IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

Microsoft vulnerabilities

16.469 CVE

Microsoft vulnerabilities
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2016-3209 MED 5.5 microsoft .net_framework Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word 53.7% —
CVE-2021-27068 HIGH 8.8 microsoft visual_studio_2019 Visual Studio Remote Code Execution Vulnerability 53.6% —
CVE-2022-35823 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability 53.6% —
CVE-2002-1143 MED 5.0 microsoft excel Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in 53.6% —
CVE-2023-32029 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 53.5% —
CVE-2002-1254 HIGH 7.5 microsoft ie Internet Explorer 5.5 and 6.0 allows remote attackers to bypass the cross-domain security model and access information on the local system or in other domains, and possibly execute code, via cached methods and objects, aka "Cross Domain Verification via Cached 53.5% —
CVE-2011-0104 HIGH 9.3 microsoft excel Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted HLink record in an Excel file, aka " 53.4% —
CVE-2005-1978 HIGH 7.5 microsoft windows_2000 COM+ in Microsoft Windows does not properly "create and use memory structures," which allows local users or remote attackers to execute arbitrary code. 53.4% —
CVE-1999-0191 MED 6.4 microsoft internet_information_server IIS newdsn.exe CGI script allows remote users to overwrite files. 53.3% —
CVE-2006-5583 HIGH 10.0 microsoft windows_2003_server Buffer overflow in the SNMP Service in Microsoft Windows 2000 SP4, XP SP2, Server 2003, Server 2003 SP1, and possibly other versions allows remote attackers to execute arbitrary code via a crafted SNMP packet, aka "SNMP Memory Corruption Vulnerability." 53.1% —
CVE-2010-0248 HIGH 8.1 microsoft internet_explorer Microsoft Internet Explorer 6, 6 SP1, 7, and 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka 53.1% —
CVE-2018-0840 HIGH 7.5 microsoft edge Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote cod 53.1% —
CVE-2024-38023 HIGH 7.2 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 52.9% —
CVE-2007-5348 HIGH 9.3 microsoft digital_image_suite Integer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewe 52.9% —
CVE-2001-0538 HIGH 10.0 microsoft outlook Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrary commands via a malicious HTML e-mail message or web page. 52.9% —
CVE-2021-31213 HIGH 7.8 microsoft remote Visual Studio Code Remote Containers Extension Remote Code Execution Vulnerability 52.8% —
CVE-2000-0457 HIGH 7.5 microsoft internet_information_server ISM.DLL in IIS 4.0 and 5.0 allows remote attackers to read file contents by requesting the file and appending a large number of encoded spaces (%20) and terminated with a .htr extension, aka the ".HTR File Fragment Reading" or "File Fragment Reading via .HTR" 52.8% —
CVE-2008-0108 HIGH 9.3 microsoft office Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted field lengths, aka "Microsoft W 52.6% —
CVE-2003-1041 HIGH 7.5 microsoft ie Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal attack using a URL containing ".." (dot dot) sequences and a filename that ends in "::" which is treated as a .chm file even if it does not h 52.6% —
CVE-2017-8734 HIGH 7.5 microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft Edge accesses objects in memory, aka "Microsoft Edge Memory Co 52.5% —
CVE-2008-3471 HIGH 9.3 microsoft excel Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 52.3% —
CVE-2007-3898 MED 6.4 microsoft windows_2000 The DNS server in Microsoft Windows 2000 Server SP4, and Server 2003 SP1 and SP2, uses predictable transaction IDs when querying other DNS servers, which allows remote attackers to spoof DNS replies, poison the DNS cache, and facilitate further attack vectors. 52.3% —
CVE-2008-3013 HIGH 9.3 microsoft digital_image_suite gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, Office XP SP3, Office 2003 SP2 and SP3, 2007 Microsoft Office System Gold and SP1, Visio 2002 SP2, PowerPoint Viewer 200 52.1% —
CVE-2008-1898 HIGH 9.3 microsoft office A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterface pro 52.0% —
CVE-2023-36777 MED 5.7 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 52.0% —