imPC@ndo IT

Microsoft vulnerabilities

15.453 CVE

CVE-2011-1270
High 9.3

Buffer overflow in Microsoft PowerPoint 2002 SP3 and 2003 SP3 allows remote attackers to execute arbitrary code via a crafted PowerPoint document, aka "Presentation Buffer Overrun RCE Vulnerability."

microsoft powerpoint
0.16EPSS
CVE-2016-3214
High 8.8

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE…

microsoft edge
0.16EPSS
CVE-2015-2530
High 9.3

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows remote attackers to execute arbitrary code via a crafted …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · and 5 more
0.16EPSS
CVE-2012-2552
Medium 4.3

Cross-site scripting (XSS) vulnerability in the SQL Server Report Manager in Microsoft SQL Server 2000 Reporting Services SP2 and SQL Server 2005 SP4, 2008 SP2 and SP3, 2008 R2 SP1, and 2012 allows remote attackers to inject arbitrary web script or HTML via an…

microsoft sql_server · microsoft sql_server_reporting_services
0.16EPSS
CVE-2016-0139
High 7.8

Microsoft Excel 2010 SP2, Word for Mac 2011, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft excel · microsoft excel_viewer · microsoft word_for_mac
0.16EPSS
CVE-2016-0055
High 7.8

Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

microsoft office
0.16EPSS
CVE-2016-7242
High 7.5

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerabilit…

microsoft edge
0.16EPSS
CVE-1999-0233
High 10.0

IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.

microsoft internet_information_services
0.16EPSS
CVE-2005-3595
High 10.0

By default Microsoft Windows XP Home Edition installs with a blank password for the Administrator account, which allows remote attackers to gain control of the computer.

microsoft windows_xp
0.16EPSS
CVE-2015-1686
Medium 4.3

The Microsoft (1) VBScript 5.6 through 5.8 and (2) JScript 5.6 through 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript A…

microsoft internet_explorer · microsoft vbscript
0.16EPSS
CVE-2015-1684
Medium 4.3

VBScript.dll in the Microsoft VBScript 5.6 through 5.8 engine, as used in Internet Explorer 8 through 11 and other products, allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript ASLR Bypass."

microsoft internet_explorer · microsoft vbscript
0.16EPSS
CVE-2018-0903
High 7.8

Microsoft Access 2010 SP2, Microsoft Access 2013 SP1, Microsoft Access 2016, and Microsoft Office 2016 Click-to-Run allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Access Remote Code Execution Vulnerability"…

microsoft access · microsoft office
0.16EPSS
CVE-2024-21407
High 8.1

Windows Hyper-V Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 9 more
0.16EPSS
CVE-2006-0028
Medium 5.1

Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory…

microsoft excel · microsoft office
0.16EPSS
CVE-2018-8375
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft E…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.16EPSS
CVE-2019-0546
High 7.8

A remote code execution vulnerability exists in Visual Studio when the C++ compiler improperly handles specific combinations of C++ constructs, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio.

microsoft visual_studio_2017
0.16EPSS
CVE-1999-0444
Medium 5.0

Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.

microsoft windows_95 · microsoft windows_98 · microsoft windows_nt
0.16EPSS
CVE-1999-0357
Medium 5.0

Windows 98 and other operating systems allows remote attackers to cause a denial of service via crafted "oshare" packets, possibly involving invalid fragmentation offsets.

microsoft windows_98
0.16EPSS
CVE-2016-3366
Medium 6.5

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement RFC 2046, which allows remote attackers to bypass virus or spam detection via crafted MIME data in an e-mail a…

microsoft outlook
0.16EPSS
CVE-2000-0266
Low 2.6

Internet Explorer 5.01 allows remote attackers to bypass the cross frame security policy via a malicious applet that interacts with the Java JSObject to modify the DOM properties to set the IFRAME to an arbitrary Javascript URL.

microsoft internet_explorer
0.16EPSS
CVE-2015-0070
Medium 4.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability."

microsoft internet_explorer
0.16EPSS
CVE-2004-0474
Medium 5.1

Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" argument to the topic parameter in an hcp:// URL. NOTE: since the initial report of this problem, several researchers have been unable to rep…

microsoft windows_xp
0.16EPSS
CVE-2019-0790
High 8.8

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0791, CVE-2019-0792, CVE-2019-0793, CVE-2019-0795.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.16EPSS
CVE-2018-8636
High 7.8

A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel…

microsoft excel · microsoft office_365_proplus
0.16EPSS
CVE-2018-8628
High 7.8

A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Micro…

microsoft office · microsoft office_365_proplus · microsoft office_compatibility_pack · microsoft office_online_server · and 5 more
0.16EPSS