imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2022-26809
Critical 9.8

Remote Procedure Call Runtime Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 6 more
0.91EPSS
CVE-2001-0333
High 7.5

Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encoding .. (dot dot) and "\" characters twice.

microsoft internet_information_server
0.91EPSS
CVE-2000-0402
Low 2.1

The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in plaintext in a log file which is readable by any user, aka the "SQL Server 7.0 Service Pack Password" vulnerability.

microsoft sql_server
0.91EPSS
CVE-2006-2372
High 10.0

Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via a crafted DHCP response.

microsoft dhcp_client_service
0.90EPSS
CVE-2009-3103
High 10.0

Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC allows remote attackers to execute arbitrary code or cause a denial of service (system crash) v…

microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2020-17132
Critical 9.1

Microsoft Exchange Remote Code Execution Vulnerability

microsoft exchange_server
0.90EPSS
CVE-2017-0004
High 7.5

The Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to cause a denial of service (reboot) via a crafted authentication request, aka "Local Security…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.90EPSS
CVE-2023-21547
High 7.5

Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · microsoft windows_10_22h2 · and 5 more
0.89EPSS
CVE-2022-30216
High 8.8

Windows Server Service Tampering Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_server_2016 · microsoft windows_server_2022
0.89EPSS
CVE-2023-21769
High 7.5

Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability

microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · microsoft windows_10_21h2 · and 8 more
0.89EPSS
CVE-2024-26256
High 7.8

Libarchive Remote Code Execution Vulnerability

fedoraproject fedora · libarchive libarchive · microsoft windows_11_22h2 · microsoft windows_11_23h2 · and 1 more
0.88EPSS
CVE-2000-1209
High 10.0

The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3) Data Engine (MSDE) 1.0, including third party packages that use these products such as (4) Tumbleweed Secure Mail (MMS) (5) Compaq Insight …

compaq insight_manager · compaq insight_manager_xe · microsoft data_engine · microsoft msde
0.87EPSS
CVE-2008-5416
High 9.0

Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and…

microsoft sql_server
0.87EPSS
CVE-2005-4360
High 7.8

The URL parser in Microsoft Internet Information Services (IIS) 5.1 on Windows XP Professional SP2 allows remote attackers to execute arbitrary code via multiple requests to ".dll" followed by arguments such as "~0" through "~9", which causes ntdll.dll to prod…

microsoft internet_information_services
0.87EPSS
CVE-2023-36035
High 8.0

Microsoft Exchange Server Spoofing Vulnerability

microsoft exchange_server
0.87EPSS
CVE-2003-0718
Medium 5.0

The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a denial of service (memory and CPU exhaustion, application crash) via a PROPFIND request with an XML message containing XML elements with a l…

microsoft internet_information_server · microsoft internet_information_services
0.87EPSS
CVE-2005-4560
High 7.5

The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and…

microsoft windows_2003_server · microsoft windows_xp
0.86EPSS
CVE-2000-0778
Medium 5.0

IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "Translate: f" header, aka the "Specialized Header" vulnerability.

microsoft internet_information_services
0.86EPSS
CVE-2010-0483
High 7.6

vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when Internet Explorer is used, allows user-assisted remote attackers to execute arbitrary code by referencing a (1) local pathname, (2) UNC sha…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2003 · microsoft windows_xp
0.86EPSS
CVE-2012-0152
Medium 4.3

The Remote Desktop Protocol (RDP) service in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (application hang) via a series of crafted packets, aka "Terminal Server Denial of Service …

microsoft windows_7 · microsoft windows_server_2008
0.86EPSS
CVE-2022-37958
High 8.1

SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 5 more
0.86EPSS
CVE-2001-0241
High 10.0

Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via a long print request that is passed to the extension through IIS 5.0.

microsoft windows_2000
0.86EPSS
CVE-2003-0109
High 7.5

Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.

microsoft windows_2000 · microsoft windows_2000_terminal_services
0.86EPSS
CVE-2003-0533
High 7.5

Stack-based buffer overflow in certain Active Directory service functions in LSASRV.DLL of the Local Security Authority Subsystem Service (LSASS) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows M…

microsoft netmeeting · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · and 3 more
0.86EPSS
CVE-2009-0075
High 9.3

Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to CFunctionPointer and the appending of document objects, ak…

microsoft internet_explorer
0.85EPSS