IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.478 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2001-1219 MED 5.0 microsoft internet_explorer Microsoft Internet Explorer 6.0 and earlier allows malicious website operators to cause a denial of service (client crash) via JavaScript that continually refreshes the window via self.location. 6.0% —
CVE-1999-0258 MED 5.0 microsoft windows_95 Bonk variation of teardrop IP fragmentation denial of service. 6.0% —
CVE-1999-0275 MED 5.0 microsoft windows_nt Denial of service in Windows NT DNS servers by flooding port 53 with too many characters. 6.0% —
CVE-1999-0292 MED 5.0 microsoft windows_nt Denial of service through Winpopup using large user names. 6.0% —
CVE-2017-0192 MED 4.3 microsoft windows_10 The Adobe Type Manager Font Driver (ATMFD.dll) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold , 1511, 1607, and 1703 allows an attacker to gai 6.0% —
CVE-2022-24547 HIGH 7.8 microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability 6.0% —
CVE-1999-0179 MED 5.0 microsoft windows_95 Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. 6.0% —
CVE-2019-1006 HIGH 7.5 microsoft .net_framework An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. 6.0% —
CVE-2014-2781 HIGH 7.6 microsoft windows_7 Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the exchange of keyboard and mouse data between programs at different 6.0% —
CVE-1999-0590 HIGH 10.0 apple macos A system does not present an appropriate legal message or warning to a user who is accessing it. 6.0% —
CVE-2024-38241 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming Service Driver Elevation of Privilege Vulnerability 6.0% —
CVE-2017-8542 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6.0% —
CVE-2017-8539 MED 5.5 microsoft forefront_security The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, a 6.0% —
CVE-2020-1042 CRIT 9.0 microsoft windows_server_2008 A remote code execution vulnerability exists when Hyper-V RemoteFX vGPU on a host server fails to properly validate input from an authenticated user on a guest operating system, aka 'Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability'. This CVE ID is un 6.0% —
CVE-2019-1466 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1467. 6.0% —
CVE-2019-1465 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1466, CVE-2019-1467. 6.0% —
CVE-2016-3232 MED 5.0 microsoft windows_server_2012 The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulne 6.0% —
CVE-2019-1467 MED 6.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1465, CVE-2019-1466. 6.0% —
CVE-2000-0415 MED 5.0 microsoft outlook Buffer overflow in Outlook Express 4.x allows attackers to cause a denial of service via a mail or news message that has a .jpg or .bmp attachment with a long file name. 6.0% —
CVE-2023-38142 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 6.0% —
CVE-2021-26700 HIGH 7.8 microsoft npm Visual Studio Code npm-script Extension Remote Code Execution Vulnerability 6.0% —
CVE-2017-8659 MED 4.3 microsoft edge Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to obtain information to further compromise the user's system due to the Chakra scripting engine not properly handling objects in memory, aka "Scripting Engine Information Disclosure Vulnerability" 6.0% —
CVE-1999-0537 HIGH 7.5 microsoft internet_explorer A configuration in a web browser such as Internet Explorer or Netscape Navigator allows execution of active content such as ActiveX, Java, Javascript, etc. 6.0% —
CVE-2020-26233 HIGH 7.3 microsoft git_credential_manager_core Git Credential Manager Core (GCM Core) is a secure Git credential helper built on .NET Core that runs on Windows and macOS. In Git Credential Manager Core before version 2.0.289, when recursively cloning a Git repository on Windows with submodules, Git will fi 6.0% —
CVE-2021-40486 HIGH 7.8 microsoft office Microsoft Word Remote Code Execution Vulnerability 6.0% —