IT

Microsoft vulnerabilities

15.453 CVE

CVE-2013-1289
Medium 4.3

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTM…

microsoft groove_server · microsoft infopath · microsoft office_web_apps · microsoft sharepoint_foundation · and 1 more
0.15EPSS
CVE-2018-0857
High 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CV…

microsoft chakracore · microsoft edge
0.15EPSS
CVE-2018-0856
High 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 1703 and 1709 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2…

microsoft chakracore · microsoft edge
0.15EPSS
CVE-2018-0836
High 7.5

Microsoft Edge and ChakraCore in Microsoft Windows 10 1703 and 1709 allows remote code execution, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0834, CVE-2…

microsoft chakracore · microsoft edge
0.15EPSS
CVE-2014-1778
Medium 6.8

Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary web script with increased privileges via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2014-2777.

microsoft internet_explorer
0.15EPSS
CVE-2007-2237
Medium 5.5

Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.

microsoft windows_xp
0.15EPSS
CVE-2019-0613
High 8.8

A remote code execution vulnerability exists in .NET Framework and Visual Studio software when the software fails to check the source markup of a file.An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the curre…

microsoft .net_framework · microsoft visual_studio_2017
0.15EPSS
CVE-2018-8469
High 7.4

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique …

microsoft edge
0.15EPSS
CVE-2018-8463
High 7.4

An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge. This CVE ID is unique …

microsoft edge
0.15EPSS
CVE-2018-8245
High 7.8

A remote code execution vulnerability exists when Microsoft Publisher fails to utilize features that lock down the Local Machine zone when instantiating OLE objects, aka "Microsoft Publisher Remote Code Execution Vulnerability." This affects Microsoft Publishe…

microsoft publisher
0.15EPSS
CVE-2012-1861
Medium 4.3

Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elem…

microsoft office_web_apps · microsoft sharepoint_foundation · microsoft sharepoint_server
0.15EPSS
CVE-2019-0586
Critical 9.8

A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.

microsoft exchange_server
0.15EPSS
CVE-2006-2055
Medium 5.0

Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote attackers to modify command line arguments to an invoked mail client via " (double quote) characters in a mailto: scheme handler, as demonstrated by launching Microsoft …

microsoft outlook
0.15EPSS
CVE-2016-0080
Medium 4.3

Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass."

microsoft edge
0.15EPSS
CVE-2008-2841
Medium 6.8

Argument injection vulnerability in XChat 2.8.7b and earlier on Windows, when Internet Explorer is used, allows remote attackers to execute arbitrary commands via the --command parameter in an ircs:// URI.

microsoft internet_explorer · xchat xchat
0.15EPSS
CVE-2018-8122
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-094…

microsoft internet_explorer
0.15EPSS
CVE-2018-8114
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 11. This CVE ID is unique from CVE-2018-094…

microsoft internet_explorer
0.15EPSS
CVE-2018-0955
High 7.5

A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer …

microsoft internet_explorer
0.15EPSS
CVE-2014-0260
High 9.3

Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office Compatibility Pack SP3; Word Viewer; SharePoint Server 2010 SP1 and SP2 and 2013; Office Web Apps 2010 SP1 and SP2; and Office Web Apps Server 2013 allow remote attackers to execute…

microsoft office_compatibility_pack · microsoft office_web_apps · microsoft office_web_apps_server · microsoft sharepoint_server · and 2 more
0.15EPSS
CVE-2019-0662
High 8.8

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0618.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.15EPSS
CVE-2003-1448
High 7.8

Memory leak in the Windows 2000 kernel allows remote attackers to cause a denial of service (SMB request hang) via a NetBIOS continuation packet.

microsoft windows_2000
0.15EPSS
CVE-2010-3141
High 9.3

Untrusted search path vulnerability in Microsoft PowerPoint 2010 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse pptimpconv.dll that is located in the same folder as a .odp, .pot…

microsoft powerpoint
0.15EPSS
CVE-2015-0080
Medium 4.3

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG image…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 5 more
0.15EPSS
CVE-2015-0076
Medium 4.3

The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR im…

microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · microsoft windows_rt · and 4 more
0.15EPSS
CVE-2009-0419
Medium 5.0

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict access from web pages to Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive in…

microsoft xml_core_services
0.15EPSS