imPC@ndo IT

Microsoft vulnerabilities

15.391 CVE

CVE-2008-4295
Medium 5.4

Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection to a peer with a long name, which allows remote attackers to cause a denial of service (device reboot) by confi…

microsoft windows_mobile
0.30EPSS
CVE-2008-0951
High 9.3

Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB …

microsoft windows_vista
0.30EPSS
CVE-2007-0208
High 9.3

Microsoft Word in Office 2000 SP3, XP SP3, Office 2003 SP2, Works Suite 2004 to 2006, and Office 2004 for Mac does not correctly check the properties of certain documents and warn the user of macro content, which allows user-assisted remote attackers to execut…

microsoft office · microsoft word · microsoft word_viewer · microsoft works
0.30EPSS
CVE-2006-3014
Medium 5.1

Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spread…

microsoft excel
0.30EPSS
CVE-2007-6255
High 9.3

Buffer overflow in the Microsoft HeartbeatCtl ActiveX control in HRTBEAT.OCX allows remote attackers to execute arbitrary code via the Host argument to an unspecified method.

microsoft windows_2000 · microsoft windows_server_2003 · microsoft windows_vista · microsoft windows_xp
0.30EPSS
CVE-2008-2259
High 9.3

Microsoft Internet Explorer 6 and 7 does not perform proper "argument validation" during print preview, which allows remote attackers to execute arbitrary code via unknown vectors, aka "HTML Component Handling Vulnerability."

microsoft internet_explorer
0.30EPSS
CVE-2008-3019
High 9.3

Microsoft Office 2000 SP3, XP SP3, and 2003 SP2; Office Converter Pack; and Works 8 do not properly parse the length of an Encapsulated PostScript (EPS) file, which allows remote attackers to execute arbitrary code via a crafted EPS file, aka the "Malformed EP…

microsoft office · microsoft office_converter_pack · microsoft works
0.30EPSS
CVE-2008-0103
High 9.3

Unspecified vulnerability in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP2, and Office 2004 for Mac allows remote attackers to execute arbitrary code via an Office document that contains a malformed object, related to a "memory handling error," aka…

microsoft office
0.30EPSS
CVE-2006-5270
High 9.3

Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, Defender, and Forefront Security, allows user-assisted remote attackers to execute arbitrary code via a crafted PDF file.

microsoft antigen · microsoft forefront_security · microsoft malware_protection_engine · microsoft windows_defender · and 1 more
0.30EPSS
CVE-2009-0224
High 9.3

Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; PowerPoint Viewer 2003 and 2007 SP1 and SP2; PowerPoint in Microsoft Office 2004 for Mac and 2008 for Mac; Open XML File Format Converter for Mac; Microsoft Works 8.5 and 9.0; and …

microsoft compatibility_pack_word_excel_powerpoint · microsoft office_compatibility_pack_for_word_excel_ppt_2007 · microsoft office_powerpoint · microsoft office_powerpoint_viewer · and 3 more
0.30EPSS
CVE-2003-0665
High 7.5

Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote attackers to execute arbitrary code via long parameters to the control.

microsoft access
0.30EPSS
CVE-2003-0701
High 7.5

Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) allows remote attackers to execute arbitrary code via the Type property of an Object tag, a variant of CVE-2003-0344.

microsoft ie · microsoft internet_explorer
0.30EPSS
CVE-2006-1257
High 7.5

The sample files in the authfiles directory in Microsoft Commerce Server 2002 before SP2 allow remote attackers to bypass authentication by logging in to authfiles/login.asp with a valid username and any password, then going to the main site twice.

microsoft commerce_server
0.30EPSS
CVE-2012-0177
High 9.3

Heap-based buffer overflow in the Office Works File Converter in Microsoft Office 2007 SP2, Works 9, and Works 6-9 File Converter allows remote attackers to execute arbitrary code via a crafted Works (aka .wps) file, aka "Office WPS Converter Heap Overflow Vul…

microsoft office · microsoft works · microsoft works_6-9_file_converter
0.30EPSS
CVE-2021-31181
High 8.8

Microsoft SharePoint Remote Code Execution Vulnerability

microsoft sharepoint_enterprise_server · microsoft sharepoint_foundation · microsoft sharepoint_server
0.30EPSS
CVE-2015-0040
High 9.3

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2015-0018, CVE…

microsoft internet_explorer
0.30EPSS
CVE-2009-1928
High 7.8

Stack consumption vulnerability in the LDAP service in Active Directory on Microsoft Windows 2000 SP4, Server 2003 SP2, and Server 2008 Gold and SP2; Active Directory Application Mode (ADAM) on Windows XP SP2 and SP3 and Server 2003 SP2; and Active Directory L…

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_server_2008 · microsoft windows_vista · and 1 more
0.30EPSS
CVE-2001-0242
High 7.5

Buffer overflows in Microsoft Windows Media Player 7 and earlier allow remote attackers to execute arbitrary commands via (1) a long version tag in an .ASX file, or (2) a long banner tag, a variant of the ".ASX Buffer Overrun" vulnerability as discussed in MS:…

microsoft windows_media_player
0.30EPSS
CVE-2001-0506
High 7.2

Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes (SSI) directive for a long filename, which triggers the overflow when the directory name is added, aka the "SSI privilege elevation" vulnera…

microsoft internet_information_server · microsoft internet_information_services
0.30EPSS
CVE-2011-0101
High 9.3

Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, double-byte characters, and an incorrect pointer calculation, aka "Excel …

microsoft excel
0.30EPSS
CVE-2023-36413
Medium 6.5

Microsoft Office Security Feature Bypass Vulnerability

microsoft 365_apps · microsoft office · microsoft office_long_term_servicing_channel
0.30EPSS
CVE-2008-0083
High 9.3

The (1) VBScript (VBScript.dll) and (2) JScript (JScript.dll) scripting engines 5.1 and 5.6, as used in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2, do not properly decode script, which allows remote attackers to execute arbitrary code via …

microsoft windows_2000 · microsoft windows_2003_server · microsoft windows_xp
0.30EPSS
CVE-2013-3137
Medium 4.3

Microsoft FrontPage 2003 SP3 does not properly parse DTDs, which allows remote attackers to obtain sensitive information via crafted XML data in a FrontPage document, aka "XML Disclosure Vulnerability."

microsoft frontpage
0.30EPSS
CVE-2015-0064
High 9.3

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service…

microsoft office · microsoft office_compatibility_pack · microsoft sharepoint_server · microsoft web_applications · and 3 more
0.30EPSS
CVE-2017-0066
Medium 4.2

Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0…

microsoft edge
0.30EPSS