IT
58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2016-3383 HIGH 7.5 microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability." 13.6% —
CVE-2022-37957 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 13.6% —
CVE-2006-1302 HIGH 9.3 microsoft excel Buffer overflow in Microsoft Excel 2000 through 2003 allows user-assisted attackers to execute arbitrary code via a .xls file with certain crafted fields in a SELECTION record, which triggers memory corruption, aka "Malformed SELECTION record Vulnerability." 13.6% —
CVE-1999-0140 MED 5.0 microsoft windows_nt Denial of service in RAS/PPTP on NT systems. 13.6% —
CVE-2014-6346 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 8 through 11 allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka "Internet Explorer Cross-domain Information Disclosure Vulnerability." 13.6% —
CVE-2014-6323 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 7 through 11 allows remote attackers to obtain sensitive clipboard information via a crafted web site, aka "Internet Explorer Clipboard Information Disclosure Vulnerability." 13.6% —
CVE-2008-4300 MED 5.0 microsoft internet_information_services A certain ActiveX control in adsiis.dll in Microsoft Internet Information Services (IIS) allows remote attackers to cause a denial of service (browser crash) via a long string in the second argument to the GetObject method. NOTE: this issue was disclosed by a 13.6% —
CVE-2013-0001 MED 4.3 microsoft .net_framework The Windows Forms (aka WinForms) component in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.0 SP2, 4, and 4.5 does not properly initialize memory arrays, which allows remote attackers to obtain sensitive information via (1) a crafted XAML browser appli 13.6% —
CVE-2002-1444 LOW 2.6 google toolbar The Google toolbar 1.1.60, when running on Internet Explorer 5.5 and 6.0, allows remote attackers to cause a denial of service (crash with an exception in oleaut32.dll) via malicious HTML, possibly related to small width and height parameters or an incorrect c 13.5% —
CVE-2013-3126 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script De 13.5% —
CVE-2006-3227 LOW 2.6 microsoft internet_explorer Interpretation conflict between Internet Explorer and other web browsers such as Mozilla, Opera, and Firefox might allow remote attackers to modify the visual presentation of web pages and possibly bypass protection mechanisms such as content filters via ASCII 13.5% —
CVE-2011-3404 MED 4.3 microsoft internet_explorer Microsoft Internet Explorer 6 through 9 does not properly use the Content-Disposition HTTP header to control rendering of the HTTP response body, which allows remote attackers to read content from a different (1) domain or (2) zone via a crafted web site, aka 13.5% —
CVE-2017-0018 HIGH 7.5 microsoft internet_explorer Microsoft Internet Explorer 10 and 11 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." This vulnerability is different from those 13.5% —
CVE-2015-1683 HIGH 9.3 microsoft office Microsoft Office 2007 SP3 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." 13.5% —
CVE-2003-0839 MED 5.0 microsoft windows_2003_server Directory traversal vulnerability in the "Shell Folders" capability in Microsoft Windows Server 2003 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a "shell:" link. 13.5% —
CVE-2003-0505 MED 5.0 microsoft netmeeting Directory traversal vulnerability in Microsoft NetMeeting 3.01 2000 before SP4 allows remote attackers to read arbitrary files via "..\.." (dot dot) sequences in a file transfer request. 13.5% —
CVE-2020-0708 HIGH 7.8 microsoft windows_10 A remote code execution vulnerability exists when the Windows Imaging Library improperly handles memory.To exploit this vulnerability, an attacker would first have to coerce a victim to open a specially crafted file.The security update addresses the vulnerabil 13.5% —
CVE-2022-22715 HIGH 7.8 microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability 13.5% —
CVE-2021-31179 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 13.5% —
CVE-2014-0305 HIGH 9.3 microsoft internet_explorer Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014 13.5% —
CVE-2016-0018 HIGH 7.3 microsoft windows_10 Microsoft Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 R2, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability." 13.5% —
CVE-2007-4040 HIGH 8.8 microsoft outlook Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI 13.5% —
CVE-2015-1764 MED 4.3 microsoft exchange_server The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) issue, a 13.5% —
CVE-2017-0040 HIGH 7.5 microsoft internet_explorer The scripting engine in Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability." This vulnerabili 13.5% —
CVE-2016-0138 MED 4.3 microsoft exchange_server Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook 13.5% —