imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2016-1101
High 7.5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in…

adobe flash_player · microsoft edge · microsoft internet_explorer
0.38EPSS
CVE-2004-0116
Medium 5.0

An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.38EPSS
CVE-2011-1892
Medium 4.0

Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 20…

microsoft forms_server · microsoft groove · microsoft groove_data_bridge_server · microsoft groove_management_server · and 6 more
0.38EPSS
CVE-2003-0903
High 10.0

Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.

microsoft data_access_components
0.37EPSS
CVE-2017-0039
High 7.8

Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle dynamic link library (DLL) loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."

microsoft windows_server_2008 · microsoft windows_vista
0.37EPSS
CVE-2012-0217
High 7.2

The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3;…

citrix xenserver · freebsd freebsd · illumos illumos · joyent smartos · and 7 more
0.37EPSS
CVE-2009-0231
High 8.8

The Embedded OpenType (EOT) Font Engine (T2EMBED.DLL) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows remote attackers to execute arbitrary code via a crafted name table in a data re…

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.37EPSS
CVE-2009-1547
High 8.8

Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream header that triggers memory corruption, aka "Data Stream Header Corruption Vulnerability."

microsoft internet_explorer · microsoft windows_2000 · microsoft windows_7 · microsoft windows_server_2003 · and 3 more
0.37EPSS
CVE-2015-2455
High 9.3

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee…

microsoft .net_framework · microsoft live_meeting · microsoft lync · microsoft lync_basic · and 11 more
0.37EPSS
CVE-2008-4837
High 9.3

Stack-based buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; and Microsoft Works 8 allow remot…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · and 3 more
0.37EPSS
CVE-2014-1764
High 10.0

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code and bypass a sandbox protection mechanism by leveraging "object confusion" in a broker process, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2014.…

microsoft internet_explorer
0.37EPSS
CVE-2005-1985
High 7.5

The Client Service for NetWare (CSNW) on Microsoft Windows 2000 SP4, XP SP1 and Sp2, and Server 2003 SP1 and earlier, allows remote attackers to execute arbitrary code due to an "unchecked buffer" when processing certain crafted network messages.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.37EPSS
CVE-2007-0221
High 7.8

Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."

microsoft exchange_server
0.37EPSS
CVE-2016-1106
High 7.5

Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in…

adobe flash_player · microsoft edge · microsoft internet_explorer
0.37EPSS
CVE-2000-0854
High 10.0

When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same director…

microsoft office
0.37EPSS
CVE-2008-0077
High 8.8

Use-after-free vulnerability in Microsoft Internet Explorer 6 SP1, 6 SP2, and and 7 allows remote attackers to execute arbitrary code by assigning malformed values to certain properties, as demonstrated using the by property of an animateMotion SVG element, ak…

microsoft internet_explorer
0.37EPSS
CVE-2006-1300
Medium 5.0

Microsoft .NET framework 2.0 (ASP.NET) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1 allows remote attackers to bypass access restrictions via unspecified "URL paths" that can access Application Folder objects "explicitly by name."

microsoft .net_framework
0.37EPSS
CVE-2013-3868
Medium 5.0

Microsoft Active Directory Lightweight Directory Service (AD LDS) on Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 and Active Directory Services on Windows Server 2008 SP2 and R2 SP1 and Server 2012 allow remote attackers …

microsoft active_directory_lightweight_directory_service · microsoft windows_7 · microsoft windows_8 · microsoft windows_server_2008 · and 2 more
0.37EPSS
CVE-2009-0220
High 9.3

Multiple stack-based buffer overflows in the PowerPoint 4.0 importer (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via crafted formatting data for paragraphs in a file that uses a …

microsoft office_powerpoint
0.37EPSS
CVE-2007-0034
High 9.3

Buffer overflow in the Advanced Search (Finder.exe) feature of Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to execute arbitrary code via a crafted Outlook Saved Searches (OSS) file that triggers memory corruption, aka "Microsof…

microsoft office · microsoft outlook
0.37EPSS
CVE-2005-2117
Medium 5.1

Web View in Windows Explorer on Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 does not properly handle certain HTML characters in preview fields, which allows remote user-assisted attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_explorer · microsoft windows_xp
0.37EPSS
CVE-2010-0255
Medium 4.3

Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not prevent rendering of non-HTML local files as HTML documents, which allows remote attackers to bypass intended access restrictions and read arbitrary files via vectors involving JavaScript exploi…

microsoft internet_explorer
0.37EPSS
CVE-2002-0023
Medium 5.0

Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObject function, which bypass some of GetObject's security checks.

microsoft internet_explorer
0.37EPSS
CVE-2017-0008
Medium 4.3

Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CV…

microsoft internet_explorer
0.37EPSS
CVE-2022-24500
High 8.8

Windows SMB Remote Code Execution Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 6 more
0.37EPSS