imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2024-43464
High 7.2

Microsoft SharePoint Server Remote Code Execution Vulnerability

microsoft sharepoint_server
0.36EPSS
CVE-2022-37974
Medium 6.5

Windows Mixed Reality Developer Tools Information Disclosure Vulnerability

microsoft windows_10 · microsoft windows_11
0.36EPSS
CVE-2008-1457
High 9.0

The Event System in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate per-user subscriptions, which allows remote authenticated users to execute arbitrary code via a crafted even…

microsoft windows-nt · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_vista · and 1 more
0.36EPSS
CVE-2007-3895
High 9.3

Buffer overflow in Microsoft DirectShow in Microsoft DirectX 7.0 through 10.0 allows remote attackers to execute arbitrary code via a crafted (1) WAV or (2) AVI file.

microsoft directx
0.36EPSS
CVE-2019-1311
High 7.8

A remote code execution vulnerability exists when the Windows Imaging API improperly handles objects in memory, aka 'Windows Imaging API Remote Code Execution Vulnerability'.

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.36EPSS
CVE-2007-2581
Medium 4.3

Multiple cross-site scripting (XSS) vulnerabilities in Microsoft Windows SharePoint Services 3.0 for Windows Server 2003 and Office SharePoint Server 2007 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO (query string) in "every …

microsoft sharepoint_server · microsoft sharepoint_services · microsoft windows_2003
0.36EPSS
CVE-2007-2884
High 9.3

Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial of service (CPU consumption) or execute arbitrary code via a Visual Basic Project (vbp) file with a long (1) Description or (2) Company Nam…

microsoft visual_basic
0.36EPSS
CVE-2003-0231
Medium 5.0

Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.

microsoft data_engine · microsoft sql_server
0.36EPSS
CVE-2007-0064
High 9.3

Heap-based buffer overflow in Windows Media Format Runtime 7.1, 9, 9.5, 9.5 x64 Edition, 11, and Windows Media Services 9.1 for Microsoft Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via a crafted Adv…

microsoft windows_media_format_runtime · microsoft windows_media_services
0.36EPSS
CVE-2009-1131
High 9.3

Multiple stack-based buffer overflows in Microsoft Office PowerPoint 2000 SP3 allow remote attackers to execute arbitrary code via a large amount of data associated with unspecified atoms in a PowerPoint file that triggers memory corruption, aka "Data Out of B…

microsoft office_powerpoint
0.36EPSS
CVE-2008-3021
High 9.3

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of a PICT file, which allows remote attackers to execute arbitrary code via a crafted PICT file with an invalid bits_per_pixel field, aka the "…

microsoft office · microsoft office_converter_pack · microsoft works
0.36EPSS
CVE-2000-0097
Medium 5.0

The WebHits ISAPI filter in Microsoft Index Server allows remote attackers to read arbitrary files, aka the "Malformed Hit-Highlighting Argument" vulnerability.

microsoft index_server
0.36EPSS
CVE-2024-38071
High 7.5

Windows Remote Desktop Licensing Service Denial of Service Vulnerability

microsoft windows_server_2008 · microsoft windows_server_2012 · microsoft windows_server_2016 · microsoft windows_server_2019 · and 2 more
0.36EPSS
CVE-2006-5162
Medium 5.0

wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.

microsoft internet_explorer
0.36EPSS
CVE-2017-0266
High 7.5

A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render when handling objects in memory, aka "Microsoft Edge Remote Code Execution Vulnerability."

microsoft edge
0.36EPSS
CVE-2009-3135
High 9.3

Stack-based buffer overflow in Microsoft Office Word 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, Open XML File Format Converter for Mac, Office Word Viewer 2003 SP3, and Office Word Viewer allow remote attackers to execute arbitrary code via a Word do…

microsoft office · microsoft office_word · microsoft office_word_viewer · microsoft open_xml_file_format_converter
0.36EPSS
CVE-2007-1658
High 9.3

Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same l…

microsoft windows_vista
0.36EPSS
CVE-2017-0215
Medium 5.3

Microsoft Windows 10 1607 and Windows Server 2016 allow an attacker to exploit a security feature bypass vulnerability in Device Guard that could allow the attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Po…

microsoft windows_10 · microsoft windows_server_2016
0.36EPSS
CVE-2011-3417
High 9.3

The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0, when sliding expiry is enabled, does not properly handle cached content, which allows remote attackers to obtain access to arbitrar…

microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.36EPSS
CVE-2009-1129
High 9.3

Multiple stack-based buffer overflows in the PowerPoint 95 importer (PP7X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allow remote attackers to execute arbitrary code via an inconsistent record length in sound data in a file that use…

microsoft office_powerpoint
0.36EPSS
CVE-2009-0227
High 9.3

Stack-based buffer overflow in the PowerPoint 4.2 conversion filter (PP4X32.DLL) in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3 allows remote attackers to execute arbitrary code via a large number of structures in sound data in a file that use…

microsoft office_powerpoint
0.36EPSS
CVE-2009-1134
High 9.3

Excel in 2007 Microsoft Office System SP1 and SP2; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a BIFF file with a malf…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_excel · microsoft office_excel_viewer · and 2 more
0.36EPSS
CVE-1999-0015
Medium 5.0

Teardrop IP denial of service.

hp hp-ux · microsoft windows_95 · microsoft windows_nt · netbsd netbsd · and 1 more
0.36EPSS
CVE-2008-3477
High 9.3

Microsoft Excel 2000 SP3, 2002 SP3, and 2003 SP2 and SP3 does not properly validate data in the VBA Performance Cache when processing an Office document with an embedded object, which allows remote attackers to execute arbitrary code via an Excel file containi…

microsoft internet_explorer
0.36EPSS
CVE-2010-2746
High 7.6

Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, when a third-party SVG viewer is used, al…

microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 2 more
0.36EPSS