imPC@ndo IT

Microsoft vulnerabilities

15.441 CVE

CVE-2013-3872
High 9.3

Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3873, CVE…

microsoft internet_explorer
0.21EPSS
CVE-2010-2558
High 9.3

Race condition in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to an object in memory, aka "Race Condition Memory Corruption Vulnerability."

microsoft internet_explorer
0.21EPSS
CVE-2013-3134
High 9.3

The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application …

microsoft .net_framework
0.21EPSS
CVE-2009-3671
High 8.1

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized M…

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.21EPSS
CVE-2013-3858
High 9.3

Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cau…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · microsoft word · and 1 more
0.21EPSS
CVE-2013-3857
High 9.3

Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execu…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · microsoft word · and 1 more
0.21EPSS
CVE-2013-3849
High 9.3

Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cau…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft sharepoint_server · microsoft word · and 1 more
0.21EPSS
CVE-2010-3242
High 9.3

Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Ghost Record Type Parsing…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.21EPSS
CVE-2010-3241
High 9.3

Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out-of-Bounds…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.21EPSS
CVE-2010-3240
High 9.3

Microsoft Excel 2002 SP3 and 2007 SP2; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Exce…

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.21EPSS
CVE-2010-3239
High 9.3

Microsoft Excel 2002 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Extra Out of Boundary Record Parsing Vulnerability."

microsoft excel
0.21EPSS
CVE-2010-3238
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, and Office 2004 for Mac, does not properly validate binary file-format information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Negative Future Function Vulnerability."

microsoft excel · microsoft office
0.21EPSS
CVE-2010-3237
High 9.3

Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Merge Cell Record Pointer Vulnerability."

microsoft excel · microsoft office
0.21EPSS
CVE-2010-3236
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Out Of Bound…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.21EPSS
CVE-2010-3235
High 9.3

Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Biff Record Vulnerability."

microsoft excel
0.21EPSS
CVE-2010-3233
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3 does not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted .wk3 (aka Lotus 1-2-3 workbook) file, aka "Lotus 1-2-3 Workbook Parsing Vulnerability."

microsoft excel
0.21EPSS
CVE-2010-3232
High 9.3

Microsoft Excel 2003 SP3 and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information, whic…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.21EPSS
CVE-2017-8630
High 7.8

Microsoft Office 2016 allows a remote code execution vulnerability when it fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8631, CVE-2017-8632, and CVE-2017-8744.

microsoft office
0.21EPSS
CVE-2015-2504
High 9.3

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6 improperly counts objects before performing an array copy, which allows remote attackers to (1) execute arbitrary code via a crafted XAML browser application (XBAP) or (2) bypass Code …

microsoft .net_framework
0.21EPSS
CVE-2018-0920
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-…

microsoft excel
0.21EPSS
CVE-2010-2569
High 9.3

pubconv.dll (aka the Publisher Converter DLL) in Microsoft Publisher 2002 SP3, 2003 SP3, and 2007 SP2 does not properly handle an unspecified size field in certain older file formats, which allows remote attackers to execute arbitrary code or cause a denial of…

microsoft publisher
0.21EPSS
CVE-2000-0419
High 7.5

The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.

microsoft access · microsoft excel · microsoft frontpage · microsoft office · and 6 more
0.21EPSS
CVE-2010-2265
Medium 4.3

Cross-site scripting (XSS) vulnerability in the GetServerName function in sysinfo/commonFunc.js in Microsoft Windows Help and Support Center for Windows XP and Windows Server 2003 allows remote attackers to inject arbitrary web script or HTML via the svr param…

microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.21EPSS
CVE-2009-2504
High 9.3

Multiple integer overflows in unspecified APIs in GDI+ in Microsoft .NET Framework 1.1 SP1, .NET Framework 2.0 SP1 and SP2, Windows XP SP2 and SP3, Windows Server 2003 SP2, Vista Gold and SP1, Server 2008 Gold, Office XP SP3, Office 2003 SP3, 2007 Microsoft Of…

microsoft .net_framework · microsoft excel_viewer · microsoft expression_web · microsoft forefront_client_security · and 22 more
0.21EPSS
CVE-2009-0090
High 9.3

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unintended access to stack memory, and execute arbitrary code, via (1) a crafted XAML browser application (XBAP), (2…

microsoft .net_framework · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.21EPSS