IT

Microsoft vulnerabilities

15.453 CVE

CVE-2000-0222
High 10.0

The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs.

microsoft windows_2000
0.15EPSS
CVE-2018-1023
High 7.5

A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory, aka "Microsoft Browser Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore.

microsoft chakracore · microsoft edge
0.15EPSS
CVE-2002-0723
High 7.5

Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag."

microsoft internet_explorer
0.15EPSS
CVE-2002-1187
Medium 6.8

Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demon…

microsoft internet_explorer
0.15EPSS
CVE-2001-0339
High 7.5

Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability."

microsoft internet_explorer
0.15EPSS
CVE-2018-0744
High 7.0

The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memo…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 1 more
0.15EPSS
CVE-2000-0330
High 7.6

The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability.

microsoft windows_95 · microsoft windows_98
0.15EPSS
CVE-2007-5158
Medium 4.3

The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upl…

microsoft internet_explorer
0.15EPSS
CVE-2018-8231
High 8.1

A remote code execution vulnerability exists when HTTP Protocol Stack (Http.sys) improperly handles objects in memory, aka "HTTP Protocol Stack Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

microsoft windows_10 · microsoft windows_server_1803 · microsoft windows_server_2016
0.15EPSS
CVE-2016-3295
High 7.5

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

microsoft edge · microsoft internet_explorer
0.15EPSS
CVE-2025-21309
High 8.1

Windows Remote Desktop Services Remote Code Execution Vulnerability

microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · microsoft windows_server_2022 · and 2 more
0.15EPSS
CVE-2023-28220
High 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.15EPSS
CVE-2023-28219
High 8.1

Layer 2 Tunneling Protocol Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 9 more
0.15EPSS
CVE-2000-0849
Low 2.6

Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability.

microsoft windows_media_services
0.15EPSS
CVE-2016-7284
Medium 4.3

Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.15EPSS
CVE-2016-3381
High 7.8

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerabil…

microsoft excel · microsoft excel_viewer · microsoft office_compatibility_pack
0.15EPSS
CVE-2002-0974
Medium 5.0

Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm.

microsoft windows_xp
0.15EPSS
CVE-1999-0755
Medium 5.0

Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option.

microsoft windows_2000 · microsoft windows_nt
0.15EPSS
CVE-2015-1729
Medium 4.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

microsoft internet_explorer
0.15EPSS
CVE-2019-1347
Medium 6.5

A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-1343, CVE-2019-1346.

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 2 more
0.15EPSS
CVE-2000-0085
High 7.5

Hotmail does not properly filter JavaScript code from a user's mailbox, which allows a remote attacker to execute code via the LOWSRC or DYNRC parameters in the IMG tag.

microsoft hotmail
0.15EPSS
CVE-2006-3659
Medium 5.0

Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the location or URL property of a MHTMLFile ActiveX object.

microsoft ie · microsoft internet_explorer
0.15EPSS
CVE-2009-1335
Medium 4.3

Microsoft Internet Explorer 7 and 8 on Windows XP and Vista allows remote attackers to cause a denial of service (application hang) via a large document composed of unprintable characters, aka MSRC 9011jr.

microsoft internet_explorer
0.15EPSS
CVE-2015-6052
Medium 4.3

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "VBScript and JScript ASLR Bypa…

microsoft internet_explorer · microsoft jscript · microsoft vbscript
0.15EPSS
CVE-2016-0068
High 8.8

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.

microsoft internet_explorer
0.15EPSS