imPC@ndo IT

Microsoft vulnerabilities

15.453 CVE

CVE-2002-0695
High 7.5

Buffer overflow in the Transact-SQL (T-SQL) OpenRowSet component of Microsoft Data Access Components (MDAC) 2.5 through 2.7 for SQL Server 7.0 or 2000 allows remote attackers to execute arbitrary code via a query that calls the OpenRowSet command.

microsoft data_access_components · microsoft microsoft_data_access_components
0.17EPSS
CVE-2002-0020
High 7.5

Buffer overflow in telnet server in Windows 2000 and Interix 2.2 allows remote attackers to execute arbitrary code via malformed protocol options.

microsoft interix · microsoft windows_2000
0.17EPSS
CVE-2019-1128
High 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.17EPSS
CVE-2019-1123
High 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.17EPSS
CVE-2019-1122
High 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1121, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.17EPSS
CVE-2019-1121
High 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1120, CVE-2019-1122, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.17EPSS
CVE-2019-1120
High 8.8

A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1117, CVE-2019-1118, CVE-2019-1119, CVE-2019-1121, CVE-2019-1122, CVE…

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.17EPSS
CVE-2011-1262
High 9.3

Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "HTTP Redirect Memory Corruption Vul…

microsoft internet_explorer
0.17EPSS
CVE-2011-1261
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Selection Object Memory Corruption …

microsoft internet_explorer
0.17EPSS
CVE-2008-4301
High 10.0

A certain ActiveX control in iisext.dll in Microsoft Internet Information Services (IIS) allows remote attackers to set a password via a string argument to the SetPassword method. NOTE: this issue could not be reproduced by a reliable third party. In additio…

microsoft internet_information_services
0.17EPSS
CVE-2002-0621
Medium 5.0

Buffer overflow in the Office Web Components (OWC) package installer used by Microsoft Commerce Server 2000 allows remote attackers to cause the process to fail or run arbitrary code in the LocalSystem security context via certain input to the OWC package inst…

microsoft commerce_server
0.17EPSS
CVE-2012-0012
Medium 4.3

Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerabi…

microsoft internet_explorer
0.17EPSS
CVE-2011-0653
Medium 4.3

Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010, allows remote attackers to inject arbitrary web script or HTML via the URI, aka "XSS in SharePoint Calendar Vulnerability."

microsoft sharepoint_foundation · microsoft sharepoint_server
0.17EPSS
CVE-2017-8692
High 7.5

The Windows Uniscribe component on Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote code execution vulnerability when it fails to properly handle objects in mem…

microsoft windows_10 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · microsoft windows_server_2016
0.17EPSS
CVE-2017-0247
High 7.5

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package …

microsoft asp.net_model_view_controller · microsoft microsoft.aspnetcore.mvc.abstractions · microsoft microsoft.aspnetcore.mvc.apiexplorer · microsoft microsoft.aspnetcore.mvc.cors · and 14 more
0.17EPSS
CVE-2015-2479
High 9.3

The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execute arbitrary code via a crafted .NET application, aka "RyuJIT Optimization Elevation of Privilege Vulnerability…

microsoft .net_framework
0.17EPSS
CVE-2014-0280
High 9.3

Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

microsoft internet_explorer
0.17EPSS
CVE-2014-0278
High 9.3

Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-0277 and C…

microsoft internet_explorer
0.17EPSS
CVE-2016-0192
High 7.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2008-0250
High 9.3

Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a Studio Solution (.SLN) file with a long Project line.

microsoft visual_interdev
0.17EPSS
CVE-2015-1646
Medium 4.3

Microsoft XML Core Services (aka MSXML) 3.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted DTD, aka "MSXML3 Same Origin Policy SFB Vulnerability."

microsoft xml_core_services
0.17EPSS
CVE-2020-0881
High 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0883.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.17EPSS
CVE-2016-3390
High 7.5

The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by the Chakra JavaScript engine, aka "Scripting…

microsoft edge · microsoft internet_explorer
0.17EPSS
CVE-2017-8537
Medium 5.5

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft endpoint_protection · microsoft exchange_server · microsoft forefront_endpoint_protection · microsoft security_essentials · and 3 more
0.17EPSS
CVE-2017-8536
Medium 5.5

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a…

microsoft endpoint_protection · microsoft exchange_server · microsoft forefront_endpoint_protection · microsoft security_essentials · and 3 more
0.17EPSS