imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2008-4023
High 10.0

Active Directory in Microsoft Windows 2000 SP4 does not properly allocate memory for (1) LDAP and (2) LDAPS requests, which allows remote attackers to execute arbitrary code via a crafted request, aka "Active Directory Overflow Vulnerability."

microsoft windows_2000
0.39EPSS
CVE-2007-0040
High 10.0

The LDAP service in Windows Active Directory in Microsoft Windows 2000 Server SP4, Server 2003 SP1 and SP2, Server 2003 x64 Edition and SP2, and Server 2003 for Itanium-based Systems SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted L…

microsoft windows_2000 · microsoft windows_2003_server
0.39EPSS
CVE-2004-1166
High 7.5

CRLF injection vulnerability in Microsoft Internet Explorer 6.0.2800.1106 and earlier allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to b…

microsoft ie · microsoft internet_explorer
0.39EPSS
CVE-2009-1139
High 7.8

Memory leak in the LDAP service in Active Directory on Microsoft Windows 2000 SP4 and Server 2003 SP2, and Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2, allows remote attackers to cause a denial of service (memory cons…

microsoft adam · microsoft windows_2000 · microsoft windows_server_2003
0.39EPSS
CVE-2013-1309
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulner…

microsoft internet_explorer
0.39EPSS
CVE-2016-0120
Medium 6.5

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (s…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.39EPSS
CVE-2006-4301
Medium 5.0

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attribute in multiple DirectX Media Image DirectX Transforms ActiveX COM Objects from (a) dxtmsft.dll and (b) dxtmsft3.dll, including (1) DXImageT…

microsoft ie
0.39EPSS
CVE-2007-0219
High 10.0

Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from (1) Msb1fren.dll, (2) Htmlmm.ocx, and (3) Blnmgrps.dll as ActiveX controls, which allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-200…

microsoft ie · microsoft internet_explorer
0.39EPSS
CVE-2017-0283
High 8.8

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, …

microsoft lync · microsoft office · microsoft office_word_viewer · microsoft silverlight · and 7 more
0.39EPSS
CVE-2003-1328
High 7.5

The showHelp() function in Microsoft Internet Explorer 5.01, 5.5, and 6.0 supports certain types of pluggable protocols that allow remote attackers to bypass the cross-domain security model and execute arbitrary code, aka "Improper Cross Domain Security Valida…

microsoft ie · microsoft internet_explorer
0.39EPSS
CVE-2017-0049
Medium 4.3

The VBScript engine in Microsoft Internet Explorer 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability." This vulnerability is different from those de…

microsoft internet_explorer
0.39EPSS
CVE-2006-2389
High 9.3

Unspecified vulnerability in Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, and other products, allows user-assisted attackers to execute arbitrary code via an Office file with a malformed property that triggers memory corruption related to…

microsoft office
0.39EPSS
CVE-2008-1442
High 9.3

Heap-based buffer overflow in the substringData method in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code, related to an unspecified manipulation of a DOM object before a call to this method, aka the "HTML Objects Memory C…

microsoft internet_explorer
0.39EPSS
CVE-2008-0114
High 9.3

Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office for Mac 2004 allows user-assisted remote attackers to execute arbitrary code via crafted Style records that trigger memory corruption.

microsoft excel · microsoft excel_viewer · microsoft office
0.39EPSS
CVE-2014-0253
Medium 5.0

Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine TCP connection states, which allows remote attackers to cause a denial of service (ASP.NET daemon hang) via crafted HTTP requests that trigger persistent resou…

microsoft .net_framework
0.39EPSS
CVE-2006-0005
High 9.3

Buffer overflow in the plug-in for Microsoft Windows Media Player (WMP) 9 and 10, when used in browsers other than Internet Explorer and set as the default application to handle media files, allows remote attackers to execute arbitrary code via HTML with an EM…

microsoft windows-nt · microsoft windows_2000 · microsoft windows_2000_advanced_server · microsoft windows_2003_server · and 3 more
0.39EPSS
CVE-2021-28476
Critical 9.9

Windows Hyper-V Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_server_2008 · and 3 more
0.39EPSS
CVE-2005-0048
High 7.5

Microsoft Windows XP SP2 and earlier, 2000 SP3 and SP4, Server 2003, and older operating systems allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted IP packets with malformed options, aka the "IP Validation Vuln…

microsoft windows_2000 · microsoft windows_xp
0.39EPSS
CVE-2011-1255
High 9.3

The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not pr…

microsoft internet_explorer
0.39EPSS
CVE-2013-3195
High 10.0

The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does no…

microsoft windows_7 · microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2003 · and 4 more
0.38EPSS
CVE-2004-0566
High 7.5

Integer overflow in imgbmp.cxx for Windows 2000 allows remote attackers to execute arbitrary code via a BMP image with a large bfOffBits value.

microsoft internet_explorer
0.38EPSS
CVE-2011-1871
High 7.8

Tcpip.sys in the TCP/IP stack in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to cause a denial of service (reboot) via a series of crafted ICMP messages, aka "ICMP Denial of Service V…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.38EPSS
CVE-2014-0271
High 9.3

The VBScript engine in Microsoft Internet Explorer 6 through 11, and VBScript 5.6 through 5.8, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "VBScript Memory Corruption Vulnerabil…

microsoft internet_explorer · microsoft vbscript
0.38EPSS
CVE-2000-0305
High 7.8

Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.

be beos · microsoft terminal_server · microsoft windows_2000 · microsoft windows_95 · and 2 more
0.38EPSS
CVE-2022-37985
Medium 5.5

Windows Graphics Component Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 6 more
0.38EPSS