imPC@ndo IT

Microsoft vulnerabilities

15.453 CVE

CVE-2017-0197
High 7.8

Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office DLL Loading Vulnerability."

microsoft onenote
0.19EPSS
CVE-2016-3356
High 7.8

The Graphics Device Interface (GDI) in Microsoft Windows 10 1607 allows remote attackers to execute arbitrary code via a crafted document, aka "GDI Remote Code Execution Vulnerability."

microsoft windows_10
0.19EPSS
CVE-2019-1331
High 8.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1327.

microsoft excel · microsoft excel_services · microsoft office · microsoft office_365_proplus · and 1 more
0.19EPSS
CVE-2018-8332
High 8.8

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Win32k Graphics Remote Code Execution Vulnerability." This affects Windows 7, Microsoft Office, Windows Server 2012 R2, Windows…

microsoft office · microsoft office_for_mac · microsoft windows_10 · microsoft windows_7 · and 2 more
0.19EPSS
CVE-2010-1260
High 7.5

The IE8 Developer Toolbar in Microsoft Internet Explorer 8 SP1, SP2, and SP3 allows user-assisted remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML…

microsoft internet_explorer
0.19EPSS
CVE-2019-0595
High 7.8

A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory, aka 'Jet Database Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0596, CVE-2019-0597, CVE-2019-0598, CVE-2…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.19EPSS
CVE-2018-8577
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_365_proplus · and 2 more
0.19EPSS
CVE-2018-8576
High 7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. Th…

microsoft office · microsoft office_365_proplus · microsoft outlook
0.19EPSS
CVE-2018-8574
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel…

microsoft office · microsoft office_365_proplus
0.19EPSS
CVE-2018-8573
High 7.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office. This CVE ID…

microsoft office · microsoft office_365_proplus · microsoft word
0.19EPSS
CVE-2018-8553
High 7.8

A remote code execution vulnerability exists in the way that Microsoft Graphics Components handle objects in memory, aka "Microsoft Graphics Components Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Window…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.19EPSS
CVE-2018-8539
High 7.8

A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Microsoft Office. This CVE ID is uni…

microsoft office · microsoft office_web_apps · microsoft sharepoint_server
0.19EPSS
CVE-2018-8524
High 7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. Th…

microsoft office · microsoft office_365_proplus · microsoft outlook · microsoft outlook_rt
0.19EPSS
CVE-2018-8522
High 7.8

A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka "Microsoft Outlook Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Outlook. Th…

microsoft office · microsoft office_365_proplus · microsoft outlook · microsoft outlook_rt
0.19EPSS
CVE-2020-1219
High 7.5

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka 'Microsoft Browser Memory Corruption Vulnerability'.

microsoft chakracore · microsoft edge · microsoft internet_explorer
0.19EPSS
CVE-2006-0020
High 9.3

An unspecified Microsoft WMF parsing application, as used in Internet Explorer 5.01 SP4 on Windows 2000 SP4, and 5.5 SP2 on Windows Millennium, and possibly other versions, allows attackers to cause a denial of service (crash) and possibly execute code via a c…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 2 more
0.19EPSS
CVE-2003-1028
Medium 5.0

The download function of Internet Explorer 6 SP1 allows remote attackers to obtain the cache directory name via an HTTP response with an invalid ContentType and a .htm file, which could allow remote attackers to bypass security mechanisms that rely on random n…

microsoft ie · microsoft internet_explorer
0.19EPSS
CVE-2000-0132
Low 2.6

Microsoft Java Virtual Machine allows remote attackers to read files via the getSystemResourceAsStream function.

microsoft virtual_machine
0.19EPSS
CVE-2010-0246
High 9.3

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized M…

microsoft internet_explorer
0.19EPSS
CVE-2010-0245
High 9.3

Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized M…

microsoft internet_explorer
0.19EPSS
CVE-2005-1215
High 7.5

Microsoft ISA Server 2000 allows remote attackers to poison the ISA cache or bypass content restriction policies via a malformed HTTP request packet containing multiple Content-Length headers.

microsoft isa_server
0.19EPSS
CVE-1999-0450
High 7.5

In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl (perl.exe).

microsoft internet_information_server · microsoft internet_information_services
0.19EPSS
CVE-2019-1372
Critical 10.0

An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run …

microsoft azure_app_service_on_azure_stack
0.19EPSS
CVE-2017-8527
High 8.8

Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows a remote code execution vulnerability due to the way it handles objec…

microsoft lync · microsoft office · microsoft silverlight · microsoft skype_for_business · and 7 more
0.19EPSS
CVE-2017-0204
Medium 5.5

Microsoft Outlook 2007 SP3, Microsoft Outlook 2010 SP2, Microsoft Outlook 2013 SP1, and Microsoft Outlook 2016 allow remote attackers to bypass the Office Protected View via a specially crafted document, aka "Microsoft Office Security Feature Bypass Vulnerabil…

microsoft outlook
0.19EPSS