imPC@ndo IT

Microsoft vulnerabilities

15.441 CVE

CVE-2014-1752
High 9.3

Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.20EPSS
CVE-2014-1751
High 9.3

Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0235 and C…

microsoft internet_explorer
0.20EPSS
CVE-2021-41355
Medium 5.7

.NET Core and Visual Studio Information Disclosure Vulnerability

microsoft .net · microsoft powershell · microsoft visual_studio_2019
0.20EPSS
CVE-2017-8725
High 7.8

A remote code execution vulnerability exists in Microsoft Publisher 2007 Service Pack 3 and Microsoft Publisher 2010 Service Pack 2 when they fail to properly handle objects in memory, aka "Microsoft Office Publisher Remote Code Execution".

microsoft publisher
0.20EPSS
CVE-2017-8567
High 7.8

A remote code execution vulnerability exists in Microsoft Excel for Mac 2011 when it fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution".

microsoft excel_for_mac
0.20EPSS
CVE-2010-1881
High 9.3

The FieldList ActiveX control in the Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 does not properly interact with the memory-access approach used by Internet Explorer and Office during instantiation, which allows remote at…

microsoft access
0.20EPSS
CVE-2005-0551
High 10.0

Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000, Windows XP SP1 and SP2, and Windows Server 2003 allows local users to gain privileges via a specially-designed application that provides co…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.20EPSS
CVE-2010-0816
High 9.3

Integer overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7; and Windows Mail on Windows Vista SP1 and SP2, Wi…

microsoft outlook_express · microsoft windows_live_mail · microsoft windows_mail
0.20EPSS
CVE-2014-6331
Medium 5.0

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not properly process logoff actions, which makes it easier for remote attackers to obtain access by leveraging an una…

microsoft active_directory_federation_services
0.20EPSS
CVE-2024-38200
Medium 6.5

Microsoft Office Spoofing Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.20EPSS
CVE-2012-0020
High 9.3

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a diffe…

microsoft visio_viewer
0.20EPSS
CVE-2012-0019
High 9.3

Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a diffe…

microsoft visio_viewer
0.20EPSS
CVE-2010-1879
High 9.3

Unspecified vulnerability in Quartz.dll for DirectShow; Windows Media Format Runtime 9, 9.5, and 11; Media Encoder 9; and the Asycfilt.dll COM component allows remote attackers to execute arbitrary code via a media file with crafted compression data, aka "Medi…

microsoft directx · microsoft windows_media_encoder · microsoft windows_media_format_runtime
0.20EPSS
CVE-2010-3234
High 9.3

Microsoft Excel 2002 SP3 does not properly validate formula information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Formula Substream Memory Corruption Vulnerability."

microsoft excel
0.20EPSS
CVE-2010-3231
High 9.3

Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memo…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.20EPSS
CVE-2020-1439
High 8.8

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.20EPSS
CVE-2014-1815
High 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as exploited in the wild in May 2014, aka "Internet Explorer Memory Corruption Vulnerability," a…

microsoft internet_explorer
0.20EPSS
CVE-2006-5544
Medium 6.4

Visual truncation vulnerability in Microsoft Internet Explorer 7 allows remote attackers to spoof the address bar and possibly conduct phishing attacks via a malicious URL containing non-breaking spaces (%A0), which causes the address bar to omit some characte…

microsoft ie
0.20EPSS
CVE-2002-0698
High 7.5

Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC…

microsoft exchange_server
0.20EPSS
CVE-2026-45502
Medium 5.0

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

microsoft exchange_server · microsoft exchange_server_subscription_edition
0.20EPSS
CVE-2015-2542
High 9.3

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.20EPSS
CVE-2015-2494
High 9.3

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015…

microsoft edge · microsoft internet_explorer
0.20EPSS
CVE-2015-2486
High 9.3

Microsoft Internet Explorer 7 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015…

microsoft edge · microsoft internet_explorer
0.20EPSS
CVE-2015-2372
High 9.3

vbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory …

microsoft vbscript
0.20EPSS
CVE-2004-0985
High 10.0

Internet Explorer 6.x on Windows XP SP2 allows remote attackers to execute arbitrary code, as demonstrated using a document with a draggable file type such as .xml, .doc, .py, .cdf, .css, .pdf, or .ppt, and using ADODB.Connection and ADODB.recordset to write t…

microsoft ie
0.20EPSS