IT
58.587 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2000-0770 MED 6.4 microsoft internet_information_server IIS 4.0 and 5.0 does not properly restrict access to certain types of files when their parent folders have less restrictive permissions, which could allow remote attackers to bypass access restrictions to some files, aka the "File Permission Canonicalization" 15.1% —
CVE-2016-0158 MED 6.5 microsoft edge Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161. 15.1% —
CVE-2010-3140 HIGH 9.3 microsoft windows_xp Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse schannel.dll that is lo 15.1% —
CVE-2021-38666 HIGH 8.8 microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability 15.1% —
CVE-2000-0222 HIGH 10.0 microsoft windows_2000 The installation for Windows 2000 does not activate the Administrator password until the system has rebooted, which allows remote attackers to connect to the ADMIN$ share without a password until the reboot occurs. 15.0% —
CVE-2002-0723 HIGH 7.5 microsoft internet_explorer Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which allows remote attackers to read client files or invoke executable objects via the Object tag, aka "Cross Domain Verification in Object Tag." 15.0% —
CVE-2002-1187 MED 6.8 microsoft internet_explorer Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execute files on the local system via web pages using the <frame> or <iframe> element and javascript, aka "Frames Cross Site Scripting," as demon 15.0% —
CVE-2001-0339 HIGH 7.5 microsoft internet_explorer Internet Explorer 5.5 and earlier allows remote attackers to display a URL in the address bar that is different than the URL that is actually being displayed, which could be used in web site spoofing attacks, aka the "Web page spoofing vulnerability." 15.0% —
CVE-2018-0744 HIGH 7.0 microsoft windows_10 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memo 15.0% —
CVE-2013-3909 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 6 through 8 allows remote attackers to read content from a different (1) domain or (2) zone via crafted characters in Cascading Style Sheets (CSS) token sequences, aka "Internet Explorer Information Disclosure Vulnerability." 15.0% —
CVE-2000-0330 HIGH 7.6 microsoft windows_95 The networking software in Windows 95 and Windows 98 allows remote attackers to execute commands via a long file name string, aka the "File Access URL" vulnerability. 15.0% —
CVE-2016-0080 MED 4.3 microsoft edge Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass." 15.0% —
CVE-2007-5158 MED 4.3 microsoft internet_explorer The focus handling for the onkeydown event in Microsoft Internet Explorer 6.0 allows remote attackers to change field focus and copy keystrokes via a certain use of a JavaScript htmlFor attribute, as demonstrated by changing focus from a textarea to a file upl 15.0% —
CVE-2010-1098 HIGH 7.1 microsoft windows_vista The ANI parser in Microsoft Windows before 7 on the x86 platform, as used in Internet Explorer and other applications, allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted biClrUsed value in the BITMAPINFO header of a 15.0% —
CVE-2016-3295 HIGH 7.5 microsoft edge Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." 15.0% —
CVE-2023-28220 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 15.0% —
CVE-2023-28219 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 15.0% —
CVE-2000-0849 LOW 2.6 microsoft windows_media_services Race condition in Microsoft Windows Media server allows remote attackers to cause a denial of service in the Windows Media Unicast Service via a malformed request, aka the "Unicast Service Race Condition" vulnerability. 15.0% —
CVE-2016-7284 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." 15.0% —
CVE-2006-6602 MED 4.3 microsoft windows_explorer explorer.exe in Windows Explorer 6.00.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a crafted WMV file. 15.0% —
CVE-2016-3381 HIGH 7.8 microsoft excel Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerabil 15.0% —
CVE-2002-0974 MED 5.0 microsoft windows_xp Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm. 15.0% —
CVE-1999-0755 MED 5.0 microsoft windows_2000 Windows NT RRAS and RAS clients cache a user's password even if the user has not selected the "Save password" option. 15.0% —
CVE-2018-1001 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 15.0% —
CVE-2018-0996 HIGH 7.5 microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka "Scripting Engine Memory Corruption Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 15.0% —