017-8728
High 7.5

Microsoft Windows PDF Library in Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way th…

microsoft edge · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2008 · and 1 more
0.22EPSS
CVE-1999-0867
Medium 5.0

Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.

microsoft commercial_internet_system · microsoft internet_information_server · microsoft site_server
0.22EPSS
CVE-2006-4219
High 7.5

The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.

microsoft ie
0.22EPSS
CVE-2011-1986
High 9.3

Use-after-free vulnerability in Microsoft Excel 2003 SP3 allows remote attackers to execute arbitrary code via a crafted spreadsheet, aka "Excel Use after Free WriteAV Vulnerability."

microsoft excel
0.22EPSS
CVE-2009-1920
High 9.3

The JScript scripting engine 5.1, 5.6, 5.7, and 5.8 in JScript.dll in Microsoft Windows, as used in Internet Explorer, does not properly load decoded scripts into memory before execution, which allows remote attackers to execute arbitrary code via a crafted we…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.22EPSS
CVE-2007-2108
Medium 6.8

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers to have an unknown impact, aka DB01. NOTE: as of 20070424, Oracle has not disputed reliable claims that this i…

microsoft windows · oracle database_server
0.21EPSS