imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2009-1918
High 10.0

Microsoft Internet Explorer 5.01 SP4 and 6 SP1; Internet Explorer 6 for Windows XP SP2 and SP3 and Server 2003 SP2; and Internet Explorer 7 and 8 for Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 do not properl…

microsoft internet_explorer
0.43EPSS
CVE-2007-2228
High 7.8

rpcrt4.dll (aka the RPC runtime library) in Microsoft Windows XP SP2, XP Professional x64 Edition, Server 2003 SP1 and SP2, Server 2003 x64 Edition and x64 Edition SP2, and Vista and Vista x64 Edition allows remote attackers to cause a denial of service (RPCSS…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · microsoft windows_xp
0.43EPSS
CVE-2002-0370
High 7.5

Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP,…

allume_systems_division stuffit_expander · ibm lotus_notes · microsoft windows_98_plus_pack · microsoft windows_me · and 3 more
0.43EPSS
CVE-2016-3272
Low 2.8

The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles page-fault system calls, which allows local users to obtain sensitive information from an arbitrary process via a crafted application,…

microsoft windows_10 · microsoft windows_7 · microsoft windows_rt_8.1 · microsoft windows_server_2012
0.43EPSS
CVE-2016-0145
High 8.8

The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, …

microsoft .net_framework · microsoft live_meeting · microsoft lync · microsoft office · and 9 more
0.43EPSS
CVE-2016-0169
Medium 6.5

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, ak…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2016-0168
Medium 6.5

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to obtain sensitive information via a crafted document, ak…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.43EPSS
CVE-2007-0065
High 10.0

Heap-based buffer overflow in Object Linking and Embedding (OLE) Automation in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, Office 2004 for Mac, and Visual basic 6.0 SP6 allows remote attackers to execute arbitrary code via a crafted scr…

microsoft office · microsoft visual_basic
0.43EPSS
CVE-2023-21818
High 7.5

Windows Secure Channel Denial of Service Vulnerability

microsoft windows_10 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_20h2 · and 8 more
0.43EPSS
CVE-2024-30080
Critical 9.8

Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

microsoft windows_10_1507 · microsoft windows_10_1607 · microsoft windows_10_1809 · microsoft windows_10_21h1 · and 9 more
0.43EPSS
CVE-2017-0061
Medium 5.3

The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and R2, and Windows 7 SP1 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted we…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2011-2001
High 9.3

Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code via an attempted access to a virtual function table after corruption of this table has occurred, aka "Virtual Function T…

microsoft internet_explorer
0.43EPSS
CVE-2013-3894
High 8.1

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a cr…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · and 4 more
0.43EPSS
CVE-2006-3869
High 7.5

Heap-based buffer overflow in URLMON.DLL in Microsoft Internet Explorer 6 SP1 on Windows 2000 and XP SP1, with versions the MS06-042 patch before 20060824, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long URL on…

microsoft ie
0.43EPSS
CVE-2008-4841
High 9.3

The WordPad Text Converter for Word 97 files in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exp…

microsoft wordpad
0.43EPSS
CVE-2007-0612
High 7.8

Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of service (Internet Explorer crash) by accessing the bgColor, fgColor, linkColor, alinkColor, vlinkColor, or defaultCharset properties in the (1…

microsoft ie · microsoft internet_explorer
0.43EPSS
CVE-2004-0897
High 10.0

The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.

microsoft windows_2003_server · microsoft windows_xp
0.43EPSS
CVE-2006-3449
High 7.5

Unspecified vulnerability in Microsoft PowerPoint 2000 through 2003, possibly a buffer overflow, allows user-assisted remote attackers to execute arbitrary commands via a malformed record in the BIFF file format used in a PPT file, a different issue than CVE-2…

microsoft powerpoint
0.43EPSS
CVE-2018-8464
High 7.5

An remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka "Microsoft Edge PDF Remote Code Execution Vulnerability." This affects Microsoft Edge.

microsoft edge
0.43EPSS
CVE-1999-0891
Medium 5.0

The "download behavior" in Internet Explorer 5 allows remote attackers to read arbitrary files via a server-side redirect.

microsoft internet_explorer
0.43EPSS
CVE-2011-0978
High 9.3

Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via ve…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft office_compatibility_pack
0.43EPSS
CVE-2017-0090
High 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0087
High 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0086
High 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS
CVE-2017-0083
High 8.8

Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers to execute arbitrary code via a crafted web site, aka "Uniscribe Remote Code Execution Vulnerability." This vulnerability is different from …

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.43EPSS