imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2008-1089
High 9.3

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a Visio file containing crafted object header data, aka "Visio Object Header Vulnerability."

microsoft office · microsoft visio
0.32EPSS
CVE-2008-1090
High 9.3

Unspecified vulnerability in Microsoft Visio 2002 SP2, 2003 SP2 and SP3, and 2007 up to SP1 allows user-assisted remote attackers to execute arbitrary code via a crafted .DXF file, aka "Visio Memory Validation Vulnerability."

microsoft office · microsoft visio
0.32EPSS
CVE-2013-0005
High 7.8

The WCF Replace function in the Open Data (aka OData) protocol implementation in Microsoft .NET Framework 3.5, 3.5 SP1, 3.5.1, and 4, and the Management OData IIS Extension on Windows Server 2012, allows remote attackers to cause a denial of service (resource …

microsoft .net_framework · microsoft management_odata_iis_extension
0.32EPSS
CVE-2007-0035
High 9.3

Word (or Word Viewer) in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, 2004 for Mac, and Works Suite 2004, 2005, and 2006 does not properly handle data in a certain array, which allows user-assisted remote attackers to execute arbitrary code, aka the "Word Arra…

microsoft office · microsoft works
0.32EPSS
CVE-2013-3178
High 9.3

Microsoft Silverlight 5 before 5.1.20513.0 does not properly initialize arrays, which allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via a crafted Silverlight application, aka "Null Pointer Vulnerabili…

microsoft silverlight
0.32EPSS
CVE-2008-2246
High 7.8

Microsoft Windows Vista through SP1 and Server 2008 do not properly import the default IPsec policy from a Windows Server 2003 domain to a Windows Server 2008 domain, which prevents IPsec rules from being enforced and allows remote attackers to bypass intended…

microsoft windows-nt · microsoft windows_vista
0.32EPSS
CVE-2007-1756
High 9.3

Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and Office Excel 2007 does not properly validate version information, which allows user-assisted remote attackers to execute arbitrary code via a crafted Excel file, aka "Calculation Error Vulnerabilit…

microsoft excel · microsoft excel_viewer · microsoft office
0.32EPSS
CVE-2010-0020
High 9.0

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate request fields, which…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_7 · microsoft windows_server_2008 · and 2 more
0.32EPSS
CVE-2003-0663
Medium 5.0

Unknown vulnerability in the Local Security Authority Subsystem Service (LSASS) in Windows 2000 domain controllers allows remote attackers to cause a denial of service via a crafted LDAP message.

microsoft windows_2000
0.32EPSS
CVE-2013-3174
High 9.3

DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a crafted GIF file, aka "Dir…

microsoft windows_7 · microsoft windows_8 · microsoft windows_server_2003 · microsoft windows_server_2008 · and 3 more
0.32EPSS
CVE-2016-3263
Medium 5.5

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word…

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 8 more
0.32EPSS
CVE-2016-3262
Medium 5.5

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word…

microsoft live_meeting · microsoft lync · microsoft office · microsoft skype_for_business · and 8 more
0.32EPSS
CVE-2007-0947
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in accessing deallocated memory of CMarkup o…

microsoft internet_explorer
0.32EPSS
CVE-2024-21388
Medium 6.5

Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

microsoft edge_chromium
0.32EPSS
CVE-2008-3007
High 9.3

Argument injection vulnerability in a URI handler in Microsoft Office XP SP3, 2003 SP2 and SP3, 2007 Office System Gold and SP1, and Office OneNote 2007 Gold and SP1 allow remote attackers to execute arbitrary code via a crafted onenote:// URL, aka "Uniform Re…

microsoft office · microsoft office_onenote
0.32EPSS
CVE-2008-3005
High 9.3

Array index vulnerability in Microsoft Office Excel 2000 SP3 and 2002 SP3, and Office 2004 and 2008 for Mac allows remote attackers to execute arbitrary code via an Excel file with a crafted array index for a FORMAT record, aka the "Excel Index Array Vulnerabi…

microsoft office
0.32EPSS
CVE-2008-1088
High 9.3

Microsoft Project 2000 Service Release 1, 2002 SP1, and 2003 SP2 allows user-assisted remote attackers to execute arbitrary code via a crafted Project file, related to improper validation of "memory resource allocations."

microsoft project
0.32EPSS
CVE-2008-0110
High 9.3

Unspecified vulnerability in Microsoft Outlook in Office 2000 SP3, XP SP3, 2003 SP2 and Sp3, and Office System allows user-assisted remote attackers to execute arbitrary code via a crafted mailto URI.

microsoft office
0.32EPSS
CVE-2010-3328
High 8.8

Use-after-free vulnerability in the CAttrArray::PrivateFind function in mshtml.dll in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code by setting an unspecified property of a stylesheet object, aka "Uninitialized Memory…

microsoft internet_explorer
0.32EPSS
CVE-2008-0120
High 9.3

Integer overflow in Microsoft PowerPoint Viewer 2003 allows remote attackers to execute arbitrary code via a PowerPoint file with a malformed picture index that triggers memory corruption, related to handling of CString objects, aka "Memory Allocation Vulnerab…

microsoft office_powerpoint_viewer
0.32EPSS
CVE-2008-1085
High 9.3

Use-after-free vulnerability in Microsoft Internet Explorer 5.01 SP4, 6 through SP1, and 7 allows remote attackers to execute arbitrary code via a crafted data stream that triggers memory corruption, as demonstrated using an invalid MIME-type that does not hav…

microsoft ie · microsoft internet_explorer
0.32EPSS
CVE-2004-0901
High 10.0

Microsoft Word for Windows 6.0 Converter (MSWRD632.WPC), as used in WordPad, does not properly validate certain data lengths, which allows remote attackers to execute arbitrary code via a .wri, .rtf, and .doc file sent by email or malicious web site, aka "Font…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_98 · microsoft windows_98se · and 3 more
0.32EPSS
CVE-2017-0071
High 7.5

A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in…

microsoft edge
0.32EPSS
CVE-2010-0250
High 9.3

Heap-based buffer overflow in DirectShow in Microsoft DirectX, as used in the AVI Filter on Windows 2000 SP4, Windows XP SP2 and SP3, and Windows Server 2003 SP2, and in Quartz on Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista…

microsoft windows_7 · microsoft windows_server_2008 · microsoft windows_vista · microsoft windows_xp
0.32EPSS
CVE-2003-0659
High 7.2

Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_nt · microsoft windows_xp
0.32EPSS