imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2005-1979
Medium 5.0

Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC service exception and exit) via an "unexpected protocol command during the reconnection request," which is not properly handled by the Transaction…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.33EPSS
CVE-2010-4588
High 9.3

The WBEMSingleView.ocx ActiveX control 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier allows remote attackers to execute arbitrary code via a crafted argument to the ReleaseContext method, a different vector than CVE-2010-3973, possibly an u…

microsoft wmi_administrative_tools
0.33EPSS
CVE-2007-4675
High 9.3

Heap-based buffer overflow in the QuickTime VR extension 7.2.0.240 in QuickTime.qts in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via a QTVR (QuickTime Virtual Reality) movie file containing a large size field in the atom head…

apple mac_os_x · microsoft windows_vista · microsoft windows_xp
0.33EPSS
CVE-2006-2218
High 9.3

Unspecified vulnerability in Internet Explorer 6.0 on Microsoft Windows XP SP2 allows remote attackers to execute arbitrary code via "exceptional conditions" that trigger memory corruption, as demonstrated using an exception handler and nested object tags, a v…

microsoft internet_explorer
0.33EPSS
CVE-2007-1754
High 9.3

PUBCONV.DLL in Microsoft Office Publisher 2007 does not properly clear memory when transferring data from disk to memory, which allows user-assisted remote attackers to execute arbitrary code via a malformed .pub page via a certain negative value, which bypass…

microsoft publisher
0.33EPSS
CVE-2004-2434
Medium 5.0

Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with "::{" (colon colon left brace), which triggers a null dereference when the user attempts to save the link using "Save As" and Internet Expl…

microsoft ie
0.33EPSS
CVE-2004-0844
Medium 5.0

Internet Explorer 6 on Double Byte Character Set (DBCS) systems allows remote attackers to alter displayed address bars and spoof web pages via a URL containing special characters, facilitating phishing attacks, aka the "Address Bar Spoofing on Double Byte Cha…

microsoft ie
0.33EPSS
CVE-2013-3143
High 9.3

Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-316…

microsoft internet_explorer
0.33EPSS
CVE-2005-1184
Medium 5.0

The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) via a TCP packet with the correct sequence number but the wrong Acknowledgement number, which generates a large number of "keep alive" packets…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98se · microsoft windows_nt · and 1 more
0.33EPSS
CVE-2015-2525
High 7.2

Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to bypass intended filesystem restrictions and…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8 · microsoft windows_8.1 · and 5 more
0.33EPSS
CVE-2018-8423
High 7.8

A remote code execution vulnerability exists in the Microsoft JET Database Engine, aka "Microsoft JET Database Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019…

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 4 more
0.33EPSS
CVE-2014-0254
High 7.8

The IPv6 implementation in Microsoft Windows 8, Windows Server 2012, and Windows RT does not properly validate packets, which allows remote attackers to cause a denial of service (system hang) via crafted ICMPv6 Router Advertisement packets, aka "TCP/IP Versio…

microsoft windows_8 · microsoft windows_rt · microsoft windows_server_2012
0.33EPSS
CVE-2003-0346
High 7.5

Multiple integer overflows in a Microsoft Windows DirectX MIDI library (QUARTZ.DLL) allow remote attackers to execute arbitrary code via a MIDI (.mid) file with (1) large length for a Text or Copyright string, or (2) a large number of tracks, which leads to a …

microsoft directx
0.33EPSS
CVE-2008-4259
High 9.3

Microsoft Internet Explorer 7 sometimes attempts to access uninitialized memory locations, which allows remote attackers to execute arbitrary code via a crafted HTML document that triggers memory corruption, related to a WebDAV request for a file with a long n…

microsoft internet_explorer
0.33EPSS
CVE-2004-0963
High 10.0

Buffer overflow in Microsoft Word 2002 (10.6612.6714) SP3, and possibly other versions, allows remote attackers to cause a denial of service (application exception) and possibly execute arbitrary code in winword.exe via certain unexpected values in a .doc file…

microsoft word
0.33EPSS
CVE-2010-2552
High 7.8

Stack consumption vulnerability in the SMB Server in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows remote attackers to cause a denial of service (system hang) via a malformed SMBv2 compounded request, aka "SMB…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista
0.33EPSS
CVE-2009-3830
Medium 5.0

The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.

microsoft sharepoint_server
0.33EPSS
CVE-2008-3472
High 9.3

Microsoft Internet Explorer 6 and 7 does not properly determine the domain or security zone of origin of web script, which allows remote attackers to bypass the intended cross-domain security policy, and execute arbitrary code or obtain sensitive information, …

microsoft internet_explorer
0.33EPSS
CVE-2007-1644
High 10.0

The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-m…

microsoft all_windows
0.33EPSS
CVE-2009-0239
Medium 4.3

Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result…

microsoft windows_search
0.33EPSS
CVE-2016-3198
Medium 6.5

Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

microsoft edge
0.32EPSS
CVE-2016-3345
High 8.8

The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via crafted …

microsoft windows_10 · microsoft windows_7 · microsoft windows_8.1 · microsoft windows_rt_8.1 · and 3 more
0.32EPSS
CVE-2008-0087
High 7.5

The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_vista · microsoft windows_xp
0.32EPSS
CVE-2018-5391
High 7.5

The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various …

canonical ubuntu_linux · debian debian_linux · f5 big-ip_access_policy_manager · f5 big-ip_advanced_firewall_manager · and 47 more
0.32EPSS
CVE-2009-0568
High 10.0

The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locati…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server · microsoft windows_server_2008 · and 2 more
0.32EPSS