56.560 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
Microsoft vulnerabilities
15.453 CVE
| Identifier | Severity | Product and flaw | EPSS | In KEV since |
|---|---|---|---|---|
| CVE-2015-6046 | MED 4.3 | microsoft internet_explorer Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | 14.0% | — |
| CVE-2015-2375 | MED 4.3 | microsoft excel Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spre | 14.0% | — |
| CVE-2008-5551 | MED 4.3 | microsoft internet_explorer The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism and conduct XSS attacks by injecting data at two different positions within an HTML document, related to STYLE elements and the CSS expressi | 14.0% | — |
| CVE-2016-7153 | MED 5.3 | apple safari The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookie | 14.0% | — |
| CVE-2016-7152 | MED 5.3 | apple safari The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies | 14.0% | — |
| CVE-2017-0211 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 versions of Microsoft Windows OLE when it fails an integrity-level check, aka "Windows OLE Elevation | 14.0% | — |
| CVE-2014-0301 | HIGH 9.3 | microsoft windows_7 Double free vulnerability in qedit.dll in DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a | 14.0% | — |
| CVE-2011-1252 | MED 6.1 | microsoft internet_explorer Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint | 14.0% | — |
| CVE-2000-1112 | MED 4.6 | microsoft windows_media_player Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. | 14.0% | — |
| CVE-2018-8283 | HIGH 7.5 | microsoft chakracore A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore. This CVE ID is unique from CVE-2018-8242, CVE-2018-8287, CV | 14.0% | — |
| CVE-2020-17136 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 14.0% | — |
| CVE-2017-0057 | MED 4.3 | microsoft windows_10 DNS client in Microsoft Windows 8.1; Windows Server 2012 R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 fails to properly process DNS queries, which allows remote attackers to obtain sensitive information via (1) convincing a work | 14.0% | — |
| CVE-2019-1182 | CRIT 9.8 | microsoft windows_10 A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests. This vulnerability is pre-authenticat | 13.9% | — |
| CVE-2010-0818 | HIGH 9.3 | microsoft windows_server_2003 The MPEG-4 codec in the Windows Media codecs in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP1 and SP2, and Server 2008 Gold and SP2 does not properly handle crafted media content with MPEG-4 video encoding, which allows remote attackers to execu | 13.9% | — |
| CVE-2008-1933 | MED 4.3 | microsoft zune_software Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to overwrite arbitrary files via the SaveToFile method. NOTE: the victim must explicitly allow the code to run. | 13.9% | — |
| CVE-2016-0148 | HIGH 7.8 | microsoft .net_framework Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability." | 13.9% | — |
| CVE-2017-0264 | HIGH 7.8 | microsoft powerpoint_for_mac Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265. | 13.9% | — |
| CVE-2021-26897 | CRIT 9.8 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 13.9% | — |
| CVE-2019-1149 | HIGH 8.8 | microsoft office A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install p | 13.9% | — |
| CVE-2016-7181 | HIGH 7.5 | microsoft edge Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." | 13.9% | — |
| CVE-2015-6048 | HIGH 9.3 | microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015 | 13.9% | — |
| CVE-2002-2081 | MED 5.0 | microsoft site_server cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c:\temp. | 13.9% | — |
| CVE-2002-1140 | MED 5.0 | microsoft services The Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service (service hang) via malformed packet fragments, aka "Improper parameter size check lea | 13.9% | — |
| CVE-2002-1141 | MED 5.0 | microsoft services An input validation error in the Sun Microsystems RPC library Services for Unix 3.0 Interix SD, as implemented on Microsoft Windows NT4, 2000, and XP, allows remote attackers to cause a denial of service via malformed fragmented RPC client packets, aka "Denial | 13.9% | — |
| CVE-2001-1539 | MED 5.0 | microsoft internet_explorer Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem. | 13.9% | — |