imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2016-3301
High 7.8

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for …

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 8 more
0.44EPSS
CVE-2008-3479
High 10.0

Heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service (mqsvc.exe) in Microsoft Windows 2000 SP4 allows remote attackers to read memory contents and execute arbitrary code via a crafted RPC call, related to improper processing of parameters…

microsoft windows_2000
0.44EPSS
CVE-2007-3111
High 10.0

Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used on Windows 2000 SP4, allows remote attackers to execute arbitrary code via a long URL property value.

microsoft internet_explorer · provideo camimage_activex_control
0.44EPSS
CVE-2000-0951
Medium 5.0

A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list directories in the web root via a Web Distributed Authoring and Versioning (WebDAV) search.

microsoft internet_information_services
0.44EPSS
CVE-2023-33133
High 7.8

Microsoft Excel Remote Code Execution Vulnerability

microsoft 365_apps · microsoft excel · microsoft office_long_term_servicing_channel · microsoft office_online_server
0.44EPSS
CVE-2007-0024
High 9.3

Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page t…

microsoft ie · microsoft internet_explorer
0.44EPSS
CVE-2021-24093
High 8.8

Windows Graphics Component Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_server_2016 · microsoft windows_server_2019
0.44EPSS
CVE-2005-2122
High 10.0

Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsyste…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.44EPSS
CVE-2014-2815
High 8.8

Microsoft OneNote 2007 SP3 allows remote attackers to execute arbitrary code via a crafted OneNote file that triggers creation of an executable file in a startup folder, aka "OneNote Remote Code Execution Vulnerability."

microsoft onenote
0.44EPSS
CVE-2001-0877
Medium 5.0

Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to cause a denial of service via (1) a spoofed SSDP advertisement that causes the client to connect to a service on another machine that generates a large amount of traffic …

microsoft windows_98 · microsoft windows_98se · microsoft windows_me · microsoft windows_xp
0.44EPSS
CVE-2018-8625
High 7.5

A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Internet Explorer 9, Internet Explorer 11, Internet Explorer 10.

microsoft internet_explorer
0.44EPSS
CVE-2008-0105
High 9.3

Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Works 8.0, and Works Suite 2005, allows remote attackers to execute arbitrary code via a .wps file with crafted section header index table information, aka "Microsoft Works File Converter In…

microsoft office · microsoft works
0.44EPSS
CVE-2006-3637
Medium 5.1

Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering M…

microsoft ie · microsoft internet_explorer
0.44EPSS
CVE-2006-4704
Medium 6.8

Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instan…

microsoft visual_studio_.net
0.44EPSS
CVE-2016-0111
High 7.5

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerabi…

microsoft edge · microsoft internet_explorer
0.44EPSS
CVE-2018-0866
High 7.5

Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the scripting en…

microsoft internet_explorer
0.44EPSS
CVE-2022-21993
High 7.5

Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.44EPSS
CVE-2017-8558
High 7.8

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511…

microsoft endpoint_protection · microsoft forefront_endpoint_protection · microsoft security_essentials · microsoft windows_defender · and 1 more
0.44EPSS
CVE-2000-0970
High 7.5

IIS 4.0 and 5.0 .ASP pages send the same Session ID cookie for secure and insecure web sessions, which could allow remote attackers to hijack the secure web session of the user if that user moves to an insecure session, aka the "Session ID Cookie Marking" vuln…

microsoft internet_information_server · microsoft internet_information_services
0.44EPSS
CVE-2023-6702
High 8.8

Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

fedoraproject fedora · google chrome · microsoft edge_chromium
0.44EPSS
CVE-2016-3225
High 7.8

The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applicati…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2006-4696
High 9.0

Unspecified vulnerability in the Server service in Microsoft Windows 2000 SP4, Server 2003 SP1 and earlier, and XP SP2 and earlier allows remote attackers to execute arbitrary code via a crafted packet, aka "SMB Rename Vulnerability."

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.43EPSS
CVE-2017-0190
Medium 4.4

The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from pr…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2016-0108
High 7.5

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE…

microsoft internet_explorer
0.43EPSS
CVE-2003-0003
High 7.5

Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code via an RPC call to the service containing certain parameter information.

microsoft windows_2000 · microsoft windows_2000_terminal_services · microsoft windows_nt · microsoft windows_xp
0.43EPSS