imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2001-0505
Medium 5.0

Multiple memory leaks in Microsoft Services for Unix 2.0 allow remote attackers to cause a denial of service (memory exhaustion) via a large number of malformed requests to (1) the Telnet service, or (2) the NFS service.

microsoft services
0.33EPSS
CVE-2008-0117
High 9.3

Unspecified vulnerability in Microsoft Excel 2000 SP3 and 2002 SP2, and Office 2004 and 2008 for Mac, allows user-assisted remote attackers to execute arbitrary code via crafted conditional formatting values, aka "Excel Conditional Formatting Vulnerability."

microsoft compatibility_pack_word_excel_powerpoint_2007 · microsoft excel · microsoft excel_viewer · microsoft office
0.33EPSS
CVE-2017-0073
Medium 4.3

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive…

microsoft live_meeting · microsoft lync · microsoft office · microsoft office_word_viewer · and 10 more
0.33EPSS
CVE-2005-0044
High 7.5

The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulner…

microsoft exchange_server · microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · and 3 more
0.33EPSS
CVE-2002-0193
High 7.5

Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposition and Content-Type header fields that cause the application for the spoofed file type to pass the file back to the operating system for ha…

microsoft internet_explorer
0.33EPSS
CVE-2017-11779
High 8.1

The Microsoft Windows Domain Name System (DNS) DNSAPI.dll on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability when it fails to properly ha…

microsoft windows_10 · microsoft windows_8.1 · microsoft windows_rt_8.1 · microsoft windows_server_2012 · and 1 more
0.33EPSS
CVE-2016-3203
High 7.8

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows PDF Remote Code Execution Vulnerability."

microsoft edge · microsoft windows_10 · microsoft windows_8.1 · microsoft windows_server_2012
0.33EPSS
CVE-2005-1980
Medium 5.0

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service hang) via a crafted Transaction Internet Protocol (TIP) message that causes DTC to repeatedly connect to a target IP and port number after…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.33EPSS
CVE-2014-1766
High 9.3

Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, as demonstrated by Sebastian Apelt and Andreas Schmidt during a Pwn2Own competition at CanSecWes…

microsoft internet_explorer
0.33EPSS
CVE-2011-0042
High 7.8

SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft Windows XP SP2 and SP3, Windows XP Media Center Edition 2005 SP3, Windows Vista SP1 and SP2, Windows 7 Gold and SP1, and Windows Media Center TV Pack for Windows …

microsoft windows_7 · microsoft windows_media_center_tv_pack · microsoft windows_vista · microsoft windows_xp · and 1 more
0.33EPSS
CVE-2004-1244
High 7.5

Windows Media Player 9 allows remote attackers to execute arbitrary code via a PNG file containing large (1) width or (2) height values, aka the "PNG Processing Vulnerability."

microsoft windows_media_player
0.33EPSS
CVE-2007-0028
High 9.3

Microsoft Excel 2000, 2002, 2003, Viewer 2003, Office 2004 for Mac, and Office v.X for Mac does not properly handle certain opcodes, which allows user-assisted remote attackers to execute arbitrary code via a crafted XLS file, which results in an "Improper Mem…

microsoft excel · microsoft excel_viewer · microsoft office · microsoft works
0.33EPSS
CVE-2002-1182
Medium 5.0

IIS 5.0 and 5.1 allows remote attackers to cause a denial of service (crash) via malformed WebDAV requests that cause a large amount of memory to be assigned.

microsoft internet_information_services
0.33EPSS
CVE-2007-0220
Medium 6.8

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, scrip…

microsoft exchange_server
0.33EPSS
CVE-2003-0806
High 7.5

Buffer overflow in the Windows logon process (winlogon) in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, and XP SP1, when a member of a domain, allows remote attackers to execute arbitrary code.

microsoft windows_2000 · microsoft windows_nt · microsoft windows_xp
0.33EPSS
CVE-2006-0010
High 9.3

Heap-based buffer overflow in T2EMBED.DLL in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 up to SP1, Windows 98, and Windows ME allows remote attackers to execute arbitrary code via an e-mail message or web page with a crafted Embedded Open Type…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 3 more
0.33EPSS
CVE-2022-24502
Medium 4.3

Windows HTML Platforms Security Feature Bypass Vulnerability

microsoft windows_10 · microsoft windows_11 · microsoft windows_7 · microsoft windows_8.1 · and 7 more
0.33EPSS
CVE-2010-1262
High 9.3

Microsoft Internet Explorer 6 SP1 and SP2, 7, and 8 allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, related to the CStyleSheet object and a free of …

microsoft internet_explorer
0.33EPSS
CVE-2005-1205
Medium 5.0

The Telnet client for Microsoft Windows XP, Windows Server 2003, and Windows Services for UNIX allows remote attackers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command.

microsoft windows_2003_server
0.33EPSS
CVE-2019-1068
High 8.8

A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'.

microsoft sql_server
0.33EPSS
CVE-2008-4025
High 9.3

Integer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, 2003 SP3, and 2007 Gold and SP1; Outlook 2007 Gold and SP1; Word Viewer 2003 Gold and SP3; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office 2004 and 2…

microsoft office · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_outlook · microsoft office_word · and 3 more
0.33EPSS
CVE-2000-0673
Medium 5.0

The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.

microsoft windows_2000 · microsoft windows_nt
0.33EPSS
CVE-2015-6038
High 9.3

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allow remote …

microsoft excel · microsoft excel_for_mac · microsoft excel_viewer · microsoft office_compatibility_pack · and 1 more
0.33EPSS
CVE-2014-1799
High 9.3

Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014…

microsoft internet_explorer
0.33EPSS
CVE-2010-2730
High 9.3

Buffer overflow in Microsoft Internet Information Services (IIS) 7.5, when FastCGI is enabled, allows remote attackers to execute arbitrary code via crafted headers in a request, aka "Request Header Buffer Overflow Vulnerability."

microsoft internet_information_services
0.33EPSS