imPC@ndo IT

Microsoft vulnerabilities

15.453 CVE

CVE-2022-24481
High 7.8

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 6 more
0.17EPSS
CVE-2005-1191
Medium 5.0

The Web View DLL (webvw.dll), as used in Windows Explorer on Windows 2000 systems, does not properly filter an apostrophe ("'") in the author name in a document, which allows attackers to execute arbitrary script via extra attributes when Web View constructs a…

microsoft windows_2000 · microsoft windows_98 · microsoft windows_98se · microsoft windows_me
0.17EPSS
CVE-2020-0605
High 8.8

A remote code execution vulnerability exists in .NET software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user, aka '.NET Framework…

microsoft .net_core · microsoft .net_framework
0.17EPSS
CVE-2013-0008
High 7.2

win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle window broadcast messages, which allows local users t…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2008 · and 2 more
0.17EPSS
CVE-2018-8379
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-…

microsoft excel · microsoft excel_2013_rt
0.17EPSS
CVE-2006-3910
Medium 5.0

Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference.

microsoft ie
0.17EPSS
CVE-2006-3354
Medium 5.0

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset ActiveX object to certain values multiple times, which triggers a null dereference.

canon network_camera_server_vb101 · microsoft ie · microsoft internet_explorer
0.17EPSS
CVE-2009-2509
High 9.0

Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS…

microsoft windows_server_2003 · microsoft windows_server_2008
0.17EPSS
CVE-2016-3382
High 7.5

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka …

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2015-1673
High 9.3

The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted remote attackers to execute arbitrary code via a crafted partial-trust application, aka "Windows Forms Elevation o…

microsoft .net_framework
0.17EPSS
CVE-2011-0031
Medium 4.3

The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensit…

microsoft windows_7 · microsoft windows_server_2008
0.17EPSS
CVE-2009-0093
Low 3.5

Windows DNS Server in Microsoft Windows 2000 SP4, Server 2003 SP1 and SP2, and Server 2008, when dynamic updates are enabled, does not restrict registration of the "wpad" hostname, which allows remote authenticated users to hijack the Web Proxy Auto-Discovery …

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008
0.17EPSS
CVE-2016-3375
High 7.5

The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 151…

microsoft internet_explorer · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · and 4 more
0.17EPSS
CVE-2010-1258
Medium 4.3

Microsoft Internet Explorer 6, 7, and 8 does not properly determine the origin of script code, which allows remote attackers to execute script in an unintended domain or security zone, and obtain sensitive information, via unspecified vectors, aka "Event Handl…

microsoft internet_explorer
0.17EPSS
CVE-2017-0228
High 7.5

A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0229, CVE-2017-0…

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2017-8631
High 7.8

A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Ap…

microsoft excel · microsoft excel_viewer · microsoft excel_web_app · microsoft office_compatibility_pack · and 2 more
0.17EPSS
CVE-2013-1290
Low 3.5

Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via …

microsoft sharepoint_server
0.17EPSS
CVE-2019-1306
Critical 9.8

A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.

microsoft azure_devops_server · microsoft team_foundation_server
0.17EPSS
CVE-2001-0509
Medium 5.0

Vulnerabilities in RPC servers in (1) Microsoft Exchange Server 2000 and earlier, (2) Microsoft SQL Server 2000 and earlier, (3) Windows NT 4.0, and (4) Windows 2000 allow remote attackers to cause a denial of service via malformed inputs.

microsoft exchange_server · microsoft sql_server · microsoft windows_2000 · microsoft windows_nt
0.17EPSS
CVE-2006-6659
Medium 5.0

The Microsoft Office Outlook Recipient ActiveX control (ole32.dll) in Windows XP SP2 allows remote attackers to cause a denial of service (Internet Explorer 7 hang) via crafted HTML.

microsoft ie · microsoft outlook · microsoft windows_xp
0.17EPSS
CVE-2011-1279
High 9.3

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a…

microsoft excel · microsoft office · microsoft open_xml_file_format_converter
0.17EPSS
CVE-2011-1278
High 9.3

Microsoft Excel 2002 SP3 and Office 2004 for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadshee…

microsoft excel · microsoft office
0.17EPSS
CVE-2011-1273
High 9.3

Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate …

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack · and 1 more
0.17EPSS
CVE-2016-7195
High 7.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2020-0652
High 7.8

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.

microsoft excel · microsoft office_365_proplus
0.17EPSS