imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2006-3439
High 10.0

Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.85EPSS
CVE-2006-0026
Medium 6.5

Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).

microsoft internet_information_server · microsoft internet_information_services
0.85EPSS
CVE-2002-0649
High 7.5

Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that …

microsoft data_engine · microsoft sql_server
0.85EPSS
CVE-2015-6132
High 7.2

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle library loading, which allows local users to gain privilege…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · and 5 more
0.85EPSS
CVE-2023-29325
High 8.1

Windows OLE Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 8 more
0.84EPSS
CVE-2024-30044
High 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.84EPSS
CVE-2005-1790
Low 2.6

Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a Javascript BODY onload event that calls the window function, aka "Mismatched …

microsoft internet_explorer
0.83EPSS
CVE-2016-0041
High 7.8

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain priv…

microsoft internet_explorer · microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · and 4 more
0.83EPSS
CVE-2021-28482
High 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.83EPSS
CVE-2013-3861
High 7.8

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5 SP1, 3.5.1, 4, and 4.5 allows remote attackers to cause a denial of service (application crash or hang) via crafted character sequences in JSON data, aka "JSON Parsing Vulnerability."

microsoft .net_framework
0.83EPSS
CVE-2024-49113
High 7.5

Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h2 · and 10 more
0.83EPSS
CVE-2019-0539
High 7.5

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique …

microsoft chakracore · microsoft edge
0.83EPSS
CVE-2005-0356
Medium 5.0

Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host t…

alaxala alaxala_networks · cisco agent_desktop · cisco aironet_ap1200 · cisco aironet_ap350 · and 72 more
0.83EPSS
CVE-2004-0597
High 10.0

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk…

greg_roelofs libpng · microsoft msn_messenger · microsoft windows_98se · microsoft windows_me · and 2 more
0.83EPSS
CVE-2006-0003
Medium 5.1

Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and distributed in Microsoft Data Access Components (MDAC) 2.7 and 2.8, allows remote attackers to execute arbitrary code via unknown attack vector…

microsoft data_access_components
0.82EPSS
CVE-2023-21716
Critical 9.8

Microsoft Word Remote Code Execution Vulnerability

microsoft office · microsoft office_long_term_servicing_channel · microsoft office_online_server · microsoft office_web_apps · and 4 more
0.82EPSS
CVE-2009-2521
Medium 5.0

Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a…

microsoft internet_information_services
0.82EPSS
CVE-2018-0886
High 7.0

The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709 Windows Server 2016 and Windows Server, …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.82EPSS
CVE-2003-0818
High 7.5

Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.82EPSS
CVE-2017-0038
Medium 5.5

gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.82EPSS
CVE-2022-44690
High 8.8

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_foundation · microsoft sharepoint_server
0.82EPSS
CVE-2023-21707
High 8.8

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.82EPSS
CVE-2009-2526
High 7.8

Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets, which allows remote attackers to cause a denial of service (infinite loop and system hang) via a crafted packet to the Server service, aka…

microsoft windows_server_2008 · microsoft windows_vista
0.82EPSS
CVE-2015-6128
High 7.2

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Windows Library Loading Remote Code Execution Vulnerability."

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.82EPSS
CVE-2023-36744
High 8.0

Microsoft Exchange Server Remote Code Execution Vulnerability

microsoft exchange_server
0.82EPSS