imPC@ndo IT

Microsoft vulnerabilities

15.453 CVE

CVE-2015-1698
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journ…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 4 more
0.18EPSS
CVE-2015-1697
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journ…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 4 more
0.18EPSS
CVE-2015-1696
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted Journal file, aka "Windows Journ…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 4 more
0.18EPSS
CVE-2008-3957
High 9.3

The Microsoft Windows Image Acquisition Logger ActiveX control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the firs…

microsoft windows_image_acquisition_logger
0.18EPSS
CVE-2003-1105
Low 2.6

Unknown vulnerability in Internet Explorer 5.01 SP3 through 6.0 SP1 allows remote attackers to cause a denial of service (browser or Outlook Express crash) via HTML with certain input tags that are not properly rendered.

microsoft ie · microsoft internet_explorer
0.18EPSS
CVE-2002-0153
High 7.5

Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts within a specific HTML element, aka the "Local Applescript Invocation" vulnerability.

microsoft ie
0.18EPSS
CVE-1999-1127
High 7.5

Windows NT 4.0 does not properly shut down invalid named pipe RPC connections, which allows remote attackers to cause a denial of service (resource exhaustion) via a series of connections containing malformed data, aka the "Named Pipes Over RPC" vulnerability.…

microsoft windows_nt
0.18EPSS
CVE-2018-0859
High 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.18EPSS
CVE-1999-1451
Medium 5.0

The Winmsdp.exe sample file in IIS 4.0 and Site Server 3.0 allows remote attackers to read arbitrary files.

microsoft internet_information_server · microsoft site_server
0.18EPSS
CVE-2016-3289
High 7.5

Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3322.

microsoft edge · microsoft internet_explorer
0.18EPSS
CVE-2023-35636
Medium 6.5

Microsoft Outlook Information Disclosure Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.18EPSS
CVE-2015-1728
High 9.3

Microsoft Windows Media Player 10 through 12 allows remote attackers to execute arbitrary code via a crafted DataObject on a web site, aka "Windows Media Player RCE via DataObject Vulnerability."

microsoft windows_media_player
0.18EPSS
CVE-1999-0877
Medium 4.3

Internet Explorer 5 allows remote attackers to read files via an ExecCommand method called on an IFRAME.

microsoft internet_explorer
0.18EPSS
CVE-2001-1489
Medium 5.0

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a large number of images.

microsoft ie
0.18EPSS
CVE-2017-8632
High 7.8

A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011, Microsoft Exce…

microsoft excel · microsoft excel_for_mac · microsoft office_compatibility_pack · microsoft office_web_apps
0.18EPSS
CVE-2002-1705
Medium 5.0

Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading Style Sheet (CSS) with the p{cssText} element declared and a bold font weight.

microsoft internet_explorer
0.18EPSS
CVE-2010-2562
High 9.3

Microsoft Office Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse the Excel file format, which allows remote attackers to execute arbitrary code or cause a denial of service (memory cor…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.18EPSS
CVE-2011-1960
Medium 4.3

Microsoft Internet Explorer 6 through 9 does not properly implement JavaScript event handlers, which allows remote attackers to access content from a different (1) domain or (2) zone via unspecified script code, aka "Event Handlers Information Disclosure Vulne…

microsoft internet_explorer
0.18EPSS
CVE-2020-0767
High 7.5

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0674, CVE-2020-0710, CVE-2020-071…

microsoft chakracore · microsoft edge
0.18EPSS
CVE-2000-0347
Medium 5.0

Windows 95 and Windows 98 allow a remote attacker to cause a denial of service via a NetBIOS session request packet with a NULL source name.

microsoft windows_95 · microsoft windows_98
0.18EPSS
CVE-2017-0014
High 7.5

The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute ar…

microsoft office · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · and 4 more
0.18EPSS
CVE-2001-0150
Medium 5.1

Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are specified by the web site, which could allow remote attackers to execute arbitrary commands if the IE client is using the Telnet client provided in Services for Un…

microsoft internet_explorer
0.18EPSS
CVE-2014-8452
Medium 5.0

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issu…

adobe acrobat · adobe acrobat_reader · apple mac_os_x · microsoft windows
0.18EPSS
CVE-2011-1272
High 9.3

Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record struct…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.18EPSS
CVE-2001-0243
Medium 5.0

Windows Media Player 7 and earlier stores Internet shortcuts in a user's Temporary Files folder with a fixed filename instead of in the Internet Explorer cache, which causes the HTML in those shortcuts to run in the Local Computer Zone instead of the Internet …

microsoft windows_media_player
0.18EPSS