IT
56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

Microsoft vulnerabilities

15.453 CVE

Microsoft vulnerabilities
Identifier Severity Product and flaw EPSS In KEV since
CVE-2015-6046 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." 14.0%
CVE-2015-2375 MED 4.3 microsoft excel Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spre 14.0%
CVE-2008-5551 MED 4.3 microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expressi 14.0%
CVE-2016-7153 MED 5.3 apple safari The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookie 14.0%
CVE-2016-7152 MED 5.3 apple safari The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies 14.0%
CVE-2017-0211 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation 14.0%
CVE-2014-0301 HIGH 9.3 microsoft windows_7 Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a 14.0%
CVE-2011-1252 MED 6.1 microsoft internet_explorer Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint 14.0%
CVE-2000-1112 MED 4.6 microsoft windows_media_player Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. 14.0%
CVE-2018-8283 HIGH 7.5 microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8287, CV 14.0%
CVE-2020-17136 HIGH 7.8 microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 14.0%
CVE-2017-0057 MED 4.3 microsoft windows_10 DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a work 14.0%
CVE-2019-1182 CRIT 9.8 microsoft windows_10 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authenticat 13.9%
CVE-2010-0818 HIGH 9.3 microsoft windows_server_2003 The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execu 13.9%
CVE-2008-1933 MED 4.3 microsoft zune_software Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run. 13.9%
CVE-2016-0148 HIGH 7.8 microsoft .net_framework Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability." 13.9%
CVE-2017-0264 HIGH 7.8 microsoft powerpoint_for_mac Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265. 13.9%
CVE-2021-26897 CRIT 9.8 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 13.9%
CVE-2019-1149 HIGH 8.8 microsoft office A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install p 13.9%
CVE-2016-7181 HIGH 7.5 microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." 13.9%
CVE-2015-6048 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015 13.9%
CVE-2002-2081 MED 5.0 microsoft site_server cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp. 13.9%
CVE-2002-1140 MED 5.0 microsoft services The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check lea 13.9%
CVE-2002-1141 MED 5.0 microsoft services An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial 13.9%
CVE-2001-1539 MED 5.0 microsoft internet_explorer Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem. 13.9%