58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
Microsoft vulnerabilities
16.473 CVE
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-2160 | HIGH 9.3 | microsoft windows_embedded_compact Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images. | 18.0% | — |
| CVE-2024-29990 | CRIT 9.0 | microsoft azure_kubernetes_service_confidential_containers Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | 18.0% | — |
| CVE-2001-1533 | MED 5.3 | microsoft isa_server Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server | 18.0% | — |
| CVE-2019-1462 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka 'Microsoft PowerPoint Remote Code Execution Vulnerability'. | 18.0% | — |
| CVE-2002-0697 | HIGH 10.0 | microsoft metadirectory_services Microsoft Metadirectory Services (MMS) 2.2 allows remote attackers to bypass authentication and modify sensitive data by using an LDAP client to directly connect to MMS and bypass the checks for MMS credentials. | 18.0% | — |
| CVE-2011-1266 | HIGH 9.3 | microsoft internet_explorer The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initializ | 18.0% | — |
| CVE-2011-1254 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Drag and Drop Memory Corruption Vul | 18.0% | — |
| CVE-2011-1251 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory Corruption Vulnerabil | 18.0% | — |
| CVE-2016-7277 | CRIT 9.6 | microsoft office Microsoft Office 2016 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | 18.0% | — |
| CVE-2003-0110 | MED 5.0 | microsoft isa_server The Winsock Proxy service in Microsoft Proxy Server 2.0 and the Microsoft Firewall service in Internet Security and Acceleration (ISA) Server 2000 allow remote attackers to cause a denial of service (CPU consumption or packet storm) via a spoofed, malformed pa | 18.0% | — |
| CVE-2018-0922 | HIGH 7.8 | microsoft office Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Micr | 18.0% | — |
| CVE-2003-0817 | HIGH 7.5 | microsoft ie Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions and read arbitrary files via an XML object. | 18.0% | — |
| CVE-2010-2091 | MED 4.3 | microsoft exchange_server Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly handle the id parameter in a Folder IPF.Note action to the default URI, which might allow remote attackers to obtain sensitive information | 17.9% | — |
| CVE-2000-0404 | MED 5.0 | microsoft terminal_server The CIFS Computer Browser service allows remote attackers to cause a denial of service by sending a ResetBrowser frame to the Master Browser, aka the "ResetBrowser Frame" vulnerability. | 17.9% | — |
| CVE-2000-0403 | MED 5.0 | microsoft windows_nt The CIFS Computer Browser service on Windows NT 4.0 allows a remote attacker to cause a denial of service by sending a large number of host announcement requests to the master browse tables, aka the "HostAnnouncement Flooding" or "HostAnnouncement Frame" vulne | 17.9% | — |
| CVE-1999-0349 | HIGH 7.5 | microsoft internet_information_server A buffer overflow in the FTP list (ls) command in IIS allows remote attackers to conduct a denial of service and, in some cases, execute arbitrary commands. | 17.9% | — |
| CVE-2010-0256 | HIGH 7.6 | microsoft visio Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly calculate unspecified indexes associated with Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Index Calculation Memory Corrupt | 17.9% | — |
| CVE-2010-0254 | HIGH 7.6 | microsoft visio Microsoft Office Visio 2002 SP2, 2003 SP3, and 2007 SP1 and SP2 does not properly validate attributes in Visio files, which allows remote attackers to execute arbitrary code via a crafted file, aka "Visio Attribute Validation Memory Corruption Vulnerability." | 17.9% | — |
| CVE-2015-4796 | HIGH 9.0 | microsoft windows Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vu | 17.9% | — |
| CVE-2007-1117 | HIGH 10.0 | microsoft publisher Unspecified vulnerability in Publisher 2007 in Microsoft Office 2007 allows remote attackers to execute arbitrary code via unspecified vectors, related to a "file format vulnerability." NOTE: this information is based upon a vague pre-advisory with no actionab | 17.9% | — |
| CVE-2017-8744 | HIGH 7.8 | microsoft office A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, and Microsoft Excel 2016 when they fail to pr | 17.9% | — |
| CVE-2016-0050 | MED 5.3 | microsoft windows_server_2008 Network Policy Server (NPS) in Microsoft Windows Server 2008 SP2 and R2 SP1 and Server 2012 Gold and R2 misparses username queries, which allows remote attackers to cause a denial of service (RADIUS authentication outage) via crafted requests, aka "Network Pol | 17.9% | — |
| CVE-2015-2412 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allows remote attackers to read arbitrary local files via a crafted pathname, aka "Internet Explorer Information Disclosure Vulnerability." | 17.9% | — |
| CVE-2014-6333 | HIGH 9.3 | microsoft office_compatibility_pack Microsoft Word 2007 SP3, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Double Delete Remote Code Execution Vulnerability." | 17.9% | — |
| CVE-2017-0160 | HIGH 7.8 | microsoft .net_framework Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability." | 17.8% | — |